From 7a890734b8caf5f556ef60193df271b95d4f7501 Mon Sep 17 00:00:00 2001 From: runner Date: Tue, 16 Sep 2025 19:13:31 +0000 Subject: [PATCH] Automatic updates from complyscribe --- catalogs/cis_rhel10/catalog.json | 1416 +- .../component-definition.json | 16 +- .../component-definition.json | 16 +- .../component-definition.json | 32 +- .../component-definition.json | 32 +- .../component-definition.json | 9634 ++++++------ .../component-definition.json | 9468 ++++++------ .../component-definition.json | 12656 +++++++--------- .../component-definition.json | 12052 +++++++-------- .../component-definition.json | 16 +- .../component-definition.json | 16 +- .../component-definition.json | 16 +- .../component-definition.json | 32 +- .../component-definition.json | 32 +- .../component-definition.json | 16 +- .../component-definition.json | 20 +- .../component-definition.json | 20 +- .../component-definition.json | 20 +- .../component-definition.json | 18 +- .../component-definition.json | 18 +- .../component-definition.json | 34 +- .../component-definition.json | 34 +- .../component-definition.json | 18 +- .../component-definition.json | 122 +- .../component-definition.json | 98 +- .../component-definition.json | 1702 +-- 26 files changed, 22356 insertions(+), 25198 deletions(-) diff --git a/catalogs/cis_rhel10/catalog.json b/catalogs/cis_rhel10/catalog.json index ddfa65986..b4b8da761 100644 --- a/catalogs/cis_rhel10/catalog.json +++ b/catalogs/cis_rhel10/catalog.json @@ -100,6 +100,111 @@ "value": "cis_rhel10_1-01.01.09" } ] + }, + { + "id": "cis_rhel10_1-1.1.1", + "class": "CAC_IMPORT", + "title": "Ensure Cramfs Kernel Module Is Not Available (Automated)", + "props": [ + { + "name": "label", + "value": "1.1.1.1" + }, + { + "name": "sort-id", + "value": "cis_rhel10_1-01.01.01" + } + ] + }, + { + "id": "cis_rhel10_1-1.1.2", + "class": "CAC_IMPORT", + "title": "Ensure Freevxfs Kernel Module Is Not Available (Automated)", + "props": [ + { + "name": "label", + "value": "1.1.1.2" + }, + { + "name": "sort-id", + "value": "cis_rhel10_1-01.01.02" + } + ] + }, + { + "id": "cis_rhel10_1-1.1.3", + "class": "CAC_IMPORT", + "title": "Ensure Hfs Kernel Module Is Not Available (Automated)", + "props": [ + { + "name": "label", + "value": "1.1.1.3" + }, + { + "name": "sort-id", + "value": "cis_rhel10_1-01.01.03" + } + ] + }, + { + "id": "cis_rhel10_1-1.1.4", + "class": "CAC_IMPORT", + "title": "Ensure Hfsplus Kernel Module Is Not Available (Automated)", + "props": [ + { + "name": "label", + "value": "1.1.1.4" + }, + { + "name": "sort-id", + "value": "cis_rhel10_1-01.01.04" + } + ] + }, + { + "id": "cis_rhel10_1-1.1.5", + "class": "CAC_IMPORT", + "title": "Ensure Jffs2 Kernel Module Is Not Available (Automated)", + "props": [ + { + "name": "label", + "value": "1.1.1.5" + }, + { + "name": "sort-id", + "value": "cis_rhel10_1-01.01.05" + } + ] + }, + { + "id": "cis_rhel10_1-1.1.10", + "class": "CAC_IMPORT", + "title": "Ensure Usb-Storage Kernel Module Is Not Available (Automated)", + "props": [ + { + "name": "label", + "value": "1.1.1.10" + }, + { + "name": "sort-id", + "value": "cis_rhel10_1-01.01.10" + } + ] + }, + { + "id": "cis_rhel10_1-1.1.11", + "class": "CAC_IMPORT", + "title": "Ensure Unused Filesystems Kernel Modules Are Not Available (Manual)", + "props": [ + { + "name": "label", + "value": "1.1.1.11" + }, + { + "name": "sort-id", + "value": "cis_rhel10_1-01.01.11" + } + ] } ] }, @@ -610,6 +715,21 @@ "value": "cis_rhel10_1-02.01.04" } ] + }, + { + "id": "cis_rhel10_1-2.1.5", + "class": "CAC_IMPORT", + "title": "Ensure Weak Dependencies Are Configured (Automated)", + "props": [ + { + "name": "label", + "value": "1.2.1.5" + }, + { + "name": "sort-id", + "value": "cis_rhel10_1-02.01.05" + } + ] } ] }, @@ -867,6 +987,96 @@ "value": "cis_rhel10_1-05.04" } ] + }, + { + "id": "cis_rhel10_1-5.5", + "class": "CAC_IMPORT", + "title": "Ensure Kernel.Dmesg_Restrict Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "1.5.5" + }, + { + "name": "sort-id", + "value": "cis_rhel10_1-05.05" + } + ] + }, + { + "id": "cis_rhel10_1-5.6", + "class": "CAC_IMPORT", + "title": "Ensure Kernel.Kptr_Restrict Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "1.5.6" + }, + { + "name": "sort-id", + "value": "cis_rhel10_1-05.06" + } + ] + }, + { + "id": "cis_rhel10_1-5.7", + "class": "CAC_IMPORT", + "title": "Ensure Kernel.Yama.Ptrace_Scope Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "1.5.7" + }, + { + "name": "sort-id", + "value": "cis_rhel10_1-05.07" + } + ] + }, + { + "id": "cis_rhel10_1-5.8", + "class": "CAC_IMPORT", + "title": "Ensure Kernel.Randomize_Va_Space Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "1.5.8" + }, + { + "name": "sort-id", + "value": "cis_rhel10_1-05.08" + } + ] + }, + { + "id": "cis_rhel10_1-5.9", + "class": "CAC_IMPORT", + "title": "Ensure Systemd-Coredump Processsizemax Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "1.5.9" + }, + { + "name": "sort-id", + "value": "cis_rhel10_1-05.09" + } + ] + }, + { + "id": "cis_rhel10_1-5.10", + "class": "CAC_IMPORT", + "title": "Ensure Systemd-Coredump Storage Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "1.5.10" + }, + { + "name": "sort-id", + "value": "cis_rhel10_1-05.10" + } + ] } ] }, @@ -1557,6 +1767,21 @@ "value": "cis_rhel10_2-01.22" } ] + }, + { + "id": "cis_rhel10_2-1.19", + "class": "CAC_IMPORT", + "title": "Ensure Gnome Display Manager Is Removed (Automated)", + "props": [ + { + "name": "label", + "value": "2.1.19" + }, + { + "name": "sort-id", + "value": "cis_rhel10_2-01.19" + } + ] } ] }, @@ -1819,6 +2044,21 @@ "value": "cis_rhel10_2-04.01.08" } ] + }, + { + "id": "cis_rhel10_2-4.1.9", + "class": "CAC_IMPORT", + "title": "Ensure Access To Crontab Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "2.4.1.9" + }, + { + "name": "sort-id", + "value": "cis_rhel10_2-04.01.09" + } + ] } ] }, @@ -1935,117 +2175,571 @@ "value": "cis_rhel10_3-02.04" } ] - } - ] - }, - { - "id": "cis_rhel10_3-3", - "title": "REPLACE_ME", - "controls": [ - { - "id": "cis_rhel10_3-3.1", - "class": "CAC_IMPORT", - "title": "Ensure Ip Forwarding Is Disabled (Automated)", - "props": [ - { - "name": "label", - "value": "3.3.1" - }, - { - "name": "sort-id", - "value": "cis_rhel10_3-03.01" - } - ] }, { - "id": "cis_rhel10_3-3.2", + "id": "cis_rhel10_3-2.1", "class": "CAC_IMPORT", - "title": "Ensure Packet Redirect Sending Is Disabled (Automated)", + "title": "Ensure Atm Kernel Module Is Not Available (Automated)", "props": [ { "name": "label", - "value": "3.3.2" + "value": "3.2.1" }, { "name": "sort-id", - "value": "cis_rhel10_3-03.02" + "value": "cis_rhel10_3-02.01" } ] }, { - "id": "cis_rhel10_3-3.3", + "id": "cis_rhel10_3-2.3", "class": "CAC_IMPORT", - "title": "Ensure Bogus Icmp Responses Are Ignored (Automated)", + "title": "Ensure Dccp Kernel Module Is Not Available (Automated)", "props": [ { "name": "label", - "value": "3.3.3" + "value": "3.2.3" }, { "name": "sort-id", - "value": "cis_rhel10_3-03.03" + "value": "cis_rhel10_3-02.03" } ] }, { - "id": "cis_rhel10_3-3.4", + "id": "cis_rhel10_3-2.5", "class": "CAC_IMPORT", - "title": "Ensure Broadcast Icmp Requests Are Ignored (Automated)", + "title": "Ensure Rds Kernel Module Is Not Available (Automated)", "props": [ { "name": "label", - "value": "3.3.4" + "value": "3.2.5" }, { "name": "sort-id", - "value": "cis_rhel10_3-03.04" + "value": "cis_rhel10_3-02.05" } ] }, { - "id": "cis_rhel10_3-3.5", + "id": "cis_rhel10_3-2.6", "class": "CAC_IMPORT", - "title": "Ensure Icmp Redirects Are Not Accepted (Automated)", + "title": "Ensure Sctp Kernel Module Is Not Available (Automated)", "props": [ { "name": "label", - "value": "3.3.5" + "value": "3.2.6" }, { "name": "sort-id", - "value": "cis_rhel10_3-03.05" + "value": "cis_rhel10_3-02.06" } ] - }, + } + ] + }, + { + "id": "cis_rhel10_3-3", + "title": "REPLACE_ME", + "controls": [ { - "id": "cis_rhel10_3-3.6", + "id": "cis_rhel10_3-3.1", "class": "CAC_IMPORT", - "title": "Ensure Secure Icmp Redirects Are Not Accepted (Automated)", + "title": "Ensure Ip Forwarding Is Disabled (Automated)", "props": [ { "name": "label", - "value": "3.3.6" + "value": "3.3.1" }, { "name": "sort-id", - "value": "cis_rhel10_3-03.06" + "value": "cis_rhel10_3-03.01" } - ] - }, - { - "id": "cis_rhel10_3-3.7", - "class": "CAC_IMPORT", - "title": "Ensure Reverse Path Filtering Is Enabled (Automated)", - "props": [ + ], + "controls": [ { - "name": "label", - "value": "3.3.7" + "id": "cis_rhel10_3-3.1.1", + "class": "CAC_IMPORT", + "title": "Ensure Net.Ipv4.Ip_Forward Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "3.3.1.1" + }, + { + "name": "sort-id", + "value": "cis_rhel10_3-03.01.01" + } + ] }, { - "name": "sort-id", - "value": "cis_rhel10_3-03.07" - } - ] + "id": "cis_rhel10_3-3.1.2", + "class": "CAC_IMPORT", + "title": "Ensure Net.Ipv4.Conf.All.Forwarding Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "3.3.1.2" + }, + { + "name": "sort-id", + "value": "cis_rhel10_3-03.01.02" + } + ] + }, + { + "id": "cis_rhel10_3-3.1.3", + "class": "CAC_IMPORT", + "title": "Ensure Net.Ipv4.Conf.Default.Forwarding Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "3.3.1.3" + }, + { + "name": "sort-id", + "value": "cis_rhel10_3-03.01.03" + } + ] + }, + { + "id": "cis_rhel10_3-3.1.4", + "class": "CAC_IMPORT", + "title": "Ensure Net.Ipv4.Conf.All.Send_Redirects Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "3.3.1.4" + }, + { + "name": "sort-id", + "value": "cis_rhel10_3-03.01.04" + } + ] + }, + { + "id": "cis_rhel10_3-3.1.5", + "class": "CAC_IMPORT", + "title": "Ensure Net.Ipv4.Conf.Default.Send_Redirects Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "3.3.1.5" + }, + { + "name": "sort-id", + "value": "cis_rhel10_3-03.01.05" + } + ] + }, + { + "id": "cis_rhel10_3-3.1.6", + "class": "CAC_IMPORT", + "title": "Ensure Net.Ipv4.Icmp_Ignore_Bogus_Error_Responses Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "3.3.1.6" + }, + { + "name": "sort-id", + "value": "cis_rhel10_3-03.01.06" + } + ] + }, + { + "id": "cis_rhel10_3-3.1.7", + "class": "CAC_IMPORT", + "title": "Ensure Net.Ipv4.Icmp_Echo_Ignore_Broadcasts Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "3.3.1.7" + }, + { + "name": "sort-id", + "value": "cis_rhel10_3-03.01.07" + } + ] + }, + { + "id": "cis_rhel10_3-3.1.8", + "class": "CAC_IMPORT", + "title": "Ensure Net.Ipv4.Conf.All.Accept_Redirects Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "3.3.1.8" + }, + { + "name": "sort-id", + "value": "cis_rhel10_3-03.01.08" + } + ] + }, + { + "id": "cis_rhel10_3-3.1.9", + "class": "CAC_IMPORT", + "title": "Ensure Net.Ipv4.Conf.Default.Accept_Redirects Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "3.3.1.9" + }, + { + "name": "sort-id", + "value": "cis_rhel10_3-03.01.09" + } + ] + }, + { + "id": "cis_rhel10_3-3.1.10", + "class": "CAC_IMPORT", + "title": "Ensure Net.Ipv4.Conf.All.Secure_Redirects Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "3.3.1.10" + }, + { + "name": "sort-id", + "value": "cis_rhel10_3-03.01.10" + } + ] + }, + { + "id": "cis_rhel10_3-3.1.11", + "class": "CAC_IMPORT", + "title": "Ensure Net.Ipv4.Conf.Default.Secure_Redirects Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "3.3.1.11" + }, + { + "name": "sort-id", + "value": "cis_rhel10_3-03.01.11" + } + ] + }, + { + "id": "cis_rhel10_3-3.1.12", + "class": "CAC_IMPORT", + "title": "Ensure Net.Ipv4.Conf.All.Rp_Filter Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "3.3.1.12" + }, + { + "name": "sort-id", + "value": "cis_rhel10_3-03.01.12" + } + ] + }, + { + "id": "cis_rhel10_3-3.1.13", + "class": "CAC_IMPORT", + "title": "Ensure Net.Ipv4.Conf.Default.Rp_Filter Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "3.3.1.13" + }, + { + "name": "sort-id", + "value": "cis_rhel10_3-03.01.13" + } + ] + }, + { + "id": "cis_rhel10_3-3.1.14", + "class": "CAC_IMPORT", + "title": "Ensure Net.Ipv4.Conf.All.Accept_Source_Route Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "3.3.1.14" + }, + { + "name": "sort-id", + "value": "cis_rhel10_3-03.01.14" + } + ] + }, + { + "id": "cis_rhel10_3-3.1.15", + "class": "CAC_IMPORT", + "title": "Ensure Net.Ipv4.Conf.Default.Accept_Source_Route Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "3.3.1.15" + }, + { + "name": "sort-id", + "value": "cis_rhel10_3-03.01.15" + } + ] + }, + { + "id": "cis_rhel10_3-3.1.16", + "class": "CAC_IMPORT", + "title": "Ensure Net.Ipv4.Conf.All.Log_Martians Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "3.3.1.16" + }, + { + "name": "sort-id", + "value": "cis_rhel10_3-03.01.16" + } + ] + }, + { + "id": "cis_rhel10_3-3.1.17", + "class": "CAC_IMPORT", + "title": "Ensure Net.Ipv4.Conf.Default.Log_Martians Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "3.3.1.17" + }, + { + "name": "sort-id", + "value": "cis_rhel10_3-03.01.17" + } + ] + }, + { + "id": "cis_rhel10_3-3.1.18", + "class": "CAC_IMPORT", + "title": "Ensure Net.Ipv4.Tcp_Syncookies Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "3.3.1.18" + }, + { + "name": "sort-id", + "value": "cis_rhel10_3-03.01.18" + } + ] + } + ] + }, + { + "id": "cis_rhel10_3-3.2", + "class": "CAC_IMPORT", + "title": "Ensure Packet Redirect Sending Is Disabled (Automated)", + "props": [ + { + "name": "label", + "value": "3.3.2" + }, + { + "name": "sort-id", + "value": "cis_rhel10_3-03.02" + } + ], + "controls": [ + { + "id": "cis_rhel10_3-3.2.1", + "class": "CAC_IMPORT", + "title": "Ensure Net.Ipv6.Conf.All.Forwarding Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "3.3.2.1" + }, + { + "name": "sort-id", + "value": "cis_rhel10_3-03.02.01" + } + ] + }, + { + "id": "cis_rhel10_3-3.2.2", + "class": "CAC_IMPORT", + "title": "Ensure Net.Ipv6.Conf.Default.Forwarding Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "3.3.2.2" + }, + { + "name": "sort-id", + "value": "cis_rhel10_3-03.02.02" + } + ] + }, + { + "id": "cis_rhel10_3-3.2.3", + "class": "CAC_IMPORT", + "title": "Ensure Net.Ipv6.Conf.All.Accept_Redirects Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "3.3.2.3" + }, + { + "name": "sort-id", + "value": "cis_rhel10_3-03.02.03" + } + ] + }, + { + "id": "cis_rhel10_3-3.2.4", + "class": "CAC_IMPORT", + "title": "Ensure Net.Ipv6.Conf.Default.Accept_Redirects Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "3.3.2.4" + }, + { + "name": "sort-id", + "value": "cis_rhel10_3-03.02.04" + } + ] + }, + { + "id": "cis_rhel10_3-3.2.5", + "class": "CAC_IMPORT", + "title": "Ensure Net.Ipv6.Conf.All.Accept_Source_Route Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "3.3.2.5" + }, + { + "name": "sort-id", + "value": "cis_rhel10_3-03.02.05" + } + ] + }, + { + "id": "cis_rhel10_3-3.2.6", + "class": "CAC_IMPORT", + "title": "Ensure Net.Ipv6.Conf.Default.Accept_Source_Route Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "3.3.2.6" + }, + { + "name": "sort-id", + "value": "cis_rhel10_3-03.02.06" + } + ] + }, + { + "id": "cis_rhel10_3-3.2.7", + "class": "CAC_IMPORT", + "title": "Ensure Net.Ipv6.Conf.All.Accept_Ra Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "3.3.2.7" + }, + { + "name": "sort-id", + "value": "cis_rhel10_3-03.02.07" + } + ] + }, + { + "id": "cis_rhel10_3-3.2.8", + "class": "CAC_IMPORT", + "title": "Ensure Net.Ipv6.Conf.Default.Accept_Ra Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "3.3.2.8" + }, + { + "name": "sort-id", + "value": "cis_rhel10_3-03.02.08" + } + ] + } + ] + }, + { + "id": "cis_rhel10_3-3.3", + "class": "CAC_IMPORT", + "title": "Ensure Bogus Icmp Responses Are Ignored (Automated)", + "props": [ + { + "name": "label", + "value": "3.3.3" + }, + { + "name": "sort-id", + "value": "cis_rhel10_3-03.03" + } + ] + }, + { + "id": "cis_rhel10_3-3.4", + "class": "CAC_IMPORT", + "title": "Ensure Broadcast Icmp Requests Are Ignored (Automated)", + "props": [ + { + "name": "label", + "value": "3.3.4" + }, + { + "name": "sort-id", + "value": "cis_rhel10_3-03.04" + } + ] + }, + { + "id": "cis_rhel10_3-3.5", + "class": "CAC_IMPORT", + "title": "Ensure Icmp Redirects Are Not Accepted (Automated)", + "props": [ + { + "name": "label", + "value": "3.3.5" + }, + { + "name": "sort-id", + "value": "cis_rhel10_3-03.05" + } + ] + }, + { + "id": "cis_rhel10_3-3.6", + "class": "CAC_IMPORT", + "title": "Ensure Secure Icmp Redirects Are Not Accepted (Automated)", + "props": [ + { + "name": "label", + "value": "3.3.6" + }, + { + "name": "sort-id", + "value": "cis_rhel10_3-03.06" + } + ] + }, + { + "id": "cis_rhel10_3-3.7", + "class": "CAC_IMPORT", + "title": "Ensure Reverse Path Filtering Is Enabled (Automated)", + "props": [ + { + "name": "label", + "value": "3.3.7" + }, + { + "name": "sort-id", + "value": "cis_rhel10_3-03.07" + } + ] }, { "id": "cis_rhel10_3-3.8", @@ -2148,6 +2842,81 @@ "value": "cis_rhel10_4-01.02" } ] + }, + { + "id": "cis_rhel10_4-1.3", + "class": "CAC_IMPORT", + "title": "Ensure Firewalld.Service Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "4.1.3" + }, + { + "name": "sort-id", + "value": "cis_rhel10_4-01.03" + } + ] + }, + { + "id": "cis_rhel10_4-1.4", + "class": "CAC_IMPORT", + "title": "Ensure Firewalld Active Zone Target Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "4.1.4" + }, + { + "name": "sort-id", + "value": "cis_rhel10_4-01.04" + } + ] + }, + { + "id": "cis_rhel10_4-1.5", + "class": "CAC_IMPORT", + "title": "Ensure Firewalld Loopback Traffic Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "4.1.5" + }, + { + "name": "sort-id", + "value": "cis_rhel10_4-01.05" + } + ] + }, + { + "id": "cis_rhel10_4-1.6", + "class": "CAC_IMPORT", + "title": "Ensure Firewalld Loopback Source Address Traffic Is Configured (Manual)", + "props": [ + { + "name": "label", + "value": "4.1.6" + }, + { + "name": "sort-id", + "value": "cis_rhel10_4-01.06" + } + ] + }, + { + "id": "cis_rhel10_4-1.7", + "class": "CAC_IMPORT", + "title": "Ensure Firewalld Services And Ports Are Configured (Manual)", + "props": [ + { + "name": "label", + "value": "4.1.7" + }, + { + "name": "sort-id", + "value": "cis_rhel10_4-01.07" + } + ] } ] }, @@ -2758,6 +3527,36 @@ "value": "cis_rhel10_5-03.01.03" } ] + }, + { + "id": "cis_rhel10_5-3.1.4", + "class": "CAC_IMPORT", + "title": "Ensure Pam_Pwhistory Module Is Enabled (Automated)", + "props": [ + { + "name": "label", + "value": "5.3.1.4" + }, + { + "name": "sort-id", + "value": "cis_rhel10_5-03.01.04" + } + ] + }, + { + "id": "cis_rhel10_5-3.1.5", + "class": "CAC_IMPORT", + "title": "Ensure Pam_Unix Module Is Enabled (Automated)", + "props": [ + { + "name": "label", + "value": "5.3.1.5" + }, + { + "name": "sort-id", + "value": "cis_rhel10_5-03.01.05" + } + ] } ] }, @@ -2778,6 +3577,53 @@ "name": "sort-id", "value": "cis_rhel10_5-03.02.01" } + ], + "controls": [ + { + "id": "cis_rhel10_5-3.2.1.1", + "class": "CAC_IMPORT", + "title": "Ensure Password Failed Attempts Lockout Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "5.3.2.1.1" + }, + { + "name": "sort-id", + "value": "cis_rhel10_5-03.02.01.01" + } + ] + }, + { + "id": "cis_rhel10_5-3.2.1.2", + "class": "CAC_IMPORT", + "title": "Ensure Password Unlock Time Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "5.3.2.1.2" + }, + { + "name": "sort-id", + "value": "cis_rhel10_5-03.02.01.02" + } + ] + }, + { + "id": "cis_rhel10_5-3.2.1.3", + "class": "CAC_IMPORT", + "title": "Ensure Password Failed Attempts Lockout Includes Root Account (Automated)", + "props": [ + { + "name": "label", + "value": "5.3.2.1.3" + }, + { + "name": "sort-id", + "value": "cis_rhel10_5-03.02.01.03" + } + ] + } ] }, { @@ -2793,6 +3639,113 @@ "name": "sort-id", "value": "cis_rhel10_5-03.02.02" } + ], + "controls": [ + { + "id": "cis_rhel10_5-3.2.2.1", + "class": "CAC_IMPORT", + "title": "Ensure Password Number Of Changed Characters Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "5.3.2.2.1" + }, + { + "name": "sort-id", + "value": "cis_rhel10_5-03.02.02.01" + } + ] + }, + { + "id": "cis_rhel10_5-3.2.2.2", + "class": "CAC_IMPORT", + "title": "Ensure Password Length Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "5.3.2.2.2" + }, + { + "name": "sort-id", + "value": "cis_rhel10_5-03.02.02.02" + } + ] + }, + { + "id": "cis_rhel10_5-3.2.2.3", + "class": "CAC_IMPORT", + "title": "Ensure Password Complexity Is Configured (Manual)", + "props": [ + { + "name": "label", + "value": "5.3.2.2.3" + }, + { + "name": "sort-id", + "value": "cis_rhel10_5-03.02.02.03" + } + ] + }, + { + "id": "cis_rhel10_5-3.2.2.4", + "class": "CAC_IMPORT", + "title": "Ensure Password Same Consecutive Characters Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "5.3.2.2.4" + }, + { + "name": "sort-id", + "value": "cis_rhel10_5-03.02.02.04" + } + ] + }, + { + "id": "cis_rhel10_5-3.2.2.5", + "class": "CAC_IMPORT", + "title": "Ensure Password Maximum Sequential Characters Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "5.3.2.2.5" + }, + { + "name": "sort-id", + "value": "cis_rhel10_5-03.02.02.05" + } + ] + }, + { + "id": "cis_rhel10_5-3.2.2.6", + "class": "CAC_IMPORT", + "title": "Ensure Password Dictionary Check Is Enabled (Automated)", + "props": [ + { + "name": "label", + "value": "5.3.2.2.6" + }, + { + "name": "sort-id", + "value": "cis_rhel10_5-03.02.02.06" + } + ] + }, + { + "id": "cis_rhel10_5-3.2.2.7", + "class": "CAC_IMPORT", + "title": "Ensure Password Quality Is Enforced For The Root User (Automated)", + "props": [ + { + "name": "label", + "value": "5.3.2.2.7" + }, + { + "name": "sort-id", + "value": "cis_rhel10_5-03.02.02.07" + } + ] + } ] }, { @@ -2805,8 +3758,55 @@ "value": "5.3.2.3" }, { - "name": "sort-id", - "value": "cis_rhel10_5-03.02.03" + "name": "sort-id", + "value": "cis_rhel10_5-03.02.03" + } + ], + "controls": [ + { + "id": "cis_rhel10_5-3.2.3.1", + "class": "CAC_IMPORT", + "title": "Ensure Password History Remember Is Configured (Automated)", + "props": [ + { + "name": "label", + "value": "5.3.2.3.1" + }, + { + "name": "sort-id", + "value": "cis_rhel10_5-03.02.03.01" + } + ] + }, + { + "id": "cis_rhel10_5-3.2.3.2", + "class": "CAC_IMPORT", + "title": "Ensure Password History Is Enforced For The Root User (Automated)", + "props": [ + { + "name": "label", + "value": "5.3.2.3.2" + }, + { + "name": "sort-id", + "value": "cis_rhel10_5-03.02.03.02" + } + ] + }, + { + "id": "cis_rhel10_5-3.2.3.3", + "class": "CAC_IMPORT", + "title": "Ensure Pam_Pwhistory Includes Use_Authtok (Automated)", + "props": [ + { + "name": "label", + "value": "5.3.2.3.3" + }, + { + "name": "sort-id", + "value": "cis_rhel10_5-03.02.03.03" + } + ] } ] }, @@ -2823,6 +3823,68 @@ "name": "sort-id", "value": "cis_rhel10_5-03.02.04" } + ], + "controls": [ + { + "id": "cis_rhel10_5-3.2.4.1", + "class": "CAC_IMPORT", + "title": "Ensure Pam_Unix Does Not Include Nullok (Automated)", + "props": [ + { + "name": "label", + "value": "5.3.2.4.1" + }, + { + "name": "sort-id", + "value": "cis_rhel10_5-03.02.04.01" + } + ] + }, + { + "id": "cis_rhel10_5-3.2.4.2", + "class": "CAC_IMPORT", + "title": "Ensure Pam_Unix Does Not Include Remember (Automated)", + "props": [ + { + "name": "label", + "value": "5.3.2.4.2" + }, + { + "name": "sort-id", + "value": "cis_rhel10_5-03.02.04.02" + } + ] + }, + { + "id": "cis_rhel10_5-3.2.4.3", + "class": "CAC_IMPORT", + "title": "Ensure Pam_Unix Includes A Strong Password Hashing Algorithm (Automated)", + "props": [ + { + "name": "label", + "value": "5.3.2.4.3" + }, + { + "name": "sort-id", + "value": "cis_rhel10_5-03.02.04.03" + } + ] + }, + { + "id": "cis_rhel10_5-3.2.4.4", + "class": "CAC_IMPORT", + "title": "Ensure Pam_Unix Includes Use_Authtok (Automated)", + "props": [ + { + "name": "label", + "value": "5.3.2.4.4" + }, + { + "name": "sort-id", + "value": "cis_rhel10_5-03.02.04.04" + } + ] + } ] }, { @@ -4255,6 +5317,246 @@ "value": "cis_rhel10_6-03.03.21" } ] + }, + { + "id": "cis_rhel10_6-3.3.22", + "class": "CAC_IMPORT", + "title": "Ensure Session Initiation Information Is Collected (Automated)", + "props": [ + { + "name": "label", + "value": "6.3.3.22" + }, + { + "name": "sort-id", + "value": "cis_rhel10_6-03.03.22" + } + ] + }, + { + "id": "cis_rhel10_6-3.3.23", + "class": "CAC_IMPORT", + "title": "Ensure Login And Logout Events Are Collected (Automated)", + "props": [ + { + "name": "label", + "value": "6.3.3.23" + }, + { + "name": "sort-id", + "value": "cis_rhel10_6-03.03.23" + } + ] + }, + { + "id": "cis_rhel10_6-3.3.24", + "class": "CAC_IMPORT", + "title": "Ensure Unlink File Deletion Events By Users Are Collected (Automated)", + "props": [ + { + "name": "label", + "value": "6.3.3.24" + }, + { + "name": "sort-id", + "value": "cis_rhel10_6-03.03.24" + } + ] + }, + { + "id": "cis_rhel10_6-3.3.25", + "class": "CAC_IMPORT", + "title": "Ensure Rename File Deletion Events By Users Are Collected (Automated)", + "props": [ + { + "name": "label", + "value": "6.3.3.25" + }, + { + "name": "sort-id", + "value": "cis_rhel10_6-03.03.25" + } + ] + }, + { + "id": "cis_rhel10_6-3.3.26", + "class": "CAC_IMPORT", + "title": "Ensure Events That Modify The System'S Mandatory Access Controls Are Collected (Automated)", + "props": [ + { + "name": "label", + "value": "6.3.3.26" + }, + { + "name": "sort-id", + "value": "cis_rhel10_6-03.03.26" + } + ] + }, + { + "id": "cis_rhel10_6-3.3.27", + "class": "CAC_IMPORT", + "title": "Ensure Successful And Unsuccessful Attempts To Use The Chcon Command Are Collected (Automated)", + "props": [ + { + "name": "label", + "value": "6.3.3.27" + }, + { + "name": "sort-id", + "value": "cis_rhel10_6-03.03.27" + } + ] + }, + { + "id": "cis_rhel10_6-3.3.28", + "class": "CAC_IMPORT", + "title": "Ensure Successful And Unsuccessful Attempts To Use The Setfacl Command Are Collected (Automated)", + "props": [ + { + "name": "label", + "value": "6.3.3.28" + }, + { + "name": "sort-id", + "value": "cis_rhel10_6-03.03.28" + } + ] + }, + { + "id": "cis_rhel10_6-3.3.29", + "class": "CAC_IMPORT", + "title": "Ensure Successful And Unsuccessful Attempts To Use The Chacl Command Are Collected (Automated)", + "props": [ + { + "name": "label", + "value": "6.3.3.29" + }, + { + "name": "sort-id", + "value": "cis_rhel10_6-03.03.29" + } + ] + }, + { + "id": "cis_rhel10_6-3.3.30", + "class": "CAC_IMPORT", + "title": "Ensure Successful And Unsuccessful Attempts To Use The Usermod Command Are Collected (Automated)", + "props": [ + { + "name": "label", + "value": "6.3.3.30" + }, + { + "name": "sort-id", + "value": "cis_rhel10_6-03.03.30" + } + ] + }, + { + "id": "cis_rhel10_6-3.3.31", + "class": "CAC_IMPORT", + "title": "Ensure Kernel Module Loading Unloading And Modification Is Collected (Automated)", + "props": [ + { + "name": "label", + "value": "6.3.3.31" + }, + { + "name": "sort-id", + "value": "cis_rhel10_6-03.03.31" + } + ] + }, + { + "id": "cis_rhel10_6-3.3.32", + "class": "CAC_IMPORT", + "title": "Ensure Kernel \"Init_Module\" And \"Finit_Module\" Loading Unloading And Modification Is Collected (Automated)", + "props": [ + { + "name": "label", + "value": "6.3.3.32" + }, + { + "name": "sort-id", + "value": "cis_rhel10_6-03.03.32" + } + ] + }, + { + "id": "cis_rhel10_6-3.3.33", + "class": "CAC_IMPORT", + "title": "Ensure Kernel \"Delete_Module\" Loading Unloading And Modification Is Collected (Automated)", + "props": [ + { + "name": "label", + "value": "6.3.3.33" + }, + { + "name": "sort-id", + "value": "cis_rhel10_6-03.03.33" + } + ] + }, + { + "id": "cis_rhel10_6-3.3.34", + "class": "CAC_IMPORT", + "title": "Ensure Kernel \"Create_Module\" And \"Query_Module\" Loading Unloading And Modification Is Collected (Automated)", + "props": [ + { + "name": "label", + "value": "6.3.3.34" + }, + { + "name": "sort-id", + "value": "cis_rhel10_6-03.03.34" + } + ] + }, + { + "id": "cis_rhel10_6-3.3.35", + "class": "CAC_IMPORT", + "title": "Ensure The Audit Configuration Is Loaded Regardless Of Errors (Automated)", + "props": [ + { + "name": "label", + "value": "6.3.3.35" + }, + { + "name": "sort-id", + "value": "cis_rhel10_6-03.03.35" + } + ] + }, + { + "id": "cis_rhel10_6-3.3.36", + "class": "CAC_IMPORT", + "title": "Ensure The Audit Configuration Is Immutable (Automated)", + "props": [ + { + "name": "label", + "value": "6.3.3.36" + }, + { + "name": "sort-id", + "value": "cis_rhel10_6-03.03.36" + } + ] + }, + { + "id": "cis_rhel10_6-3.3.37", + "class": "CAC_IMPORT", + "title": "Ensure The Running And On Disk Configuration Is The Same (Manual)", + "props": [ + { + "name": "label", + "value": "6.3.3.37" + }, + { + "name": "sort-id", + "value": "cis_rhel10_6-03.03.37" + } + ] } ] }, diff --git a/component-definitions/fedora/fedora-cis_fedora-l1_server/component-definition.json b/component-definitions/fedora/fedora-cis_fedora-l1_server/component-definition.json index a2e1b58e3..a7430b7dd 100644 --- a/component-definitions/fedora/fedora-cis_fedora-l1_server/component-definition.json +++ b/component-definitions/fedora/fedora-cis_fedora-l1_server/component-definition.json @@ -3,8 +3,8 @@ "uuid": "77a62ff1-d5eb-47f8-a08f-063352e9479f", "metadata": { "title": "Component definition for fedora", - "last-modified": "2025-09-12T15:27:02.603895+08:00", - "version": "1.0", + "last-modified": "2025-09-16T19:40:17.201481+00:00", + "version": "1.1", "oscal-version": "1.1.3" }, "components": [ @@ -131,7 +131,7 @@ { "name": "Parameter_Value_Alternatives_5", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", + "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel10': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", "remarks": "rule_set_000" }, { @@ -149,7 +149,7 @@ { "name": "Parameter_Value_Alternatives_6", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", + "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel10': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", "remarks": "rule_set_000" }, { @@ -977,7 +977,7 @@ { "name": "Parameter_Value_Alternatives_52", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { @@ -9363,7 +9363,7 @@ { "name": "Parameter_Value_Alternatives_5", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", + "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel10': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", "remarks": "rule_set_000" }, { @@ -9381,7 +9381,7 @@ { "name": "Parameter_Value_Alternatives_6", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", + "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel10': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", "remarks": "rule_set_000" }, { @@ -10209,7 +10209,7 @@ { "name": "Parameter_Value_Alternatives_52", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { diff --git a/component-definitions/fedora/fedora-cis_fedora-l1_workstation/component-definition.json b/component-definitions/fedora/fedora-cis_fedora-l1_workstation/component-definition.json index 4a1e7a831..d9cd23711 100644 --- a/component-definitions/fedora/fedora-cis_fedora-l1_workstation/component-definition.json +++ b/component-definitions/fedora/fedora-cis_fedora-l1_workstation/component-definition.json @@ -3,8 +3,8 @@ "uuid": "e4c9973a-dbda-48c4-8081-bf2dbfe65692", "metadata": { "title": "Component definition for fedora", - "last-modified": "2025-09-12T15:27:55.639146+08:00", - "version": "1.0", + "last-modified": "2025-09-16T19:41:05.279400+00:00", + "version": "1.1", "oscal-version": "1.1.3" }, "components": [ @@ -131,7 +131,7 @@ { "name": "Parameter_Value_Alternatives_5", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", + "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel10': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", "remarks": "rule_set_000" }, { @@ -149,7 +149,7 @@ { "name": "Parameter_Value_Alternatives_6", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", + "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel10': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", "remarks": "rule_set_000" }, { @@ -977,7 +977,7 @@ { "name": "Parameter_Value_Alternatives_52", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { @@ -9143,7 +9143,7 @@ { "name": "Parameter_Value_Alternatives_5", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", + "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel10': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", "remarks": "rule_set_000" }, { @@ -9161,7 +9161,7 @@ { "name": "Parameter_Value_Alternatives_6", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", + "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel10': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", "remarks": "rule_set_000" }, { @@ -9989,7 +9989,7 @@ { "name": "Parameter_Value_Alternatives_52", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { diff --git a/component-definitions/fedora/fedora-cis_fedora-l2_server/component-definition.json b/component-definitions/fedora/fedora-cis_fedora-l2_server/component-definition.json index e9c15665d..5835c610b 100644 --- a/component-definitions/fedora/fedora-cis_fedora-l2_server/component-definition.json +++ b/component-definitions/fedora/fedora-cis_fedora-l2_server/component-definition.json @@ -3,8 +3,8 @@ "uuid": "76afcd42-7a9d-433c-b495-ef156395719c", "metadata": { "title": "Component definition for fedora", - "last-modified": "2025-09-12T15:26:09.086338+08:00", - "version": "1.0", + "last-modified": "2025-09-16T19:39:28.986783+00:00", + "version": "1.1", "oscal-version": "1.1.3" }, "components": [ @@ -131,7 +131,7 @@ { "name": "Parameter_Value_Alternatives_5", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", + "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel10': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", "remarks": "rule_set_000" }, { @@ -149,7 +149,7 @@ { "name": "Parameter_Value_Alternatives_6", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", + "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel10': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", "remarks": "rule_set_000" }, { @@ -707,7 +707,7 @@ { "name": "Parameter_Value_Alternatives_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt'}", + "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt', 'cis_rhel10': 'single|halt'}", "remarks": "rule_set_000" }, { @@ -725,7 +725,7 @@ { "name": "Parameter_Value_Alternatives_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_rhel10': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", "remarks": "rule_set_000" }, { @@ -743,7 +743,7 @@ { "name": "Parameter_Value_Alternatives_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_rhel10': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", "remarks": "rule_set_000" }, { @@ -797,7 +797,7 @@ { "name": "Parameter_Value_Alternatives_42", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt'}", + "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt', 'cis_rhel10': 'email|exec|single|halt'}", "remarks": "rule_set_000" }, { @@ -1157,7 +1157,7 @@ { "name": "Parameter_Value_Alternatives_62", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { @@ -12201,7 +12201,7 @@ { "name": "Parameter_Value_Alternatives_5", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", + "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel10': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", "remarks": "rule_set_000" }, { @@ -12219,7 +12219,7 @@ { "name": "Parameter_Value_Alternatives_6", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", + "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel10': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", "remarks": "rule_set_000" }, { @@ -12777,7 +12777,7 @@ { "name": "Parameter_Value_Alternatives_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt'}", + "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt', 'cis_rhel10': 'single|halt'}", "remarks": "rule_set_000" }, { @@ -12795,7 +12795,7 @@ { "name": "Parameter_Value_Alternatives_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_rhel10': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", "remarks": "rule_set_000" }, { @@ -12813,7 +12813,7 @@ { "name": "Parameter_Value_Alternatives_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_rhel10': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", "remarks": "rule_set_000" }, { @@ -12867,7 +12867,7 @@ { "name": "Parameter_Value_Alternatives_42", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt'}", + "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt', 'cis_rhel10': 'email|exec|single|halt'}", "remarks": "rule_set_000" }, { @@ -13227,7 +13227,7 @@ { "name": "Parameter_Value_Alternatives_62", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { diff --git a/component-definitions/fedora/fedora-cis_fedora-l2_workstation/component-definition.json b/component-definitions/fedora/fedora-cis_fedora-l2_workstation/component-definition.json index 778184293..ff8e397ec 100644 --- a/component-definitions/fedora/fedora-cis_fedora-l2_workstation/component-definition.json +++ b/component-definitions/fedora/fedora-cis_fedora-l2_workstation/component-definition.json @@ -3,8 +3,8 @@ "uuid": "5c3c7cf2-7b25-40ff-b6fe-74a80316f83a", "metadata": { "title": "Component definition for fedora", - "last-modified": "2025-09-12T15:28:53.499613+08:00", - "version": "1.0", + "last-modified": "2025-09-16T19:41:57.870121+00:00", + "version": "1.1", "oscal-version": "1.1.3" }, "components": [ @@ -131,7 +131,7 @@ { "name": "Parameter_Value_Alternatives_5", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", + "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel10': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", "remarks": "rule_set_000" }, { @@ -149,7 +149,7 @@ { "name": "Parameter_Value_Alternatives_6", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", + "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel10': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", "remarks": "rule_set_000" }, { @@ -707,7 +707,7 @@ { "name": "Parameter_Value_Alternatives_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt'}", + "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt', 'cis_rhel10': 'single|halt'}", "remarks": "rule_set_000" }, { @@ -725,7 +725,7 @@ { "name": "Parameter_Value_Alternatives_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_rhel10': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", "remarks": "rule_set_000" }, { @@ -743,7 +743,7 @@ { "name": "Parameter_Value_Alternatives_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_rhel10': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", "remarks": "rule_set_000" }, { @@ -797,7 +797,7 @@ { "name": "Parameter_Value_Alternatives_42", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt'}", + "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt', 'cis_rhel10': 'email|exec|single|halt'}", "remarks": "rule_set_000" }, { @@ -1157,7 +1157,7 @@ { "name": "Parameter_Value_Alternatives_62", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { @@ -12055,7 +12055,7 @@ { "name": "Parameter_Value_Alternatives_5", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", + "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel10': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", "remarks": "rule_set_000" }, { @@ -12073,7 +12073,7 @@ { "name": "Parameter_Value_Alternatives_6", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", + "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel10': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", "remarks": "rule_set_000" }, { @@ -12631,7 +12631,7 @@ { "name": "Parameter_Value_Alternatives_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt'}", + "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt', 'cis_rhel10': 'single|halt'}", "remarks": "rule_set_000" }, { @@ -12649,7 +12649,7 @@ { "name": "Parameter_Value_Alternatives_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_rhel10': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", "remarks": "rule_set_000" }, { @@ -12667,7 +12667,7 @@ { "name": "Parameter_Value_Alternatives_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_rhel10': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", "remarks": "rule_set_000" }, { @@ -12721,7 +12721,7 @@ { "name": "Parameter_Value_Alternatives_42", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt'}", + "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt', 'cis_rhel10': 'email|exec|single|halt'}", "remarks": "rule_set_000" }, { @@ -13081,7 +13081,7 @@ { "name": "Parameter_Value_Alternatives_62", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { diff --git a/component-definitions/rhel10/rhel10-cis_rhel10-l1_server/component-definition.json b/component-definitions/rhel10/rhel10-cis_rhel10-l1_server/component-definition.json index 420297150..1e3ee1330 100644 --- a/component-definitions/rhel10/rhel10-cis_rhel10-l1_server/component-definition.json +++ b/component-definitions/rhel10/rhel10-cis_rhel10-l1_server/component-definition.json @@ -3,8 +3,8 @@ "uuid": "c4be1cdf-5566-4add-81ec-694b72fc0910", "metadata": { "title": "Component definition for rhel10", - "last-modified": "2025-09-12T14:56:17.712050+08:00", - "version": "1.0", + "last-modified": "2025-09-16T19:15:17.421617+00:00", + "version": "1.1", "oscal-version": "1.1.3" }, "components": [ @@ -131,7 +131,7 @@ { "name": "Parameter_Value_Alternatives_5", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", + "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel10': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", "remarks": "rule_set_000" }, { @@ -149,7 +149,7 @@ { "name": "Parameter_Value_Alternatives_6", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", + "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel10': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", "remarks": "rule_set_000" }, { @@ -515,3897 +515,4131 @@ { "name": "Parameter_Id_27", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_account_disable_post_pw_expiration", + "value": "sysctl_net_ipv6_conf_default_forwarding_value", "remarks": "rule_set_000" }, { "name": "Parameter_Description_27", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The number of days to wait after a password expires, until the account will be permanently disabled.", + "value": "Toggle IPv6 default Forwarding", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_27", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'0': '0', 180: 180, 30: 30, 35: 35, 40: 40, 45: 45, 60: 60, 90: 90, 'default': 35}", + "value": "{'default': '0', 'disabled': '0', 'enabled': 1}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_28", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_maximum_age_login_defs", + "value": "var_account_disable_post_pw_expiration", "remarks": "rule_set_000" }, { "name": "Parameter_Description_28", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Maximum age of password in days", + "value": "The number of days to wait after a password expires, until the account will be permanently disabled.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_28", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{365: 365, 120: 120, 180: 180, 90: 90, 60: 60, 45: 45, 'default': 60}", + "value": "{'0': '0', 180: 180, 30: 30, 35: 35, 40: 40, 45: 45, 60: 60, 90: 90, 'default': 35}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_29", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_password_warn_age_login_defs", + "value": "var_accounts_maximum_age_login_defs", "remarks": "rule_set_000" }, { "name": "Parameter_Description_29", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The number of days' warning given before a password expires.", + "value": "Maximum age of password in days", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_29", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'0': '0', 14: 14, 10: 10, 7: 7, 'default': 7}", + "value": "{365: 365, 120: 120, 180: 180, 90: 90, 60: 60, 45: 45, 'default': 60}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_30", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_passwords_pam_faillock_deny", + "value": "var_accounts_password_warn_age_login_defs", "remarks": "rule_set_000" }, { "name": "Parameter_Description_30", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Number of failed login attempts before account lockout", + "value": "The number of days' warning given before a password expires.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_30", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{10: 10, 3: 3, 4: 4, 5: 5, 6: 6, 8: 8, 'default': 3}", + "value": "{'0': '0', 14: 14, 10: 10, 7: 7, 'default': 7}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_31", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_passwords_pam_faillock_unlock_time", + "value": "var_accounts_passwords_pam_faillock_deny", "remarks": "rule_set_000" }, { "name": "Parameter_Description_31", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Seconds before automatic unlocking or permanently locking after excessive failed logins", + "value": "Number of failed login attempts before account lockout", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_31", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{1800: 1800, 3600: 3600, 600: 600, 604800: 604800, 86400: 86400, 900: 900, 300: 300, 'default': 0, 'never': 0}", + "value": "{10: 10, 3: 3, 4: 4, 5: 5, 6: 6, 8: 8, 'default': 3}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_32", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_tmout", + "value": "var_accounts_passwords_pam_faillock_unlock_time", "remarks": "rule_set_000" }, { "name": "Parameter_Description_32", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "In an interactive shell, the value is interpreted as the number of seconds to wait for input after issuing the primary prompt. Bash terminates after waiting for that number of seconds if input does not arrive.", + "value": "Seconds before automatic unlocking or permanently locking after excessive failed logins", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_32", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'30_min': 1800, '10_min': 600, '15_min': 900, '5_min': 300, 'default': 600}", + "value": "{1800: 1800, 3600: 3600, 600: 600, 604800: 604800, 86400: 86400, 900: 900, 300: 300, 'default': 0, 'never': 0}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_33", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_user_umask", + "value": "var_accounts_tmout", "remarks": "rule_set_000" }, { "name": "Parameter_Description_33", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enter default user umask", + "value": "In an interactive shell, the value is interpreted as the number of seconds to wait for input after issuing the primary prompt. Bash terminates after waiting for that number of seconds if input does not arrive.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_33", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'007': '007', '022': '022', '027': '027', '077': '077', 'default': '027'}", + "value": "{'30_min': 1800, '10_min': 600, '15_min': 900, '5_min': 300, 'default': 600}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_34", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_authselect_profile", + "value": "var_accounts_user_umask", "remarks": "rule_set_000" }, { "name": "Parameter_Description_34", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the authselect profile to select", + "value": "Enter default user umask", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_34", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'local': 'local', 'default': 'minimal', 'minimal': 'minimal', 'sssd': 'sssd'}", + "value": "{'007': '007', '022': '022', '027': '027', '077': '077', 'default': '027'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_35", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_multiple_time_servers", + "value": "var_authselect_profile", "remarks": "rule_set_000" }, { "name": "Parameter_Description_35", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The list of vendor-approved time servers", + "value": "Specify the authselect profile to select", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_35", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'generic': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'stig': '0.us.pool.ntp.mil', 'fedora': '0.fedora.pool.ntp.org,1.fedora.pool.ntp.org,2.fedora.pool.ntp.org,3.fedora.pool.ntp.org', 'rhel': '0.rhel.pool.ntp.org,1.rhel.pool.ntp.org,2.rhel.pool.ntp.org,3.rhel.pool.ntp.org', 'ol': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'suse': '0.suse.pool.ntp.org,1.suse.pool.ntp.org,2.suse.pool.ntp.org,3.suse.pool.ntp.org', 'alinux': '0.ntp.cloud.aliyuncs.com,1.ntp.aliyun.com,2.ntp1.aliyun.com,3.ntp1.cloud.aliyuncs.com', 'amazon': '0.rhel.pool.ntp.org,1.rhel.pool.ntp.org,2.rhel.pool.ntp.org,3.rhel.pool.ntp.org', 'ubuntu': '0.ubuntu.pool.ntp.org,1.ubuntu.pool.ntp.org,2.ubuntu.pool.ntp.org,3.ubuntu.pool.ntp.org', 'almalinux': '0.almalinux.pool.ntp.org,1.almalinux.pool.ntp.org,2.almalinux.pool.ntp.org,3.almalinux.pool.ntp.org', 'debian': '0.debian.pool.ntp.org,1.debian.pool.ntp.org,2.debian.pool.ntp.org,3.debian.pool.ntp.org', 'nist': 'time.nist.gov,time-a-g.nist.gov,time-b-g.nist.gov,time-c-g.nist.gov'}", + "value": "{'local': 'local', 'default': 'minimal', 'minimal': 'minimal', 'sssd': 'sssd'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_36", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_pam_wheel_group_for_su", + "value": "var_multiple_time_servers", "remarks": "rule_set_000" }, { "name": "Parameter_Description_36", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "pam_wheel module has a parameter called group, which controls which groups can access the su command. This variable holds the valid value for the parameter.", + "value": "The list of vendor-approved time servers", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_36", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'sugroup', 'cis': 'sugroup'}", + "value": "{'default': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'generic': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'stig': '0.us.pool.ntp.mil', 'fedora': '0.fedora.pool.ntp.org,1.fedora.pool.ntp.org,2.fedora.pool.ntp.org,3.fedora.pool.ntp.org', 'rhel': '0.rhel.pool.ntp.org,1.rhel.pool.ntp.org,2.rhel.pool.ntp.org,3.rhel.pool.ntp.org', 'ol': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'suse': '0.suse.pool.ntp.org,1.suse.pool.ntp.org,2.suse.pool.ntp.org,3.suse.pool.ntp.org', 'alinux': '0.ntp.cloud.aliyuncs.com,1.ntp.aliyun.com,2.ntp1.aliyun.com,3.ntp1.cloud.aliyuncs.com', 'amazon': '0.rhel.pool.ntp.org,1.rhel.pool.ntp.org,2.rhel.pool.ntp.org,3.rhel.pool.ntp.org', 'ubuntu': '0.ubuntu.pool.ntp.org,1.ubuntu.pool.ntp.org,2.ubuntu.pool.ntp.org,3.ubuntu.pool.ntp.org', 'almalinux': '0.almalinux.pool.ntp.org,1.almalinux.pool.ntp.org,2.almalinux.pool.ntp.org,3.almalinux.pool.ntp.org', 'debian': '0.debian.pool.ntp.org,1.debian.pool.ntp.org,2.debian.pool.ntp.org,3.debian.pool.ntp.org', 'nist': 'time.nist.gov,time-a-g.nist.gov,time-b-g.nist.gov,time-c-g.nist.gov'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_hashing_algorithm", + "value": "var_pam_wheel_group_for_su", "remarks": "rule_set_000" }, { "name": "Parameter_Description_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the system default encryption algorithm for encrypting passwords. Defines the value set as ENCRYPT_METHOD in /etc/login.defs.", + "value": "pam_wheel module has a parameter called group, which controls which groups can access the su command. This variable holds the valid value for the parameter.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'SHA512', 'SHA512': 'SHA512', 'SHA256': 'SHA256', 'yescrypt': 'YESCRYPT', 'cis_ubuntu2404': 'SHA512|YESCRYPT'}", + "value": "{'default': 'sugroup', 'cis': 'sugroup'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_hashing_algorithm_pam", + "value": "var_password_hashing_algorithm", "remarks": "rule_set_000" }, { "name": "Parameter_Description_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the system default encryption algorithm for encrypting passwords. Defines the hashing algorithm to be used in pam_unix.so.", + "value": "Specify the system default encryption algorithm for encrypting passwords. Defines the value set as ENCRYPT_METHOD in /etc/login.defs.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'sha512', 'sha512': 'sha512', 'yescrypt': 'yescrypt'}", + "value": "{'default': 'SHA512', 'SHA512': 'SHA512', 'SHA256': 'SHA256', 'yescrypt': 'YESCRYPT', 'cis_ubuntu2404': 'SHA512|YESCRYPT'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_dictcheck", + "value": "var_password_hashing_algorithm_pam", "remarks": "rule_set_000" }, { "name": "Parameter_Description_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Prevent the use of dictionary words for passwords.", + "value": "Specify the system default encryption algorithm for encrypting passwords. Defines the hashing algorithm to be used in pam_unix.so.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{1: 1, 'default': 1}", + "value": "{'default': 'sha512', 'sha512': 'sha512', 'yescrypt': 'yescrypt'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_40", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_difok", + "value": "var_password_pam_dictcheck", "remarks": "rule_set_000" }, { "name": "Parameter_Description_40", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Minimum number of characters not present in old password", + "value": "Prevent the use of dictionary words for passwords.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_40", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{15: 15, 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 8: 8, 'default': 8}", + "value": "{1: 1, 'default': 1}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_41", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_maxrepeat", + "value": "var_password_pam_difok", "remarks": "rule_set_000" }, { "name": "Parameter_Description_41", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Maximum Number of Consecutive Repeating Characters in a Password", + "value": "Minimum number of characters not present in old password", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_41", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{1: 1, 2: 2, 3: 3, 'default': 3}", + "value": "{15: 15, 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 8: 8, 'default': 8}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_42", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_minclass", + "value": "var_password_pam_maxrepeat", "remarks": "rule_set_000" }, { "name": "Parameter_Description_42", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Minimum number of categories of characters that must exist in a password", + "value": "Maximum Number of Consecutive Repeating Characters in a Password", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_42", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{1: 1, 2: 2, 3: 3, 4: 4, 'default': 3}", + "value": "{1: 1, 2: 2, 3: 3, 'default': 3}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_43", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_minlen", + "value": "var_password_pam_minclass", "remarks": "rule_set_000" }, { "name": "Parameter_Description_43", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Minimum number of characters in password", + "value": "Minimum number of categories of characters that must exist in a password", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_43", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{10: 10, 12: 12, 14: 14, 15: 15, 17: 17, 18: 18, 20: 20, 6: 6, 7: 7, 8: 8, 'default': 15}", + "value": "{1: 1, 2: 2, 3: 3, 4: 4, 'default': 3}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_44", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_remember", + "value": "var_password_pam_minlen", "remarks": "rule_set_000" }, { "name": "Parameter_Description_44", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Prevent password re-use using password history lookup", + "value": "Minimum number of characters in password", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_44", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'0': '0', 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 8: 8, 9: 9, 24: 24, 'default': 5}", + "value": "{10: 10, 12: 12, 14: 14, 15: 15, 17: 17, 18: 18, 20: 20, 6: 6, 7: 7, 8: 8, 'default': 15}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_45", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_remember_control_flag", + "value": "var_password_pam_remember", "remarks": "rule_set_000" }, { "name": "Parameter_Description_45", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "'Specify the control flag required for password remember requirement. If multiple values are allowed write them separated by commas as in \"required,requisite\", for remediations the first value will be taken'", + "value": "Prevent password re-use using password history lookup", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_45", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'required': 'required', 'optional': 'optional', 'requisite': 'requisite', 'sufficient': 'sufficient', 'binding': 'binding', 'ol8': 'required,requisite', 'requisite_or_required': 'requisite,required', 'default': 'requisite'}", + "value": "{'0': '0', 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 8: 8, 9: 9, 24: 24, 'default': 5}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_46", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_postfix_inet_interfaces", + "value": "var_password_pam_remember_control_flag", "remarks": "rule_set_000" }, { "name": "Parameter_Description_46", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The setting for inet_interfaces in /etc/postfix/main.cf", + "value": "'Specify the control flag required for password remember requirement. If multiple values are allowed write them separated by commas as in \"required,requisite\", for remediations the first value will be taken'", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_46", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'loopback-only': 'loopback-only', 'default': 'loopback-only', 'localhost': 'localhost'}", + "value": "{'required': 'required', 'optional': 'optional', 'requisite': 'requisite', 'sufficient': 'sufficient', 'binding': 'binding', 'ol8': 'required,requisite', 'requisite_or_required': 'requisite,required', 'default': 'requisite'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_47", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_screensaver_lock_delay", + "value": "var_postfix_inet_interfaces", "remarks": "rule_set_000" }, { "name": "Parameter_Description_47", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Choose allowed duration (in seconds) after a screensaver becomes active before displaying an authentication prompt", + "value": "The setting for inet_interfaces in /etc/postfix/main.cf", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_47", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'10_seconds': 10, '5_seconds': 5, 'default': '0', 'immediate': '0'}", + "value": "{'loopback-only': 'loopback-only', 'default': 'loopback-only', 'localhost': 'localhost'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_48", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_selinux_policy_name", + "value": "var_screensaver_lock_delay", "remarks": "rule_set_000" }, { "name": "Parameter_Description_48", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Type of policy in use. Possible values are:
targeted - Only targeted network daemons are protected.
strict - Full SELinux protection.
mls - Multiple levels of security", + "value": "Choose allowed duration (in seconds) after a screensaver becomes active before displaying an authentication prompt", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_48", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'targeted', 'mls': 'mls', 'targeted': 'targeted'}", + "value": "{'10_seconds': 10, '5_seconds': 5, 'default': '0', 'immediate': '0'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_49", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_sshd_max_sessions", + "value": "var_selinux_policy_name", "remarks": "rule_set_000" }, { "name": "Parameter_Description_49", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the maximum number of open sessions permitted.", + "value": "Type of policy in use. Possible values are:
targeted - Only targeted network daemons are protected.
strict - Full SELinux protection.
mls - Multiple levels of security", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_49", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{10: 10, 4: 4, 3: 3, 2: 2, 1: 1, 0: 0, 'default': 10}", + "value": "{'default': 'targeted', 'mls': 'mls', 'targeted': 'targeted'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_50", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_sshd_set_keepalive", + "value": "var_sshd_max_sessions", "remarks": "rule_set_000" }, { "name": "Parameter_Description_50", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the maximum number of idle message counts before session is terminated.", + "value": "Specify the maximum number of open sessions permitted.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_50", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{10: 10, 3: 3, 5: 5, 0: 0, 1: 1, 'default': 0}", + "value": "{10: 10, 4: 4, 3: 3, 2: 2, 1: 1, 0: 0, 'default': 10}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_51", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_sshd_set_login_grace_time", + "value": "var_sshd_set_keepalive", "remarks": "rule_set_000" }, { "name": "Parameter_Description_51", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure parameters for how long the servers stays connected before the user has successfully logged in", + "value": "Specify the maximum number of idle message counts before session is terminated.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_51", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 60, 60: 60}", + "value": "{10: 10, 3: 3, 5: 5, 0: 0, 1: 1, 'default': 0}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_52", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_sshd_set_maxstartups", + "value": "var_sshd_set_login_grace_time", "remarks": "rule_set_000" }, { "name": "Parameter_Description_52", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure parameters for maximum concurrent unauthenticated connections to the SSH daemon.", + "value": "Configure parameters for how long the servers stays connected before the user has successfully logged in", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_52", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': '10:30:100', '10:30:60': '10:30:60'}", + "value": "{'default': 60, 60: 60}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_53", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_system_crypto_policy", + "value": "var_sshd_set_maxstartups", "remarks": "rule_set_000" }, { "name": "Parameter_Description_53", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the crypto policy for the system.", + "value": "Configure parameters for maximum concurrent unauthenticated connections to the SSH daemon.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_53", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': '10:30:100', '10:30:60': '10:30:60'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_54", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_user_initialization_files_regex", + "value": "var_system_crypto_policy", "remarks": "rule_set_000" }, { "name": "Parameter_Description_54", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "'A regular expression describing a list of file names for files that are sourced at login time for interactive users'", + "value": "Specify the crypto policy for the system.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_54", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Id_55", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "var_user_initialization_files_regex", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Description_55", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "'A regular expression describing a list of file names for files that are sourced at login time for interactive users'", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Value_Alternatives_55", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'default': '^(\\\\.bashrc|\\\\.zshrc|\\\\.cshrc|\\\\.profile|\\\\.bash_login|\\\\.bash_profile)$', 'all_dotfiles': '^\\\\.[\\\\w\\\\- ]+$'}", "remarks": "rule_set_000" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_usb-storage_disabled", + "value": "kernel_module_cramfs_disabled", "remarks": "rule_set_001" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Modprobe Loading of USB Storage Driver", + "value": "Disable Mounting of cramfs", "remarks": "rule_set_001" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_tmp", + "value": "kernel_module_freevxfs_disabled", "remarks": "rule_set_002" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /tmp Located On Separate Partition", + "value": "Disable Mounting of freevxfs", "remarks": "rule_set_002" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_nodev", + "value": "kernel_module_hfs_disabled", "remarks": "rule_set_003" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /tmp", + "value": "Disable Mounting of hfs", "remarks": "rule_set_003" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_nosuid", + "value": "kernel_module_hfsplus_disabled", "remarks": "rule_set_004" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /tmp", + "value": "Disable Mounting of hfsplus", "remarks": "rule_set_004" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_noexec", + "value": "kernel_module_jffs2_disabled", "remarks": "rule_set_005" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /tmp", + "value": "Disable Mounting of jffs2", "remarks": "rule_set_005" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_dev_shm", + "value": "kernel_module_firewire-core_disabled", "remarks": "rule_set_006" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /dev/shm is configured", + "value": "Disable IEEE 1394 (FireWire) Support", "remarks": "rule_set_006" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_nodev", + "value": "kernel_module_usb-storage_disabled", "remarks": "rule_set_007" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /dev/shm", + "value": "Disable Modprobe Loading of USB Storage Driver", "remarks": "rule_set_007" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_nosuid", + "value": "partition_for_tmp", "remarks": "rule_set_008" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /dev/shm", + "value": "Ensure /tmp Located On Separate Partition", "remarks": "rule_set_008" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_noexec", + "value": "mount_option_tmp_nodev", "remarks": "rule_set_009" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /dev/shm", + "value": "Add nodev Option to /tmp", "remarks": "rule_set_009" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_home_nodev", + "value": "mount_option_tmp_nosuid", "remarks": "rule_set_010" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /home", + "value": "Add nosuid Option to /tmp", "remarks": "rule_set_010" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_home_nosuid", + "value": "mount_option_tmp_noexec", "remarks": "rule_set_011" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /home", + "value": "Add noexec Option to /tmp", "remarks": "rule_set_011" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_nodev", + "value": "partition_for_dev_shm", "remarks": "rule_set_012" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /var", + "value": "Ensure /dev/shm is configured", "remarks": "rule_set_012" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_nosuid", + "value": "mount_option_dev_shm_nodev", "remarks": "rule_set_013" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /var", + "value": "Add nodev Option to /dev/shm", "remarks": "rule_set_013" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_tmp_nodev", + "value": "mount_option_dev_shm_nosuid", "remarks": "rule_set_014" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /var/tmp", + "value": "Add nosuid Option to /dev/shm", "remarks": "rule_set_014" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_tmp_nosuid", + "value": "mount_option_dev_shm_noexec", "remarks": "rule_set_015" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /var/tmp", + "value": "Add noexec Option to /dev/shm", "remarks": "rule_set_015" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_tmp_noexec", + "value": "mount_option_home_nodev", "remarks": "rule_set_016" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /var/tmp", + "value": "Add nodev Option to /home", "remarks": "rule_set_016" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_nodev", + "value": "mount_option_home_nosuid", "remarks": "rule_set_017" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /var/log", + "value": "Add nosuid Option to /home", "remarks": "rule_set_017" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_nosuid", + "value": "mount_option_var_nodev", "remarks": "rule_set_018" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /var/log", + "value": "Add nodev Option to /var", "remarks": "rule_set_018" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_noexec", + "value": "mount_option_var_nosuid", "remarks": "rule_set_019" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /var/log", + "value": "Add nosuid Option to /var", "remarks": "rule_set_019" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_audit_nodev", + "value": "mount_option_var_tmp_nodev", "remarks": "rule_set_020" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /var/log/audit", + "value": "Add nodev Option to /var/tmp", "remarks": "rule_set_020" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_audit_nosuid", + "value": "mount_option_var_tmp_nosuid", "remarks": "rule_set_021" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /var/log/audit", + "value": "Add nosuid Option to /var/tmp", "remarks": "rule_set_021" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_audit_noexec", + "value": "mount_option_var_tmp_noexec", "remarks": "rule_set_022" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /var/log/audit", + "value": "Add noexec Option to /var/tmp", "remarks": "rule_set_022" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_gpgcheck_globally_activated", + "value": "mount_option_var_log_nodev", "remarks": "rule_set_023" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure gpgcheck Enabled In Main dnf Configuration", + "value": "Add nodev Option to /var/log", "remarks": "rule_set_023" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_libselinux_installed", + "value": "mount_option_var_log_nosuid", "remarks": "rule_set_024" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install libselinux Package", + "value": "Add nosuid Option to /var/log", "remarks": "rule_set_024" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "grub2_enable_selinux", + "value": "mount_option_var_log_noexec", "remarks": "rule_set_025" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure SELinux Not Disabled in /etc/default/grub", + "value": "Add noexec Option to /var/log", "remarks": "rule_set_025" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "selinux_policytype", + "value": "mount_option_var_log_audit_nodev", "remarks": "rule_set_026" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure SELinux Policy", + "value": "Add nodev Option to /var/log/audit", "remarks": "rule_set_026" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "selinux_not_disabled", + "value": "mount_option_var_log_audit_nosuid", "remarks": "rule_set_027" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure SELinux is Not Disabled", + "value": "Add nosuid Option to /var/log/audit", "remarks": "rule_set_027" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_mcstrans_removed", + "value": "mount_option_var_log_audit_noexec", "remarks": "rule_set_028" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall mcstrans Package", + "value": "Add noexec Option to /var/log/audit", "remarks": "rule_set_028" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_setroubleshoot_removed", + "value": "ensure_gpgcheck_globally_activated", "remarks": "rule_set_029" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall setroubleshoot Package", + "value": "Ensure gpgcheck Enabled In Main dnf Configuration", "remarks": "rule_set_029" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "grub2_password", + "value": "package_libselinux_installed", "remarks": "rule_set_030" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Boot Loader Password in grub2", + "value": "Install libselinux Package", "remarks": "rule_set_030" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_grub2_cfg", + "value": "grub2_enable_selinux", "remarks": "rule_set_031" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/grub.cfg Group Ownership", + "value": "Ensure SELinux Not Disabled in /etc/default/grub", "remarks": "rule_set_031" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_grub2_cfg", + "value": "selinux_policytype", "remarks": "rule_set_032" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/grub.cfg User Ownership", + "value": "Configure SELinux Policy", "remarks": "rule_set_032" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_grub2_cfg", + "value": "selinux_not_disabled", "remarks": "rule_set_033" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/grub.cfg Permissions", + "value": "Ensure SELinux is Not Disabled", "remarks": "rule_set_033" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_user_cfg", + "value": "package_mcstrans_removed", "remarks": "rule_set_034" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/user.cfg Group Ownership", + "value": "Uninstall mcstrans Package", "remarks": "rule_set_034" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_user_cfg", + "value": "package_setroubleshoot_removed", "remarks": "rule_set_035" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/user.cfg User Ownership", + "value": "Uninstall setroubleshoot Package", "remarks": "rule_set_035" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_user_cfg", + "value": "grub2_password", "remarks": "rule_set_036" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/user.cfg Permissions", + "value": "Set Boot Loader Password in grub2", "remarks": "rule_set_036" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_kernel_randomize_va_space", + "value": "file_groupowner_grub2_cfg", "remarks": "rule_set_037" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Randomized Layout of Virtual Address Space", + "value": "Verify /boot/grub2/grub.cfg Group Ownership", "remarks": "rule_set_037" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_kernel_yama_ptrace_scope", + "value": "file_owner_grub2_cfg", "remarks": "rule_set_038" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Restrict usage of ptrace to descendant processes", + "value": "Verify /boot/grub2/grub.cfg User Ownership", "remarks": "rule_set_038" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_backtraces", + "value": "file_permissions_grub2_cfg", "remarks": "rule_set_039" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable core dump backtraces", + "value": "Verify /boot/grub2/grub.cfg Permissions", "remarks": "rule_set_039" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_storage", + "value": "file_groupowner_user_cfg", "remarks": "rule_set_040" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable storing core dump", + "value": "Verify /boot/grub2/user.cfg Group Ownership", "remarks": "rule_set_040" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_crypto_policy", + "value": "file_owner_user_cfg", "remarks": "rule_set_041" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure System Cryptography Policy", + "value": "Verify /boot/grub2/user.cfg User Ownership", "remarks": "rule_set_041" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_ssh_crypto_policy", + "value": "file_permissions_user_cfg", "remarks": "rule_set_042" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure SSH to use System Crypto Policy", + "value": "Verify /boot/grub2/user.cfg Permissions", "remarks": "rule_set_042" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "banner_etc_motd_cis", + "value": "disable_users_coredumps", "remarks": "rule_set_043" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Message Of The Day Is Configured Properly", + "value": "Disable Core Dumps for All Users", "remarks": "rule_set_043" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "banner_etc_issue_cis", + "value": "sysctl_fs_protected_hardlinks", "remarks": "rule_set_044" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Local Login Warning Banner Is Configured Properly", + "value": "Enable Kernel Parameter to Enforce DAC on Hardlinks", "remarks": "rule_set_044" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "banner_etc_issue_net_cis", + "value": "sysctl_fs_suid_dumpable", "remarks": "rule_set_045" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Remote Login Warning Banner Is Configured Properly", + "value": "Disable Core Dumps for SUID programs", "remarks": "rule_set_045" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_motd", + "value": "sysctl_kernel_dmesg_restrict", "remarks": "rule_set_046" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Ownership of Message of the Day Banner", + "value": "Restrict Access to Kernel Message Buffer", "remarks": "rule_set_046" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_motd", + "value": "sysctl_kernel_kptr_restrict", "remarks": "rule_set_047" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify ownership of Message of the Day Banner", + "value": "Restrict Exposed Kernel Pointer Addresses Access", "remarks": "rule_set_047" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_motd", + "value": "sysctl_kernel_yama_ptrace_scope", "remarks": "rule_set_048" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify permissions on Message of the Day Banner", + "value": "Restrict usage of ptrace to descendant processes", "remarks": "rule_set_048" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_issue", + "value": "sysctl_kernel_randomize_va_space", "remarks": "rule_set_049" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Ownership of System Login Banner", + "value": "Enable Randomized Layout of Virtual Address Space", "remarks": "rule_set_049" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_issue", + "value": "coredump_disable_backtraces", "remarks": "rule_set_050" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify ownership of System Login Banner", + "value": "Disable core dump backtraces", "remarks": "rule_set_050" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_issue", + "value": "coredump_disable_storage", "remarks": "rule_set_051" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify permissions on System Login Banner", + "value": "Disable storing core dump", "remarks": "rule_set_051" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_issue_net", + "value": "configure_crypto_policy", "remarks": "rule_set_052" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Ownership of System Login Banner for Remote Connections", + "value": "Configure System Cryptography Policy", "remarks": "rule_set_052" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_issue_net", + "value": "banner_etc_motd_cis", "remarks": "rule_set_053" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify ownership of System Login Banner for Remote Connections", + "value": "Ensure Message Of The Day Is Configured Properly", "remarks": "rule_set_053" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_issue_net", + "value": "banner_etc_issue_cis", "remarks": "rule_set_054" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify permissions on System Login Banner for Remote Connections", + "value": "Ensure Local Login Warning Banner Is Configured Properly", "remarks": "rule_set_054" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_banner_enabled", + "value": "banner_etc_issue_net_cis", "remarks": "rule_set_055" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable GNOME3 Login Warning Banner", + "value": "Ensure Remote Login Warning Banner Is Configured Properly", "remarks": "rule_set_055" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_login_banner_text", + "value": "file_groupowner_etc_motd", "remarks": "rule_set_056" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set the GNOME3 Login Warning Banner Text", + "value": "Verify Group Ownership of Message of the Day Banner", "remarks": "rule_set_056" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_user_list", + "value": "file_owner_etc_motd", "remarks": "rule_set_057" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable the GNOME3 Login User List", + "value": "Verify ownership of Message of the Day Banner", "remarks": "rule_set_057" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_screensaver_idle_delay", + "value": "file_permissions_etc_motd", "remarks": "rule_set_058" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set GNOME3 Screensaver Inactivity Timeout", + "value": "Verify permissions on Message of the Day Banner", "remarks": "rule_set_058" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_screensaver_lock_delay", + "value": "file_groupowner_etc_issue", "remarks": "rule_set_059" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set GNOME3 Screensaver Lock Delay After Activation Period", + "value": "Verify Group Ownership of System Login Banner", "remarks": "rule_set_059" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_session_idle_user_locks", + "value": "file_owner_etc_issue", "remarks": "rule_set_060" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Users Cannot Change GNOME3 Session Idle Settings", + "value": "Verify ownership of System Login Banner", "remarks": "rule_set_060" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_screensaver_user_locks", + "value": "file_permissions_etc_issue", "remarks": "rule_set_061" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Users Cannot Change GNOME3 Screensaver Settings", + "value": "Verify permissions on System Login Banner", "remarks": "rule_set_061" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_automount", + "value": "file_groupowner_etc_issue_net", "remarks": "rule_set_062" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable GNOME3 Automounting", + "value": "Verify Group Ownership of System Login Banner for Remote Connections", "remarks": "rule_set_062" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_automount_open", + "value": "file_owner_etc_issue_net", "remarks": "rule_set_063" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable GNOME3 Automount Opening", + "value": "Verify ownership of System Login Banner for Remote Connections", "remarks": "rule_set_063" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_autorun", + "value": "file_permissions_etc_issue_net", "remarks": "rule_set_064" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable GNOME3 Automount running", + "value": "Verify permissions on System Login Banner for Remote Connections", "remarks": "rule_set_064" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_autofs_disabled", + "value": "dconf_gnome_banner_enabled", "remarks": "rule_set_065" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable the Automounter", + "value": "Enable GNOME3 Login Warning Banner", "remarks": "rule_set_065" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_avahi-daemon_disabled", + "value": "dconf_gnome_login_banner_text", "remarks": "rule_set_066" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Avahi Server Software", + "value": "Set the GNOME3 Login Warning Banner Text", "remarks": "rule_set_066" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_kea_removed", + "value": "dconf_gnome_disable_user_list", "remarks": "rule_set_067" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall kea Package", + "value": "Disable the GNOME3 Login User List", "remarks": "rule_set_067" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_bind_removed", + "value": "dconf_gnome_screensaver_idle_delay", "remarks": "rule_set_068" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall bind Package", + "value": "Set GNOME3 Screensaver Inactivity Timeout", "remarks": "rule_set_068" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_dnsmasq_removed", + "value": "dconf_gnome_screensaver_lock_delay", "remarks": "rule_set_069" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall dnsmasq Package", + "value": "Set GNOME3 Screensaver Lock Delay After Activation Period", "remarks": "rule_set_069" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_samba_removed", + "value": "dconf_gnome_session_idle_user_locks", "remarks": "rule_set_070" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall Samba Package", + "value": "Ensure Users Cannot Change GNOME3 Session Idle Settings", "remarks": "rule_set_070" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_vsftpd_removed", + "value": "dconf_gnome_screensaver_user_locks", "remarks": "rule_set_071" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall vsftpd Package", + "value": "Ensure Users Cannot Change GNOME3 Screensaver Settings", "remarks": "rule_set_071" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_dovecot_removed", + "value": "dconf_gnome_disable_automount", "remarks": "rule_set_072" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall dovecot Package", + "value": "Disable GNOME3 Automounting", "remarks": "rule_set_072" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_cyrus-imapd_removed", + "value": "dconf_gnome_disable_automount_open", "remarks": "rule_set_073" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall cyrus-imapd Package", + "value": "Disable GNOME3 Automount Opening", "remarks": "rule_set_073" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_nfs_disabled", + "value": "dconf_gnome_disable_autorun", "remarks": "rule_set_074" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Network File System (nfs)", + "value": "Disable GNOME3 Automount running", "remarks": "rule_set_074" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_cups_disabled", + "value": "service_autofs_disabled", "remarks": "rule_set_075" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable the CUPS Service", + "value": "Disable the Automounter", "remarks": "rule_set_075" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_rpcbind_disabled", + "value": "service_avahi-daemon_disabled", "remarks": "rule_set_076" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable rpcbind Service", + "value": "Disable Avahi Server Software", "remarks": "rule_set_076" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_rsync_removed", + "value": "package_kea_removed", "remarks": "rule_set_077" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall rsync Package", + "value": "Uninstall kea Package", "remarks": "rule_set_077" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_net-snmp_removed", + "value": "package_bind_removed", "remarks": "rule_set_078" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall net-snmp Package", + "value": "Uninstall bind Package", "remarks": "rule_set_078" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_telnet-server_removed", + "value": "package_dnsmasq_removed", "remarks": "rule_set_079" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall telnet-server Package", + "value": "Uninstall dnsmasq Package", "remarks": "rule_set_079" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_tftp-server_removed", + "value": "package_vsftpd_removed", "remarks": "rule_set_080" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall tftp-server Package", + "value": "Uninstall vsftpd Package", "remarks": "rule_set_080" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_squid_removed", + "value": "package_dovecot_removed", "remarks": "rule_set_081" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall squid Package", + "value": "Uninstall dovecot Package", "remarks": "rule_set_081" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_httpd_removed", + "value": "package_cyrus-imapd_removed", "remarks": "rule_set_082" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall httpd Package", + "value": "Uninstall cyrus-imapd Package", "remarks": "rule_set_082" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_nginx_removed", + "value": "service_nfs_disabled", "remarks": "rule_set_083" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall nginx Package", + "value": "Disable Network File System (nfs)", "remarks": "rule_set_083" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "postfix_network_listening_disabled", + "value": "service_cups_disabled", "remarks": "rule_set_084" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Postfix Network Listening", + "value": "Disable the CUPS Service", "remarks": "rule_set_084" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "has_nonlocal_mta", + "value": "service_rpcbind_disabled", "remarks": "rule_set_085" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Mail Transfer Agent is not Listening on any non-loopback Address", + "value": "Disable rpcbind Service", "remarks": "rule_set_085" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_ftp_removed", + "value": "package_rsync_removed", "remarks": "rule_set_086" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Remove ftp Package", + "value": "Uninstall rsync Package", "remarks": "rule_set_086" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_telnet_removed", + "value": "package_samba_removed", "remarks": "rule_set_087" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Remove telnet Clients", + "value": "Uninstall Samba Package", "remarks": "rule_set_087" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_tftp_removed", + "value": "package_net-snmp_removed", "remarks": "rule_set_088" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Remove tftp Daemon", + "value": "Uninstall net-snmp Package", "remarks": "rule_set_088" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "chronyd_specify_remote_server", + "value": "package_telnet-server_removed", "remarks": "rule_set_089" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "A remote time server for Chrony is configured", + "value": "Uninstall telnet-server Package", "remarks": "rule_set_089" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "chronyd_run_as_chrony_user", + "value": "package_tftp-server_removed", "remarks": "rule_set_090" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that chronyd is running under chrony user account", + "value": "Uninstall tftp-server Package", "remarks": "rule_set_090" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_cron_installed", + "value": "package_squid_removed", "remarks": "rule_set_091" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install the cron service", + "value": "Uninstall squid Package", "remarks": "rule_set_091" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_crond_enabled", + "value": "package_httpd_removed", "remarks": "rule_set_092" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable cron Service", + "value": "Uninstall httpd Package", "remarks": "rule_set_092" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_crontab", + "value": "package_nginx_removed", "remarks": "rule_set_093" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns Crontab", + "value": "Uninstall nginx Package", "remarks": "rule_set_093" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_crontab", + "value": "postfix_network_listening_disabled", "remarks": "rule_set_094" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on crontab", + "value": "Disable Postfix Network Listening", "remarks": "rule_set_094" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_crontab", + "value": "has_nonlocal_mta", "remarks": "rule_set_095" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on crontab", + "value": "Ensure Mail Transfer Agent is not Listening on any non-loopback Address", "remarks": "rule_set_095" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_hourly", + "value": "package_ftp_removed", "remarks": "rule_set_096" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns cron.hourly", + "value": "Remove ftp Package", "remarks": "rule_set_096" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_hourly", + "value": "package_telnet_removed", "remarks": "rule_set_097" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on cron.hourly", + "value": "Remove telnet Clients", "remarks": "rule_set_097" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_hourly", + "value": "package_tftp_removed", "remarks": "rule_set_098" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on cron.hourly", + "value": "Remove tftp Daemon", "remarks": "rule_set_098" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_daily", + "value": "chronyd_specify_remote_server", "remarks": "rule_set_099" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns cron.daily", + "value": "A remote time server for Chrony is configured", "remarks": "rule_set_099" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_daily", + "value": "chronyd_run_as_chrony_user", "remarks": "rule_set_100" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on cron.daily", + "value": "Ensure that chronyd is running under chrony user account", "remarks": "rule_set_100" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_daily", + "value": "package_cron_installed", "remarks": "rule_set_101" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on cron.daily", + "value": "Install the cron service", "remarks": "rule_set_101" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_weekly", + "value": "service_crond_enabled", "remarks": "rule_set_102" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns cron.weekly", + "value": "Enable cron Service", "remarks": "rule_set_102" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_weekly", + "value": "file_groupowner_crontab", "remarks": "rule_set_103" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on cron.weekly", + "value": "Verify Group Who Owns Crontab", "remarks": "rule_set_103" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_weekly", + "value": "file_owner_crontab", "remarks": "rule_set_104" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on cron.weekly", + "value": "Verify Owner on crontab", "remarks": "rule_set_104" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_monthly", + "value": "file_permissions_crontab", "remarks": "rule_set_105" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns cron.monthly", + "value": "Verify Permissions on crontab", "remarks": "rule_set_105" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_monthly", + "value": "file_groupowner_cron_hourly", "remarks": "rule_set_106" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on cron.monthly", + "value": "Verify Group Who Owns cron.hourly", "remarks": "rule_set_106" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_monthly", + "value": "file_owner_cron_hourly", "remarks": "rule_set_107" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on cron.monthly", + "value": "Verify Owner on cron.hourly", "remarks": "rule_set_107" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_d", + "value": "file_permissions_cron_hourly", "remarks": "rule_set_108" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns cron.d", + "value": "Verify Permissions on cron.hourly", "remarks": "rule_set_108" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_d", + "value": "file_groupowner_cron_daily", "remarks": "rule_set_109" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on cron.d", + "value": "Verify Group Who Owns cron.daily", "remarks": "rule_set_109" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_d", + "value": "file_owner_cron_daily", "remarks": "rule_set_110" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on cron.d", + "value": "Verify Owner on cron.daily", "remarks": "rule_set_110" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_cron_deny_not_exist", + "value": "file_permissions_cron_daily", "remarks": "rule_set_111" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that /etc/cron.deny does not exist", + "value": "Verify Permissions on cron.daily", "remarks": "rule_set_111" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_cron_allow_exists", + "value": "file_groupowner_cron_weekly", "remarks": "rule_set_112" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that /etc/cron.allow exists", + "value": "Verify Group Who Owns cron.weekly", "remarks": "rule_set_112" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_allow", + "value": "file_owner_cron_weekly", "remarks": "rule_set_113" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns /etc/cron.allow file", + "value": "Verify Owner on cron.weekly", "remarks": "rule_set_113" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_allow", + "value": "file_permissions_cron_weekly", "remarks": "rule_set_114" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns /etc/cron.allow file", + "value": "Verify Permissions on cron.weekly", "remarks": "rule_set_114" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_allow", + "value": "file_groupowner_cron_monthly", "remarks": "rule_set_115" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on /etc/cron.allow file", + "value": "Verify Group Who Owns cron.monthly", "remarks": "rule_set_115" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_at_deny_not_exist", + "value": "file_owner_cron_monthly", "remarks": "rule_set_116" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that /etc/at.deny does not exist", + "value": "Verify Owner on cron.monthly", "remarks": "rule_set_116" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_at_allow", + "value": "file_permissions_cron_monthly", "remarks": "rule_set_117" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns /etc/at.allow file", + "value": "Verify Permissions on cron.monthly", "remarks": "rule_set_117" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_at_allow", + "value": "file_groupowner_cron_d", "remarks": "rule_set_118" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns /etc/at.allow file", + "value": "Verify Group Who Owns cron.d", "remarks": "rule_set_118" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_at_allow", + "value": "file_owner_cron_d", "remarks": "rule_set_119" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on /etc/at.allow file", + "value": "Verify Owner on cron.d", "remarks": "rule_set_119" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "wireless_disable_interfaces", + "value": "file_permissions_cron_d", "remarks": "rule_set_120" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Deactivate Wireless Network Interfaces", + "value": "Verify Permissions on cron.d", "remarks": "rule_set_120" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_bluetooth_disabled", + "value": "file_cron_deny_not_exist", "remarks": "rule_set_121" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Bluetooth Service", + "value": "Ensure that /etc/cron.deny does not exist", "remarks": "rule_set_121" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_ip_forward", + "value": "file_cron_allow_exists", "remarks": "rule_set_122" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for IP Forwarding on IPv4 Interfaces", + "value": "Ensure that /etc/cron.allow exists", "remarks": "rule_set_122" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_forwarding", + "value": "file_groupowner_cron_allow", "remarks": "rule_set_123" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for IPv6 Forwarding", + "value": "Verify Group Who Owns /etc/cron.allow file", "remarks": "rule_set_123" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_send_redirects", + "value": "file_owner_cron_allow", "remarks": "rule_set_124" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces", + "value": "Verify User Who Owns /etc/cron.allow file", "remarks": "rule_set_124" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_send_redirects", + "value": "file_permissions_cron_allow", "remarks": "rule_set_125" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces by Default", + "value": "Verify Permissions on /etc/cron.allow file", "remarks": "rule_set_125" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses", + "value": "file_at_deny_not_exist", "remarks": "rule_set_126" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Ignore Bogus ICMP Error Responses on IPv4 Interfaces", + "value": "Ensure that /etc/at.deny does not exist", "remarks": "rule_set_126" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts", + "value": "file_groupowner_at_allow", "remarks": "rule_set_127" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Ignore ICMP Broadcast Echo Requests on IPv4 Interfaces", + "value": "Verify Group Who Owns /etc/at.allow file", "remarks": "rule_set_127" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_accept_redirects", + "value": "file_owner_at_allow", "remarks": "rule_set_128" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Accepting ICMP Redirects for All IPv4 Interfaces", + "value": "Verify User Who Owns /etc/at.allow file", "remarks": "rule_set_128" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_accept_redirects", + "value": "file_permissions_at_allow", "remarks": "rule_set_129" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 Interfaces", + "value": "Verify Permissions on /etc/at.allow file", "remarks": "rule_set_129" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_redirects", + "value": "wireless_disable_interfaces", "remarks": "rule_set_130" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Accepting ICMP Redirects for All IPv6 Interfaces", + "value": "Deactivate Wireless Network Interfaces", "remarks": "rule_set_130" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_redirects", + "value": "service_bluetooth_disabled", "remarks": "rule_set_131" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces", + "value": "Disable Bluetooth Service", "remarks": "rule_set_131" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_secure_redirects", + "value": "kernel_module_atm_disabled", "remarks": "rule_set_132" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces", + "value": "Disable ATM Support", "remarks": "rule_set_132" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_secure_redirects", + "value": "kernel_module_can_disabled", "remarks": "rule_set_133" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Kernel Parameter for Accepting Secure Redirects By Default", + "value": "Disable CAN Support", "remarks": "rule_set_133" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_rp_filter", + "value": "kernel_module_dccp_disabled", "remarks": "rule_set_134" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces", + "value": "Disable DCCP Support", "remarks": "rule_set_134" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_rp_filter", + "value": "kernel_module_tipc_disabled", "remarks": "rule_set_135" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces by Default", + "value": "Disable TIPC Support", "remarks": "rule_set_135" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_accept_source_route", + "value": "kernel_module_rds_disabled", "remarks": "rule_set_136" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces", + "value": "Disable RDS Support", "remarks": "rule_set_136" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_accept_source_route", + "value": "kernel_module_sctp_disabled", "remarks": "rule_set_137" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces by Default", + "value": "Disable SCTP Support", "remarks": "rule_set_137" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_source_route", + "value": "sysctl_net_ipv4_conf_all_forwarding", "remarks": "rule_set_138" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces", + "value": "Disable Kernel Parameter for IPv4 Forwarding on all IPv4 Interfaces", "remarks": "rule_set_138" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_source_route", + "value": "sysctl_net_ipv4_conf_all_send_redirects", "remarks": "rule_set_139" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces by Default", + "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces", "remarks": "rule_set_139" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_log_martians", + "value": "sysctl_net_ipv4_conf_default_send_redirects", "remarks": "rule_set_140" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces", + "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces by Default", "remarks": "rule_set_140" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_log_martians", + "value": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses", "remarks": "rule_set_141" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Paremeter to Log Martian Packets on all IPv4 Interfaces by Default", + "value": "Enable Kernel Parameter to Ignore Bogus ICMP Error Responses on IPv4 Interfaces", "remarks": "rule_set_141" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_tcp_syncookies", + "value": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts", "remarks": "rule_set_142" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces", + "value": "Enable Kernel Parameter to Ignore ICMP Broadcast Echo Requests on IPv4 Interfaces", "remarks": "rule_set_142" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_ra", + "value": "sysctl_net_ipv4_conf_all_accept_redirects", "remarks": "rule_set_143" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Accepting Router Advertisements on All IPv6 Interfaces", + "value": "Disable Accepting ICMP Redirects for All IPv4 Interfaces", "remarks": "rule_set_143" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_ra", + "value": "sysctl_net_ipv4_conf_default_accept_redirects", "remarks": "rule_set_144" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Accepting Router Advertisements on all IPv6 Interfaces by Default", + "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 Interfaces", "remarks": "rule_set_144" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_nftables_installed", + "value": "sysctl_net_ipv4_conf_all_secure_redirects", "remarks": "rule_set_145" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install nftables Package", + "value": "Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces", "remarks": "rule_set_145" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_firewalld_enabled", + "value": "sysctl_net_ipv4_conf_default_secure_redirects", "remarks": "rule_set_146" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify firewalld Enabled", + "value": "Configure Kernel Parameter for Accepting Secure Redirects By Default", "remarks": "rule_set_146" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_firewalld_installed", + "value": "sysctl_net_ipv4_conf_all_rp_filter", "remarks": "rule_set_147" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install firewalld Package", + "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces", "remarks": "rule_set_147" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_nftables_disabled", + "value": "sysctl_net_ipv4_conf_default_rp_filter", "remarks": "rule_set_148" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify nftables Service is Disabled", + "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces by Default", "remarks": "rule_set_148" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "firewalld_loopback_traffic_trusted", + "value": "sysctl_net_ipv4_conf_all_accept_source_route", "remarks": "rule_set_149" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Firewalld to Trust Loopback Traffic", + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces", "remarks": "rule_set_149" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "firewalld_loopback_traffic_restricted", + "value": "sysctl_net_ipv4_conf_default_accept_source_route", "remarks": "rule_set_150" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Firewalld to Restrict Loopback Traffic", + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces by Default", "remarks": "rule_set_150" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_sshd_config", + "value": "sysctl_net_ipv4_conf_all_log_martians", "remarks": "rule_set_151" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns SSH Server config file", + "value": "Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces", "remarks": "rule_set_151" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_sshd_config", + "value": "sysctl_net_ipv4_conf_default_log_martians", "remarks": "rule_set_152" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on SSH Server config file", + "value": "Enable Kernel Paremeter to Log Martian Packets on all IPv4 Interfaces by Default", "remarks": "rule_set_152" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_config", + "value": "sysctl_net_ipv4_tcp_syncookies", "remarks": "rule_set_153" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on SSH Server config file", + "value": "Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces", "remarks": "rule_set_153" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_private_key", + "value": "sysctl_net_ipv6_conf_all_forwarding", "remarks": "rule_set_154" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on SSH Server Private *_key Key Files", + "value": "Disable Kernel Parameter for IPv6 Forwarding", "remarks": "rule_set_154" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_private_key", + "value": "sysctl_net_ipv6_conf_default_forwarding", "remarks": "rule_set_155" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Ownership on SSH Server Private *_key Key Files", + "value": "Disable Kernel Parameter for IPv6 Forwarding by default", "remarks": "rule_set_155" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_sshd_private_key", + "value": "sysctl_net_ipv6_conf_all_accept_redirects", "remarks": "rule_set_156" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Ownership on SSH Server Private *_key Key Files", + "value": "Disable Accepting ICMP Redirects for All IPv6 Interfaces", "remarks": "rule_set_156" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_pub_key", + "value": "sysctl_net_ipv6_conf_default_accept_redirects", "remarks": "rule_set_157" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on SSH Server Public *.pub Key Files", + "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces", "remarks": "rule_set_157" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_pub_key", + "value": "sysctl_net_ipv6_conf_all_accept_source_route", "remarks": "rule_set_158" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Ownership on SSH Server Public *.pub Key Files", + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces", "remarks": "rule_set_158" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_sshd_pub_key", + "value": "sysctl_net_ipv6_conf_default_accept_source_route", "remarks": "rule_set_159" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Ownership on SSH Server Public *.pub Key Files", + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces by Default", "remarks": "rule_set_159" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_kex", + "value": "sysctl_net_ipv6_conf_all_accept_ra", "remarks": "rule_set_160" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Use Only Strong Key Exchange algorithms", + "value": "Configure Accepting Router Advertisements on All IPv6 Interfaces", "remarks": "rule_set_160" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_macs", + "value": "sysctl_net_ipv6_conf_default_accept_ra", "remarks": "rule_set_161" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Use Only Strong MACs", + "value": "Disable Accepting Router Advertisements on all IPv6 Interfaces by Default", "remarks": "rule_set_161" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_limit_user_access", + "value": "package_firewalld_installed", "remarks": "rule_set_162" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Limit Users' SSH Access", + "value": "Install firewalld Package", "remarks": "rule_set_162" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_enable_warning_banner_net", + "value": "service_firewalld_enabled", "remarks": "rule_set_163" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable SSH Warning Banner", + "value": "Verify firewalld Enabled", "remarks": "rule_set_163" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_idle_timeout", + "value": "firewalld_loopback_traffic_trusted", "remarks": "rule_set_164" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set SSH Client Alive Interval", + "value": "Configure Firewalld to Trust Loopback Traffic", "remarks": "rule_set_164" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_keepalive", + "value": "firewalld_loopback_traffic_restricted", "remarks": "rule_set_165" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set SSH Client Alive Count Max", + "value": "Configure Firewalld to Restrict Loopback Traffic", "remarks": "rule_set_165" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "disable_host_auth", + "value": "file_groupowner_sshd_config", "remarks": "rule_set_166" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Host-Based Authentication", + "value": "Verify Group Who Owns SSH Server config file", "remarks": "rule_set_166" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_rhosts", + "value": "file_owner_sshd_config", "remarks": "rule_set_167" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable SSH Support for .rhosts Files", + "value": "Verify Owner on SSH Server config file", "remarks": "rule_set_167" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_login_grace_time", + "value": "file_permissions_sshd_config", "remarks": "rule_set_168" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure SSH LoginGraceTime is configured", + "value": "Verify Permissions on SSH Server config file", "remarks": "rule_set_168" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_loglevel_verbose", + "value": "file_groupownership_sshd_private_key", "remarks": "rule_set_169" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set SSH Daemon LogLevel to VERBOSE", + "value": "Verify Group Ownership on SSH Server Private *_key Key Files", "remarks": "rule_set_169" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_max_auth_tries", + "value": "file_ownership_sshd_private_key", "remarks": "rule_set_170" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set SSH authentication attempt limit", + "value": "Verify Ownership on SSH Server Private *_key Key Files", "remarks": "rule_set_170" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_maxstartups", + "value": "file_permissions_sshd_private_key", "remarks": "rule_set_171" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure SSH MaxStartups is configured", + "value": "Verify Permissions on SSH Server Private *_key Key Files", "remarks": "rule_set_171" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_max_sessions", + "value": "file_groupownership_sshd_pub_key", "remarks": "rule_set_172" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set SSH MaxSessions limit", + "value": "Verify Group Ownership on SSH Server Public *.pub Key Files", "remarks": "rule_set_172" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_empty_passwords", + "value": "file_ownership_sshd_pub_key", "remarks": "rule_set_173" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable SSH Access via Empty Passwords", + "value": "Verify Ownership on SSH Server Public *.pub Key Files", "remarks": "rule_set_173" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_root_login", + "value": "file_permissions_sshd_pub_key", "remarks": "rule_set_174" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable SSH Root Login", + "value": "Verify Permissions on SSH Server Public *.pub Key Files", "remarks": "rule_set_174" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_do_not_permit_user_env", + "value": "sshd_limit_user_access", "remarks": "rule_set_175" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Do Not Allow SSH Environment Options", + "value": "Limit Users' SSH Access", "remarks": "rule_set_175" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_enable_pam", + "value": "sshd_enable_warning_banner_net", "remarks": "rule_set_176" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable PAM", + "value": "Enable SSH Warning Banner", "remarks": "rule_set_176" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_sudo_installed", + "value": "sshd_set_idle_timeout", "remarks": "rule_set_177" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install sudo Package", + "value": "Set SSH Client Alive Interval", "remarks": "rule_set_177" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_add_use_pty", + "value": "sshd_set_keepalive", "remarks": "rule_set_178" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Only Users Logged In To Real tty Can Execute Sudo - sudo use_pty", + "value": "Set SSH Client Alive Count Max", "remarks": "rule_set_178" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_custom_logfile", + "value": "disable_host_auth", "remarks": "rule_set_179" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Sudo Logfile Exists - sudo logfile", + "value": "Disable Host-Based Authentication", "remarks": "rule_set_179" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_require_reauthentication", + "value": "sshd_disable_rhosts", "remarks": "rule_set_180" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Require Re-Authentication When Using the sudo Command", + "value": "Disable SSH Support for .rhosts Files", "remarks": "rule_set_180" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "use_pam_wheel_group_for_su", + "value": "sshd_use_strong_kex", "remarks": "rule_set_181" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enforce Usage of pam_wheel with Group Parameter for su Authentication", + "value": "Use Only Strong Key Exchange algorithms", "remarks": "rule_set_181" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_pam_wheel_group_empty", + "value": "sshd_set_login_grace_time", "remarks": "rule_set_182" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure the Group Used by pam_wheel.so Module Exists on System and is Empty", + "value": "Ensure SSH LoginGraceTime is configured", "remarks": "rule_set_182" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_pam_pwquality_installed", + "value": "sshd_set_loglevel_verbose", "remarks": "rule_set_183" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install pam_pwquality Package", + "value": "Set SSH Daemon LogLevel to VERBOSE", "remarks": "rule_set_183" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_password_auth", + "value": "sshd_use_strong_macs", "remarks": "rule_set_184" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth File.", + "value": "Use Only Strong MACs", "remarks": "rule_set_184" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_system_auth", + "value": "sshd_set_max_auth_tries", "remarks": "rule_set_185" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth File.", + "value": "Set SSH authentication attempt limit", "remarks": "rule_set_185" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_deny", + "value": "sshd_set_maxstartups", "remarks": "rule_set_186" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Lock Accounts After Failed Password Attempts", + "value": "Ensure SSH MaxStartups is configured", "remarks": "rule_set_186" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_unlock_time", + "value": "sshd_set_max_sessions", "remarks": "rule_set_187" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Lockout Time for Failed Password Attempts", + "value": "Set SSH MaxSessions limit", "remarks": "rule_set_187" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_difok", + "value": "sshd_disable_empty_passwords", "remarks": "rule_set_188" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure PAM Enforces Password Requirements - Minimum Different Characters", + "value": "Disable SSH Access via Empty Passwords", "remarks": "rule_set_188" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_minlen", + "value": "sshd_disable_root_login", "remarks": "rule_set_189" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure PAM Enforces Password Requirements - Minimum Length", + "value": "Disable SSH Root Login", "remarks": "rule_set_189" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_minclass", + "value": "sshd_do_not_permit_user_env", "remarks": "rule_set_190" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure PAM Enforces Password Requirements - Minimum Different Categories", + "value": "Do Not Allow SSH Environment Options", "remarks": "rule_set_190" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_maxrepeat", + "value": "sshd_enable_pam", "remarks": "rule_set_191" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Password Maximum Consecutive Repeating Characters", + "value": "Enable PAM", "remarks": "rule_set_191" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_dictcheck", + "value": "package_sudo_installed", "remarks": "rule_set_192" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure PAM Enforces Password Requirements - Prevent the Use of Dictionary Words", + "value": "Install sudo Package", "remarks": "rule_set_192" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_enforce_root", + "value": "sudo_add_use_pty", "remarks": "rule_set_193" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure PAM Enforces Password Requirements - Enforce for root User", + "value": "Ensure Only Users Logged In To Real tty Can Execute Sudo - sudo use_pty", "remarks": "rule_set_193" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_pwhistory_remember_password_auth", + "value": "sudo_custom_logfile", "remarks": "rule_set_194" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Limit Password Reuse: password-auth", + "value": "Ensure Sudo Logfile Exists - sudo logfile", "remarks": "rule_set_194" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_pwhistory_remember_system_auth", + "value": "sudo_require_authentication", "remarks": "rule_set_195" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Limit Password Reuse: system-auth", + "value": "Ensure Users Re-Authenticate for Privilege Escalation - sudo", "remarks": "rule_set_195" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_empty_passwords", + "value": "sudo_require_reauthentication", "remarks": "rule_set_196" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Prevent Login to Accounts With Empty Password", + "value": "Require Re-Authentication When Using the sudo Command", "remarks": "rule_set_196" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_systemauth", + "value": "use_pam_wheel_group_for_su", "remarks": "rule_set_197" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set PAM''s Password Hashing Algorithm", + "value": "Enforce Usage of pam_wheel with Group Parameter for su Authentication", "remarks": "rule_set_197" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_passwordauth", + "value": "ensure_pam_wheel_group_empty", "remarks": "rule_set_198" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set PAM''s Password Hashing Algorithm - password-auth", + "value": "Ensure the Group Used by pam_wheel.so Module Exists on System and is Empty", "remarks": "rule_set_198" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_maximum_age_login_defs", + "value": "account_password_pam_faillock_password_auth", "remarks": "rule_set_199" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Password Maximum Age", + "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth File.", "remarks": "rule_set_199" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_set_max_life_existing", + "value": "account_password_pam_faillock_system_auth", "remarks": "rule_set_200" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Existing Passwords Maximum Age", + "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth File.", "remarks": "rule_set_200" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_warn_age_login_defs", + "value": "package_pam_pwquality_installed", "remarks": "rule_set_201" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Password Warning Age", + "value": "Install pam_pwquality Package", "remarks": "rule_set_201" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_set_warn_age_existing", + "value": "accounts_passwords_pam_faillock_deny", "remarks": "rule_set_202" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Existing Passwords Warning Age", + "value": "Lock Accounts After Failed Password Attempts", "remarks": "rule_set_202" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_libuserconf", + "value": "accounts_passwords_pam_faillock_unlock_time", "remarks": "rule_set_203" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Password Hashing Algorithm in /etc/libuser.conf", + "value": "Set Lockout Time for Failed Password Attempts", "remarks": "rule_set_203" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_logindefs", + "value": "accounts_password_pam_difok", "remarks": "rule_set_204" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Password Hashing Algorithm in /etc/login.defs", + "value": "Ensure PAM Enforces Password Requirements - Minimum Different Characters", "remarks": "rule_set_204" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_disable_post_pw_expiration", + "value": "accounts_password_pam_minlen", "remarks": "rule_set_205" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Account Expiration Following Inactivity", + "value": "Ensure PAM Enforces Password Requirements - Minimum Length", "remarks": "rule_set_205" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_set_post_pw_existing", + "value": "accounts_password_pam_minclass", "remarks": "rule_set_206" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set existing passwords a period of inactivity before they been locked", + "value": "Ensure PAM Enforces Password Requirements - Minimum Different Categories", "remarks": "rule_set_206" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_last_change_is_in_past", + "value": "accounts_password_pam_maxrepeat", "remarks": "rule_set_207" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure all users last password change date is in the past", + "value": "Set Password Maximum Consecutive Repeating Characters", "remarks": "rule_set_207" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_no_uid_except_zero", + "value": "accounts_password_pam_dictcheck", "remarks": "rule_set_208" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Only Root Has UID 0", + "value": "Ensure PAM Enforces Password Requirements - Prevent the Use of Dictionary Words", "remarks": "rule_set_208" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_root_gid_zero", + "value": "accounts_password_pam_enforce_root", "remarks": "rule_set_209" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Root Has A Primary GID 0", + "value": "Ensure PAM Enforces Password Requirements - Enforce for root User", "remarks": "rule_set_209" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_root_password_configured", + "value": "accounts_password_pam_pwhistory_remember_password_auth", "remarks": "rule_set_210" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Authentication Required for Single User Mode", + "value": "Limit Password Reuse: password-auth", "remarks": "rule_set_210" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_root_path_dirs_no_write", + "value": "accounts_password_pam_pwhistory_remember_system_auth", "remarks": "rule_set_211" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that Root's Path Does Not Include World or Group-Writable Directories", + "value": "Limit Password Reuse: system-auth", "remarks": "rule_set_211" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "root_path_no_dot", + "value": "no_empty_passwords", "remarks": "rule_set_212" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that Root's Path Does Not Include Relative Paths or Null Directories", + "value": "Prevent Login to Accounts With Empty Password", "remarks": "rule_set_212" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_password_auth_for_systemaccounts", + "value": "set_password_hashing_algorithm_systemauth", "remarks": "rule_set_213" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that System Accounts Are Locked", + "value": "Set PAM''s Password Hashing Algorithm", "remarks": "rule_set_213" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_shelllogin_for_systemaccounts", + "value": "set_password_hashing_algorithm_passwordauth", "remarks": "rule_set_214" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that System Accounts Do Not Run a Shell Upon Login", + "value": "Set PAM''s Password Hashing Algorithm - password-auth", "remarks": "rule_set_214" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_tmout", + "value": "accounts_maximum_age_login_defs", "remarks": "rule_set_215" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Interactive Session Timeout", + "value": "Set Password Maximum Age", "remarks": "rule_set_215" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_umask_etc_bashrc", + "value": "accounts_password_set_max_life_existing", "remarks": "rule_set_216" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure the Default Bash Umask is Set Correctly", + "value": "Set Existing Passwords Maximum Age", "remarks": "rule_set_216" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_umask_etc_login_defs", + "value": "accounts_password_warn_age_login_defs", "remarks": "rule_set_217" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure the Default Umask is Set Correctly in login.defs", + "value": "Set Password Warning Age", "remarks": "rule_set_217" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_umask_etc_profile", + "value": "accounts_password_set_warn_age_existing", "remarks": "rule_set_218" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure the Default Umask is Set Correctly in /etc/profile", + "value": "Set Existing Passwords Warning Age", "remarks": "rule_set_218" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_aide_installed", + "value": "set_password_hashing_algorithm_libuserconf", "remarks": "rule_set_219" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install AIDE", + "value": "Set Password Hashing Algorithm in /etc/libuser.conf", "remarks": "rule_set_219" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "aide_build_database", + "value": "set_password_hashing_algorithm_logindefs", "remarks": "rule_set_220" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Build and Test AIDE Database", + "value": "Set Password Hashing Algorithm in /etc/login.defs", "remarks": "rule_set_220" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "aide_periodic_cron_checking", + "value": "account_disable_post_pw_expiration", "remarks": "rule_set_221" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Periodic Execution of AIDE", + "value": "Set Account Expiration Following Inactivity", "remarks": "rule_set_221" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "aide_check_audit_tools", + "value": "accounts_set_post_pw_existing", "remarks": "rule_set_222" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure AIDE to Verify the Audit Tools", + "value": "Set existing passwords a period of inactivity before they been locked", "remarks": "rule_set_222" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_systemd-journald_enabled", + "value": "accounts_password_last_change_is_in_past", "remarks": "rule_set_223" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable systemd-journald Service", + "value": "Ensure all users last password change date is in the past", "remarks": "rule_set_223" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_systemd-journal-remote_installed", + "value": "accounts_no_uid_except_zero", "remarks": "rule_set_224" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install systemd-journal-remote Package", + "value": "Verify Only Root Has UID 0", "remarks": "rule_set_224" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "socket_systemd-journal-remote_disabled", + "value": "accounts_root_gid_zero", "remarks": "rule_set_225" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable systemd-journal-remote Socket", + "value": "Verify Root Has A Primary GID 0", "remarks": "rule_set_225" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_compress", + "value": "groups_no_zero_gid_except_root", "remarks": "rule_set_226" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure journald is configured to compress large log files", + "value": "Verify Only Group Root Has GID 0", "remarks": "rule_set_226" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_storage", + "value": "ensure_root_password_configured", "remarks": "rule_set_227" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure journald is configured to write log files to persistent disk", + "value": "Ensure Authentication Required for Single User Mode", "remarks": "rule_set_227" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "rsyslog_files_groupownership", + "value": "accounts_root_path_dirs_no_write", "remarks": "rule_set_228" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Log Files Are Owned By Appropriate Group", + "value": "Ensure that Root's Path Does Not Include World or Group-Writable Directories", "remarks": "rule_set_228" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "rsyslog_files_ownership", + "value": "root_path_no_dot", "remarks": "rule_set_229" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Log Files Are Owned By Appropriate User", + "value": "Ensure that Root's Path Does Not Include Relative Paths or Null Directories", "remarks": "rule_set_229" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "rsyslog_files_permissions", + "value": "accounts_umask_root", "remarks": "rule_set_230" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure System Log Files Have Correct Permissions", + "value": "Ensure the Root Bash Umask is Set Correctly", "remarks": "rule_set_230" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_passwd", + "value": "no_password_auth_for_systemaccounts", "remarks": "rule_set_231" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns passwd File", + "value": "Ensure that System Accounts Are Locked", "remarks": "rule_set_231" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_passwd", + "value": "no_shelllogin_for_systemaccounts", "remarks": "rule_set_232" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns passwd File", + "value": "Ensure that System Accounts Do Not Run a Shell Upon Login", "remarks": "rule_set_232" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_passwd", + "value": "accounts_tmout", "remarks": "rule_set_233" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on passwd File", + "value": "Set Interactive Session Timeout", "remarks": "rule_set_233" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_passwd", + "value": "accounts_umask_etc_bashrc", "remarks": "rule_set_234" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns Backup passwd File", + "value": "Ensure the Default Bash Umask is Set Correctly", "remarks": "rule_set_234" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_passwd", + "value": "accounts_umask_etc_login_defs", "remarks": "rule_set_235" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns Backup passwd File", + "value": "Ensure the Default Umask is Set Correctly in login.defs", "remarks": "rule_set_235" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_passwd", + "value": "accounts_umask_etc_profile", "remarks": "rule_set_236" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on Backup passwd File", + "value": "Ensure the Default Umask is Set Correctly in /etc/profile", "remarks": "rule_set_236" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_group", + "value": "package_aide_installed", "remarks": "rule_set_237" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns group File", + "value": "Install AIDE", "remarks": "rule_set_237" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_group", + "value": "aide_build_database", "remarks": "rule_set_238" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns group File", + "value": "Build and Test AIDE Database", "remarks": "rule_set_238" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_group", + "value": "aide_periodic_cron_checking", "remarks": "rule_set_239" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on group File", + "value": "Configure Periodic Execution of AIDE", "remarks": "rule_set_239" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_group", + "value": "aide_check_audit_tools", "remarks": "rule_set_240" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns Backup group File", + "value": "Configure AIDE to Verify the Audit Tools", "remarks": "rule_set_240" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_group", + "value": "service_systemd-journald_enabled", "remarks": "rule_set_241" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns Backup group File", + "value": "Enable systemd-journald Service", "remarks": "rule_set_241" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_group", + "value": "journald_compress", "remarks": "rule_set_242" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on Backup group File", + "value": "Ensure journald is configured to compress large log files", "remarks": "rule_set_242" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_shadow", + "value": "journald_storage", "remarks": "rule_set_243" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns shadow File", + "value": "Ensure journald is configured to write log files to persistent disk", "remarks": "rule_set_243" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_shadow", + "value": "package_systemd-journal-remote_installed", "remarks": "rule_set_244" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns shadow File", + "value": "Install systemd-journal-remote Package", "remarks": "rule_set_244" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_shadow", + "value": "socket_systemd-journal-remote_disabled", "remarks": "rule_set_245" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on shadow File", + "value": "Disable systemd-journal-remote Socket", "remarks": "rule_set_245" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_shadow", + "value": "rsyslog_files_groupownership", "remarks": "rule_set_246" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns Backup shadow File", + "value": "Ensure Log Files Are Owned By Appropriate Group", "remarks": "rule_set_246" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_shadow", + "value": "rsyslog_files_ownership", "remarks": "rule_set_247" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns Backup shadow File", + "value": "Ensure Log Files Are Owned By Appropriate User", "remarks": "rule_set_247" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_shadow", + "value": "rsyslog_files_permissions", "remarks": "rule_set_248" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on Backup shadow File", + "value": "Ensure System Log Files Have Correct Permissions", "remarks": "rule_set_248" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_gshadow", + "value": "file_groupowner_etc_passwd", "remarks": "rule_set_249" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns gshadow File", + "value": "Verify Group Who Owns passwd File", "remarks": "rule_set_249" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_gshadow", + "value": "file_owner_etc_passwd", "remarks": "rule_set_250" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns gshadow File", + "value": "Verify User Who Owns passwd File", "remarks": "rule_set_250" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_gshadow", + "value": "file_permissions_etc_passwd", "remarks": "rule_set_251" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on gshadow File", + "value": "Verify Permissions on passwd File", "remarks": "rule_set_251" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_gshadow", + "value": "file_groupowner_backup_etc_passwd", "remarks": "rule_set_252" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns Backup gshadow File", + "value": "Verify Group Who Owns Backup passwd File", "remarks": "rule_set_252" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_gshadow", + "value": "file_owner_backup_etc_passwd", "remarks": "rule_set_253" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns Backup gshadow File", + "value": "Verify User Who Owns Backup passwd File", "remarks": "rule_set_253" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_gshadow", + "value": "file_permissions_backup_etc_passwd", "remarks": "rule_set_254" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on Backup gshadow File", + "value": "Verify Permissions on Backup passwd File", "remarks": "rule_set_254" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_shells", + "value": "file_groupowner_etc_group", "remarks": "rule_set_255" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns /etc/shells File", + "value": "Verify Group Who Owns group File", "remarks": "rule_set_255" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_shells", + "value": "file_owner_etc_group", "remarks": "rule_set_256" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Who Owns /etc/shells File", + "value": "Verify User Who Owns group File", "remarks": "rule_set_256" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_shells", + "value": "file_permissions_etc_group", "remarks": "rule_set_257" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on /etc/shells File", + "value": "Verify Permissions on group File", "remarks": "rule_set_257" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_etc_security_opasswd", + "value": "file_groupowner_backup_etc_group", "remarks": "rule_set_258" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions and Ownership of Old Passwords File", + "value": "Verify Group Who Owns Backup group File", "remarks": "rule_set_258" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_unauthorized_world_writable", + "value": "file_owner_backup_etc_group", "remarks": "rule_set_259" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure No World-Writable Files Exist", + "value": "Verify User Who Owns Backup group File", "remarks": "rule_set_259" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dir_perms_world_writable_sticky_bits", + "value": "file_permissions_backup_etc_group", "remarks": "rule_set_260" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify that All World-Writable Directories Have Sticky Bits Set", + "value": "Verify Permissions on Backup group File", "remarks": "rule_set_260" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_files_unowned_by_user", + "value": "file_owner_etc_shadow", "remarks": "rule_set_261" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Files Are Owned by a User", + "value": "Verify User Who Owns shadow File", "remarks": "rule_set_261" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_ungroupowned", + "value": "file_groupowner_etc_shadow", "remarks": "rule_set_262" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Files Are Owned by a Group", + "value": "Verify Group Who Owns shadow File", "remarks": "rule_set_262" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_all_shadowed", + "value": "file_permissions_etc_shadow", "remarks": "rule_set_263" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify All Account Password Hashes are Shadowed", + "value": "Verify Permissions on shadow File", "remarks": "rule_set_263" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_empty_passwords_etc_shadow", + "value": "file_groupowner_backup_etc_shadow", "remarks": "rule_set_264" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure There Are No Accounts With Blank or Null Passwords", + "value": "Verify User Who Owns Backup shadow File", "remarks": "rule_set_264" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "gid_passwd_group_same", + "value": "file_owner_backup_etc_shadow", "remarks": "rule_set_265" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "All GIDs referenced in /etc/passwd must be defined in /etc/group", + "value": "Verify Group Who Owns Backup shadow File", "remarks": "rule_set_265" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_unique_id", + "value": "file_permissions_backup_etc_shadow", "remarks": "rule_set_266" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Accounts on the System Have Unique User IDs", + "value": "Verify Permissions on Backup shadow File", "remarks": "rule_set_266" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "group_unique_id", + "value": "file_groupowner_etc_gshadow", "remarks": "rule_set_267" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Groups on the System Have Unique Group ID", + "value": "Verify Group Who Owns gshadow File", "remarks": "rule_set_267" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_unique_name", + "value": "file_owner_etc_gshadow", "remarks": "rule_set_268" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Accounts on the System Have Unique Names", + "value": "Verify User Who Owns gshadow File", "remarks": "rule_set_268" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "group_unique_name", + "value": "file_permissions_etc_gshadow", "remarks": "rule_set_269" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Groups on the System Have Unique Group Names", + "value": "Verify Permissions on gshadow File", "remarks": "rule_set_269" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_user_interactive_home_directory_exists", + "value": "file_groupowner_backup_etc_gshadow", "remarks": "rule_set_270" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "All Interactive Users Home Directories Must Exist", + "value": "Verify Group Who Owns Backup gshadow File", "remarks": "rule_set_270" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_home_directories", + "value": "file_owner_backup_etc_gshadow", "remarks": "rule_set_271" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "All Interactive User Home Directories Must Be Owned By The Primary User", + "value": "Verify User Who Owns Backup gshadow File", "remarks": "rule_set_271" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_home_directories", + "value": "file_permissions_backup_etc_gshadow", "remarks": "rule_set_272" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "All Interactive User Home Directories Must Have mode 0750 Or Less Permissive", + "value": "Verify Permissions on Backup gshadow File", "remarks": "rule_set_272" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_user_dot_group_ownership", + "value": "file_groupowner_etc_shells", "remarks": "rule_set_273" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "User Initialization Files Must Be Group-Owned By The Primary Group", + "value": "Verify Group Who Owns /etc/shells File", "remarks": "rule_set_273" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_user_dot_user_ownership", + "value": "file_owner_etc_shells", "remarks": "rule_set_274" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "User Initialization Files Must Be Owned By the Primary User", + "value": "Verify Who Owns /etc/shells File", "remarks": "rule_set_274" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_user_dot_no_world_writable_programs", + "value": "file_permissions_etc_shells", "remarks": "rule_set_275" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "User Initialization Files Must Not Run World-Writable Programs", + "value": "Verify Permissions on /etc/shells File", "remarks": "rule_set_275" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permission_user_init_files", + "value": "file_etc_security_opasswd", "remarks": "rule_set_276" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All User Initialization Files Have Mode 0740 Or Less Permissive", + "value": "Verify Permissions and Ownership of Old Passwords File", "remarks": "rule_set_276" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_forward_files", + "value": "file_permissions_unauthorized_world_writable", "remarks": "rule_set_277" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify No .forward Files Exist", + "value": "Ensure No World-Writable Files Exist", "remarks": "rule_set_277" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_netrc_files", + "value": "dir_perms_world_writable_sticky_bits", "remarks": "rule_set_278" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify No netrc Files Exist", + "value": "Verify that All World-Writable Directories Have Sticky Bits Set", "remarks": "rule_set_278" - } - ], - "control-implementations": [ + }, { - "uuid": "fbb83d4e-ff5c-4742-b9f7-1feb246c50e2", - "source": "trestle://profiles/rhel10-cis_rhel10-l1_server/profile.json", - "description": "REPLACE_ME", - "props": [ - { - "name": "Framework_Short_Name", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal", - "value": "cis_server_l1" - } - ], - "set-parameters": [ - { - "param-id": "cis_banner_text", - "values": [ - "cis" - ] - }, - { - "param-id": "inactivity_timeout_value", - "values": [ - "15_minutes" - ] - }, - { - "param-id": "login_banner_text", - "values": [ - "cis_banners" - ] - }, - { - "param-id": "sshd_idle_timeout_value", - "values": [ - "5_minutes" - ] - }, - { - "param-id": "sshd_max_auth_tries_value", - "values": [ - "4" - ] + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "no_files_unowned_by_user", + "remarks": "rule_set_279" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure All Files Are Owned by a User", + "remarks": "rule_set_279" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_ungroupowned", + "remarks": "rule_set_280" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure All Files Are Owned by a Group", + "remarks": "rule_set_280" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_password_all_shadowed", + "remarks": "rule_set_281" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify All Account Password Hashes are Shadowed", + "remarks": "rule_set_281" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "no_empty_passwords_etc_shadow", + "remarks": "rule_set_282" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure There Are No Accounts With Blank or Null Passwords", + "remarks": "rule_set_282" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "gid_passwd_group_same", + "remarks": "rule_set_283" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "All GIDs referenced in /etc/passwd must be defined in /etc/group", + "remarks": "rule_set_283" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "account_unique_id", + "remarks": "rule_set_284" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure All Accounts on the System Have Unique User IDs", + "remarks": "rule_set_284" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "group_unique_id", + "remarks": "rule_set_285" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure All Groups on the System Have Unique Group ID", + "remarks": "rule_set_285" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "account_unique_name", + "remarks": "rule_set_286" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure All Accounts on the System Have Unique Names", + "remarks": "rule_set_286" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "group_unique_name", + "remarks": "rule_set_287" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure All Groups on the System Have Unique Group Names", + "remarks": "rule_set_287" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_user_interactive_home_directory_exists", + "remarks": "rule_set_288" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "All Interactive Users Home Directories Must Exist", + "remarks": "rule_set_288" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_ownership_home_directories", + "remarks": "rule_set_289" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "All Interactive User Home Directories Must Be Owned By The Primary User", + "remarks": "rule_set_289" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_home_directories", + "remarks": "rule_set_290" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "All Interactive User Home Directories Must Have mode 0750 Or Less Permissive", + "remarks": "rule_set_290" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_user_dot_group_ownership", + "remarks": "rule_set_291" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "User Initialization Files Must Be Group-Owned By The Primary Group", + "remarks": "rule_set_291" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_user_dot_user_ownership", + "remarks": "rule_set_292" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "User Initialization Files Must Be Owned By the Primary User", + "remarks": "rule_set_292" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_user_dot_no_world_writable_programs", + "remarks": "rule_set_293" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "User Initialization Files Must Not Run World-Writable Programs", + "remarks": "rule_set_293" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permission_user_init_files", + "remarks": "rule_set_294" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure All User Initialization Files Have Mode 0740 Or Less Permissive", + "remarks": "rule_set_294" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "no_forward_files", + "remarks": "rule_set_295" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify No .forward Files Exist", + "remarks": "rule_set_295" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "no_netrc_files", + "remarks": "rule_set_296" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify No netrc Files Exist", + "remarks": "rule_set_296" + } + ], + "control-implementations": [ + { + "uuid": "613f34e1-4f03-4361-b38f-434f0c3ddbc3", + "source": "trestle://profiles/rhel10-cis_rhel10-l1_server/profile.json", + "description": "REPLACE_ME", + "props": [ + { + "name": "Framework_Short_Name", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal", + "value": "cis_server_l1" + } + ], + "set-parameters": [ + { + "param-id": "cis_banner_text", + "values": [ + "cis" + ] + }, + { + "param-id": "inactivity_timeout_value", + "values": [ + "15_minutes" + ] + }, + { + "param-id": "login_banner_text", + "values": [ + "cis_banners" + ] + }, + { + "param-id": "sshd_idle_timeout_value", + "values": [ + "5_minutes" + ] + }, + { + "param-id": "sshd_max_auth_tries_value", + "values": [ + "4" + ] }, { "param-id": "sshd_strong_kex", "values": [ - "cis_rhel8" + "cis_rhel10" ] }, { "param-id": "sshd_strong_macs", "values": [ - "cis_rhel8" + "cis_rhel10" ] }, { @@ -4528,6 +4762,12 @@ "disabled" ] }, + { + "param-id": "sysctl_net_ipv6_conf_default_forwarding_value", + "values": [ + "disabled" + ] + }, { "param-id": "var_account_disable_post_pw_expiration", "values": [ @@ -4699,7 +4939,7 @@ ], "implemented-requirements": [ { - "uuid": "86045c6c-d1fd-43c0-afd0-037210b50ab1", + "uuid": "5282ebad-2555-4ab7-b985-b7aaf9cf4c77", "control-id": "reload_dconf_db", "description": "This is a helper rule to reload Dconf database correctly.", "props": [ @@ -4716,8 +4956,8 @@ ] }, { - "uuid": "59709b28-e290-445b-afc2-1479802993cb", - "control-id": "cis_rhel10_1-1.1.8", + "uuid": "1c467d5a-1d2f-442f-b89f-f175119ee2f2", + "control-id": "cis_rhel10_1-1.1.9", "description": "REPLACE_ME", "props": [ { @@ -4728,25 +4968,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_usb-storage_disabled" - } - ] - }, - { - "uuid": "c1d5555f-3017-4960-b289-177fff13145c", - "control-id": "cis_rhel10_1-1.1.9", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "kernel_module_firewire-core_disabled" } ] }, { - "uuid": "fd185a91-c947-4069-8b69-e8debce73947", + "uuid": "be335e6a-73a7-4dab-91bc-828ebda75630", "control-id": "cis_rhel10_1-1.2.1.1", "description": "REPLACE_ME", "props": [ @@ -4763,7 +4990,7 @@ ] }, { - "uuid": "30d38c3a-fb8c-4dc6-96a9-0b68cce33bcf", + "uuid": "e1411005-e4a9-454d-8f31-e3a0ac461e89", "control-id": "cis_rhel10_1-1.2.1.2", "description": "REPLACE_ME", "props": [ @@ -4780,7 +5007,7 @@ ] }, { - "uuid": "8adea8b5-9f52-4030-ac9b-a0321a1869e9", + "uuid": "71e052e7-dcf6-4162-be95-27de61c414ea", "control-id": "cis_rhel10_1-1.2.1.3", "description": "REPLACE_ME", "props": [ @@ -4797,7 +5024,7 @@ ] }, { - "uuid": "7fa96596-5fb2-4666-b0d1-97081b207e99", + "uuid": "cd9cfd66-1282-41d8-aff4-9e11751a303a", "control-id": "cis_rhel10_1-1.2.1.4", "description": "REPLACE_ME", "props": [ @@ -4814,7 +5041,7 @@ ] }, { - "uuid": "bbfc20dc-0239-4913-bbe2-29f76156bba8", + "uuid": "e6d67165-f3ab-47bf-af01-a0c9972702bd", "control-id": "cis_rhel10_1-1.2.2.1", "description": "REPLACE_ME", "props": [ @@ -4831,7 +5058,7 @@ ] }, { - "uuid": "3aa2fd18-8b92-4d87-b7b5-8fea7655bd62", + "uuid": "c05f34ea-83c2-4aa8-8566-0e17d02ee65b", "control-id": "cis_rhel10_1-1.2.2.2", "description": "REPLACE_ME", "props": [ @@ -4848,7 +5075,7 @@ ] }, { - "uuid": "deb085a6-a589-417f-98f8-f6026450745a", + "uuid": "ced59a5d-3340-4452-80f1-9c9130480971", "control-id": "cis_rhel10_1-1.2.2.3", "description": "REPLACE_ME", "props": [ @@ -4865,7 +5092,7 @@ ] }, { - "uuid": "f9c6147a-c786-4980-8f88-9dfab8d58b2a", + "uuid": "e88dc4a4-5c6f-4402-875d-a81b3620b4ca", "control-id": "cis_rhel10_1-1.2.2.4", "description": "REPLACE_ME", "props": [ @@ -4882,7 +5109,7 @@ ] }, { - "uuid": "43206d68-2ee2-4b12-83a3-a2483ff2503e", + "uuid": "e604f052-ead9-44b2-87e9-40ae4bc7e739", "control-id": "cis_rhel10_1-1.2.3.2", "description": "REPLACE_ME", "props": [ @@ -4899,7 +5126,7 @@ ] }, { - "uuid": "6a846c96-c160-42dd-9d20-6fcd47ea570b", + "uuid": "2155fe6a-9ad3-484c-a9f1-ba5d73d96237", "control-id": "cis_rhel10_1-1.2.3.3", "description": "REPLACE_ME", "props": [ @@ -4916,7 +5143,7 @@ ] }, { - "uuid": "0a95ea36-30f6-4637-9665-9f89b9d510b7", + "uuid": "8dbaab86-ec14-437a-92a4-d20ef7e5b8f6", "control-id": "cis_rhel10_1-1.2.4.2", "description": "REPLACE_ME", "props": [ @@ -4933,7 +5160,7 @@ ] }, { - "uuid": "40daeb28-1941-4dec-b6f6-03237cfea0c6", + "uuid": "9cd6abff-2fa4-4fa7-8838-c00ec9411193", "control-id": "cis_rhel10_1-1.2.4.3", "description": "REPLACE_ME", "props": [ @@ -4950,7 +5177,7 @@ ] }, { - "uuid": "a7d81e0c-3126-4a71-b0cc-95e0d80d1afd", + "uuid": "a9dd3b38-ba79-4388-b407-39b0298abcfc", "control-id": "cis_rhel10_1-1.2.5.2", "description": "REPLACE_ME", "props": [ @@ -4967,7 +5194,7 @@ ] }, { - "uuid": "afe05cae-9d7b-4456-91e3-760e2fa6b8b5", + "uuid": "e76279e8-299f-4207-82a4-0995cdc9ee52", "control-id": "cis_rhel10_1-1.2.5.3", "description": "REPLACE_ME", "props": [ @@ -4984,7 +5211,7 @@ ] }, { - "uuid": "cfd19307-96e8-434f-82d5-1e03c672bf61", + "uuid": "5f8c774e-d20d-4c85-af5c-a5dc61caf4d4", "control-id": "cis_rhel10_1-1.2.5.4", "description": "REPLACE_ME", "props": [ @@ -5001,7 +5228,7 @@ ] }, { - "uuid": "7c77a2df-7732-4911-b034-aed1ed743e09", + "uuid": "a05a1762-3d8c-4f70-ba74-e4c9179492d9", "control-id": "cis_rhel10_1-1.2.6.2", "description": "REPLACE_ME", "props": [ @@ -5018,7 +5245,7 @@ ] }, { - "uuid": "76d94bb5-34d3-42f6-8fee-2c37953e3ee9", + "uuid": "5968b609-156d-4147-8fdd-b50ed21d4a9e", "control-id": "cis_rhel10_1-1.2.6.3", "description": "REPLACE_ME", "props": [ @@ -5035,7 +5262,7 @@ ] }, { - "uuid": "103dba27-eb82-4b75-85d1-7ea59ecba4b8", + "uuid": "a7a04e87-b73a-457a-8264-48e390711ef7", "control-id": "cis_rhel10_1-1.2.6.4", "description": "REPLACE_ME", "props": [ @@ -5052,7 +5279,7 @@ ] }, { - "uuid": "2df2b7bc-1f10-4ef1-b5e3-158ba9a74cc6", + "uuid": "34cc71fc-18a2-40d2-a10c-3f241b7a2193", "control-id": "cis_rhel10_1-1.2.7.2", "description": "REPLACE_ME", "props": [ @@ -5069,7 +5296,7 @@ ] }, { - "uuid": "ae5ea05c-cff1-4889-85d2-597af95a7ecc", + "uuid": "32fcfd9c-6f8b-42c5-ae62-ef5938b26e1e", "control-id": "cis_rhel10_1-1.2.7.3", "description": "REPLACE_ME", "props": [ @@ -5086,7 +5313,7 @@ ] }, { - "uuid": "468adc93-5082-43d4-825d-61e355fdcf66", + "uuid": "743d84e7-589a-4d2d-9b72-0967925e907a", "control-id": "cis_rhel10_1-1.2.7.4", "description": "REPLACE_ME", "props": [ @@ -5103,7 +5330,7 @@ ] }, { - "uuid": "f426d2eb-837d-4621-b057-4c720b7a04b4", + "uuid": "69ac0a5d-7636-4b2c-b579-d1f0dc77f4e5", "control-id": "cis_rhel10_1-2.1.1", "description": "REPLACE_ME", "props": [ @@ -5116,7 +5343,7 @@ ] }, { - "uuid": "1ca88df2-f7ff-4831-8fc6-94c417692588", + "uuid": "7d2ae1c8-a3de-442a-bb1d-86ab4402ba72", "control-id": "cis_rhel10_1-2.1.2", "description": "REPLACE_ME", "props": [ @@ -5133,7 +5360,7 @@ ] }, { - "uuid": "403c63ab-db3d-4647-be2e-dc1435831a44", + "uuid": "fc23137d-e7fd-49dd-a519-c17f4e617f28", "control-id": "cis_rhel10_1-2.1.4", "description": "REPLACE_ME", "props": [ @@ -5146,7 +5373,7 @@ ] }, { - "uuid": "58a10da3-2c93-4f0a-9947-0bd57315b57a", + "uuid": "b2b84b11-09eb-4a78-a2b6-0345a38aba12", "control-id": "cis_rhel10_1-2.2.1", "description": "REPLACE_ME", "props": [ @@ -5159,7 +5386,7 @@ ] }, { - "uuid": "5386a81a-d4fc-4109-b5c9-3f6e7a32e68b", + "uuid": "ecd0623e-6626-4df9-90ff-251892c3165c", "control-id": "cis_rhel10_1-3.1.1", "description": "REPLACE_ME", "props": [ @@ -5176,7 +5403,7 @@ ] }, { - "uuid": "ba9dbc05-06de-4f61-a824-0adc8fbb5c88", + "uuid": "4679210c-fb2e-42c0-a1dd-b33175d88141", "control-id": "cis_rhel10_1-3.1.2", "description": "REPLACE_ME", "props": [ @@ -5193,7 +5420,7 @@ ] }, { - "uuid": "cffe8cd7-5d8e-46b6-88a6-216f376c3bcd", + "uuid": "14cdd056-2cc8-4a0f-8def-2c4817c956a2", "control-id": "cis_rhel10_1-3.1.3", "description": "REPLACE_ME", "props": [ @@ -5210,7 +5437,7 @@ ] }, { - "uuid": "665a8554-1be6-4b1e-95aa-701fab2c6fb1", + "uuid": "f3866dc4-80ef-4722-ab9d-cd5c72bf9ee2", "control-id": "cis_rhel10_1-3.1.4", "description": "REPLACE_ME", "props": [ @@ -5227,7 +5454,7 @@ ] }, { - "uuid": "a430864f-d3a3-4387-8180-ab36ce254347", + "uuid": "8113ca46-4ad1-4d28-adab-7c2ae3cb8f8f", "control-id": "cis_rhel10_1-3.1.7", "description": "REPLACE_ME", "props": [ @@ -5244,7 +5471,7 @@ ] }, { - "uuid": "ac004357-9f3d-4a79-a224-6c121d18ff7a", + "uuid": "91d2eef4-9ce4-487f-bbff-81fa688b26f8", "control-id": "cis_rhel10_1-3.1.8", "description": "REPLACE_ME", "props": [ @@ -5261,7 +5488,7 @@ ] }, { - "uuid": "26696d88-24a0-48df-b97a-d43ad470aae1", + "uuid": "9898323c-4273-472d-b4b3-6c0549370728", "control-id": "cis_rhel10_1-4.1", "description": "There is no automated remediation for this rule and this is intentional.\nMore details in the rule description.", "props": [ @@ -5278,7 +5505,7 @@ ] }, { - "uuid": "67a6b1d1-0720-468d-a229-a1721b8392ae", + "uuid": "76edd4c9-6af9-494b-be62-3897f68a73b3", "control-id": "cis_rhel10_1-4.2", "description": "REPLACE_ME", "props": [ @@ -5321,9 +5548,9 @@ ] }, { - "uuid": "f73dd618-1efc-4e41-8433-b4004f3153d2", + "uuid": "8d2b6a72-de59-437b-b98d-407037befb98", "control-id": "cis_rhel10_1-5.1", - "description": "Address Space Layout Randomization (ASLR)", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -5333,12 +5560,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_kernel_randomize_va_space" + "value": "disable_users_coredumps" } ] }, { - "uuid": "f74b6234-5a91-4d10-85dd-e02b298d3c2a", + "uuid": "a6eb7a89-bd33-4371-921f-a8c79d4cf7ee", "control-id": "cis_rhel10_1-5.2", "description": "REPLACE_ME", "props": [ @@ -5350,13 +5577,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_kernel_yama_ptrace_scope" + "value": "sysctl_fs_protected_hardlinks" } ] }, { - "uuid": "01f37814-2fb7-49b7-b630-91282973f5f2", - "control-id": "cis_rhel10_1-5.3", + "uuid": "67386707-db0d-434a-bef4-1829370795c6", + "control-id": "cis_rhel10_1-5.4", "description": "REPLACE_ME", "props": [ { @@ -5367,13 +5594,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_backtraces" + "value": "sysctl_fs_suid_dumpable" } ] }, { - "uuid": "e6852037-9719-4cdd-b320-c3bba60da285", - "control-id": "cis_rhel10_1-5.4", + "uuid": "e8e3e58e-37cc-425c-8588-fd54a98573a9", + "control-id": "cis_rhel10_1-6.1", "description": "REPLACE_ME", "props": [ { @@ -5384,59 +5611,26 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_storage" + "value": "configure_crypto_policy" } ] }, { - "uuid": "7005b60a-ee94-437e-8d50-39341dfd0692", - "control-id": "cis_rhel10_1-6.1", + "uuid": "865e801f-9871-4087-98f3-dde311a47b25", + "control-id": "cis_rhel10_1-6.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_crypto_policy" + "value": "alternative", + "remarks": "It is necessary a new rule to ensure a module disabling sha1 in\n/etc/crypto-policies/policies/modules/ so it can be used by update-crypto-policies command." } ] }, { - "uuid": "00f8cc1b-84ba-4303-ac07-5c8f378fd68b", - "control-id": "cis_rhel10_1-6.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_ssh_crypto_policy" - } - ] - }, - { - "uuid": "37a816c9-8f10-461a-ae1f-be55a51871a8", - "control-id": "cis_rhel10_1-6.3", - "description": "This requirement is already satisfied by 1.6.1.", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - } - ] - }, - { - "uuid": "fc3b00c0-0c0b-4fa3-8a33-9ecc41087adc", - "control-id": "cis_rhel10_1-6.4", + "uuid": "813c12b8-db08-4112-b157-9d29ec052b16", + "control-id": "cis_rhel10_1-6.3", "description": "REPLACE_ME", "props": [ { @@ -5448,8 +5642,8 @@ ] }, { - "uuid": "1e146f8d-3e95-4491-b756-1d72e4f9e0e2", - "control-id": "cis_rhel10_1-6.5", + "uuid": "12b72c80-10f6-4d7a-a862-31c88baaa6b1", + "control-id": "cis_rhel10_1-6.4", "description": "REPLACE_ME", "props": [ { @@ -5461,33 +5655,7 @@ ] }, { - "uuid": "d00f7354-f3b1-4173-a716-99aef2e9f329", - "control-id": "cis_rhel10_1-6.6", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } - ] - }, - { - "uuid": "e3833bfa-25f6-42d1-afbe-fff985f5368a", - "control-id": "cis_rhel10_1-6.7", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } - ] - }, - { - "uuid": "0a98a123-8777-441d-88c7-b9a11a5d4faf", + "uuid": "cb4afe47-49cf-4151-91ac-e9a74de2f83d", "control-id": "cis_rhel10_1-7.1", "description": "REPLACE_ME", "props": [ @@ -5504,7 +5672,7 @@ ] }, { - "uuid": "2198d809-5075-4127-8592-88504b08baa6", + "uuid": "e4ca4682-34b0-4f5e-bdb1-2a53b2105018", "control-id": "cis_rhel10_1-7.2", "description": "REPLACE_ME", "props": [ @@ -5521,7 +5689,7 @@ ] }, { - "uuid": "32a20d6b-acd5-486a-a7ba-16575f00e31b", + "uuid": "0c907078-3d16-4c53-a578-7d2881562561", "control-id": "cis_rhel10_1-7.3", "description": "REPLACE_ME", "props": [ @@ -5538,7 +5706,7 @@ ] }, { - "uuid": "cc0c30eb-f4b7-42a1-a280-90becf8ac696", + "uuid": "b8d0c7e8-fb21-4730-bcee-0a1fcfdb1a29", "control-id": "cis_rhel10_1-7.4", "description": "REPLACE_ME", "props": [ @@ -5565,7 +5733,7 @@ ] }, { - "uuid": "45c42a67-f060-4dce-aa04-e806df22203b", + "uuid": "f4542118-554e-4e54-af48-3394d60d761a", "control-id": "cis_rhel10_1-7.5", "description": "REPLACE_ME", "props": [ @@ -5592,7 +5760,7 @@ ] }, { - "uuid": "75fba3fe-14e7-46a8-86e8-40507453a0c4", + "uuid": "48dfba81-ff54-461a-9c98-ce1665621ed9", "control-id": "cis_rhel10_1-7.6", "description": "REPLACE_ME", "props": [ @@ -5619,31 +5787,9 @@ ] }, { - "uuid": "e8163869-2b42-4189-b465-9d7e393b1f8d", + "uuid": "1022fea5-b22c-469e-87eb-362bd9e2a842", "control-id": "cis_rhel10_1-8.2", "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_banner_enabled" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_login_banner_text" - } - ] - }, - { - "uuid": "f693823e-c5ff-411c-9b9b-ab51edcdff0a", - "control-id": "cis_rhel10_1-8.3", - "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -5658,8 +5804,8 @@ ] }, { - "uuid": "0c2fb857-cea8-4e1f-9e22-2002d98567ff", - "control-id": "cis_rhel10_1-8.4", + "uuid": "cc0d15c4-5811-495c-9c5e-b932786f7ae5", + "control-id": "cis_rhel10_1-8.3", "description": "REPLACE_ME", "props": [ { @@ -5676,18 +5822,6 @@ "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_screensaver_lock_delay" - } - ] - }, - { - "uuid": "10c8c51d-f65e-45b5-9bbf-c7e6adbe06fa", - "control-id": "cis_rhel10_1-8.5", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" }, { "name": "Rule_Id", @@ -5702,30 +5836,8 @@ ] }, { - "uuid": "a33ae18c-c19c-40e5-919f-608d3d39fbe3", - "control-id": "cis_rhel10_1-8.6", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_automount" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_automount_open" - } - ] - }, - { - "uuid": "ee0f85b4-6d2a-4310-81fb-8b11ee8d2fe4", - "control-id": "cis_rhel10_1-8.7", + "uuid": "8d5a7efd-2e06-4a27-a59d-c2476cdf2013", + "control-id": "cis_rhel10_1-8.4", "description": "REPLACE_ME", "props": [ { @@ -5746,25 +5858,8 @@ ] }, { - "uuid": "7b24d858-22e9-469a-a7a7-3fbac932eda3", - "control-id": "cis_rhel10_1-8.8", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_autorun" - } - ] - }, - { - "uuid": "5ff87bac-af2c-4e0a-a500-8d50e37e13df", - "control-id": "cis_rhel10_1-8.9", + "uuid": "14478e3a-532a-4589-811f-7f06bcdf5652", + "control-id": "cis_rhel10_1-8.5", "description": "REPLACE_ME", "props": [ { @@ -5780,19 +5875,7 @@ ] }, { - "uuid": "45555435-2f11-4d11-bb4e-55d288b91dff", - "control-id": "cis_rhel10_1-8.10", - "description": "This was inherited from the RHEL 9 profile.\nHowever, it was reported that XDMCP is no\nlonger in RHEL 10.", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - } - ] - }, - { - "uuid": "60f5465f-ca8d-4784-8f15-db22e87974e1", + "uuid": "6e02604c-800c-4f37-bde6-0c833ee21ac9", "control-id": "cis_rhel10_2-1.1", "description": "REPLACE_ME", "props": [ @@ -5809,7 +5892,7 @@ ] }, { - "uuid": "8ec55da2-31c3-4ab3-ab98-3d664672f990", + "uuid": "34076702-83ef-4255-9595-29f603cb27bb", "control-id": "cis_rhel10_2-1.2", "description": "REPLACE_ME", "props": [ @@ -5826,24 +5909,7 @@ ] }, { - "uuid": "7640e264-8b85-410a-8104-2b054a2f47f7", - "control-id": "cis_rhel10_2-1.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_kea_removed" - } - ] - }, - { - "uuid": "96de33d3-a770-4e02-8d5c-d7f5f1cd5ac8", + "uuid": "066d5b39-95fe-43e2-aa69-d9ff71910ae5", "control-id": "cis_rhel10_2-1.4", "description": "REPLACE_ME", "props": [ @@ -5855,12 +5921,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_bind_removed" + "value": "package_kea_removed" } ] }, { - "uuid": "9cde2b97-d305-4624-a567-6a78020d55ca", + "uuid": "035a0070-23b4-4a70-b0cd-1fdb858d8543", "control-id": "cis_rhel10_2-1.5", "description": "REPLACE_ME", "props": [ @@ -5872,12 +5938,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_dnsmasq_removed" + "value": "package_bind_removed" } ] }, { - "uuid": "d271ca0d-56db-4ffa-934e-9ba7a390ca1f", + "uuid": "332b8e55-387a-4df8-81ec-8ccf0c47cd45", "control-id": "cis_rhel10_2-1.6", "description": "REPLACE_ME", "props": [ @@ -5889,12 +5955,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_samba_removed" + "value": "package_dnsmasq_removed" } ] }, { - "uuid": "51c6a97c-a083-4430-8ab9-d7d19091c372", + "uuid": "3ad922b3-7c8c-46b1-9b33-6a580d491552", "control-id": "cis_rhel10_2-1.7", "description": "REPLACE_ME", "props": [ @@ -5911,7 +5977,7 @@ ] }, { - "uuid": "2a8a1d89-9a18-4928-b441-0dccc8e6c415", + "uuid": "4eab93d5-8794-418d-b0d4-26ee9dc997d7", "control-id": "cis_rhel10_2-1.8", "description": "REPLACE_ME", "props": [ @@ -5933,7 +5999,7 @@ ] }, { - "uuid": "a0b1d2d2-3c58-4074-96ce-b853b568cfc2", + "uuid": "0eca2dd1-6f34-41d5-894f-d07914f720f4", "control-id": "cis_rhel10_2-1.9", "description": "Many of the libvirt packages used by Enterprise Linux virtualization are dependent on the\nnfs-utils package.", "props": [ @@ -5950,7 +6016,7 @@ ] }, { - "uuid": "072605f7-2c0b-4dfe-8296-48f08756753e", + "uuid": "e04f22a4-ec72-4cc0-b506-c6bca1a734b0", "control-id": "cis_rhel10_2-1.10", "description": "REPLACE_ME", "props": [ @@ -5958,13 +6024,18 @@ "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "service_cups_disabled" } ] }, { - "uuid": "2b4a4872-8679-4667-8a20-a89208fe24bd", + "uuid": "b8c8fd50-cf67-4507-ad57-534864ab42d8", "control-id": "cis_rhel10_2-1.11", - "description": "REPLACE_ME", + "description": "Many of the libvirt packages used by Enterprise Linux virtualization, and the nfs-utils\npackage used for The Network File System (NFS), are dependent on the rpcbind package.", "props": [ { "name": "implementation-status", @@ -5974,14 +6045,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_cups_disabled" + "value": "service_rpcbind_disabled" } ] }, { - "uuid": "3d3ac37c-46d9-4b15-b966-bfb0a85cbaf7", + "uuid": "3c0d7df8-fbea-4b2f-ab53-7eed4ab2b760", "control-id": "cis_rhel10_2-1.12", - "description": "Many of the libvirt packages used by Enterprise Linux virtualization, and the nfs-utils\npackage used for The Network File System (NFS), are dependent on the rpcbind package.", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -5991,12 +6062,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_rpcbind_disabled" + "value": "package_rsync_removed" } ] }, { - "uuid": "6aa74afe-a912-4ecc-b698-9ef35536bbe4", + "uuid": "f77d079a-5a14-4c7d-a9da-65fcbbb7f1b7", "control-id": "cis_rhel10_2-1.13", "description": "REPLACE_ME", "props": [ @@ -6008,12 +6079,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_rsync_removed" + "value": "package_samba_removed" } ] }, { - "uuid": "bcab2b9a-e0b9-4336-b8ef-677e03ad2b45", + "uuid": "de2cba73-94f8-4d5f-a375-f53eb13d5709", "control-id": "cis_rhel10_2-1.14", "description": "REPLACE_ME", "props": [ @@ -6030,7 +6101,7 @@ ] }, { - "uuid": "cc0b65ca-01ed-4586-8dc1-cbdb33b53875", + "uuid": "e2d6ff64-1c1e-410e-8145-5c9b2a26d081", "control-id": "cis_rhel10_2-1.15", "description": "REPLACE_ME", "props": [ @@ -6047,7 +6118,7 @@ ] }, { - "uuid": "36d69ded-1200-41d2-a11b-333c27c4afd5", + "uuid": "1d283a70-ddf1-4e6e-816a-8ec9d25afe9e", "control-id": "cis_rhel10_2-1.16", "description": "REPLACE_ME", "props": [ @@ -6064,7 +6135,7 @@ ] }, { - "uuid": "5555a71f-3d20-4b49-89cc-66d716ad2b9d", + "uuid": "c464ce38-7495-4c03-902b-44ec0804a21f", "control-id": "cis_rhel10_2-1.17", "description": "REPLACE_ME", "props": [ @@ -6081,7 +6152,7 @@ ] }, { - "uuid": "3a1ea3e3-de6b-4569-b775-2b08e11dae1c", + "uuid": "1ccd3469-733b-4520-8ec6-1a465b8df4b8", "control-id": "cis_rhel10_2-1.18", "description": "REPLACE_ME", "props": [ @@ -6103,7 +6174,7 @@ ] }, { - "uuid": "608d7302-b418-446d-9122-a6df6c91301f", + "uuid": "6c3d6a6d-724f-4494-879c-df76731b9e6b", "control-id": "cis_rhel10_2-1.21", "description": "The rule has_nonlocal_mta currently checks for services listening only on port 25,\nbut the policy checks also for ports 465 and 587", "props": [ @@ -6125,7 +6196,7 @@ ] }, { - "uuid": "4f65b49e-0586-4316-a3b7-339477be93be", + "uuid": "f41ba646-06a2-45ab-b6ac-ed66bc7d2d91", "control-id": "cis_rhel10_2-1.22", "description": "REPLACE_ME", "props": [ @@ -6138,7 +6209,7 @@ ] }, { - "uuid": "8f1fec78-988e-44f6-a129-c55f58342fd6", + "uuid": "d9093823-4792-4116-94c8-1dd76b37a751", "control-id": "cis_rhel10_2-2.1", "description": "REPLACE_ME", "props": [ @@ -6155,21 +6226,9 @@ ] }, { - "uuid": "4df68a02-bbee-44eb-955d-3d4b42467701", + "uuid": "ecfb6aca-b656-4949-af69-43138e5bab97", "control-id": "cis_rhel10_2-2.3", "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - } - ] - }, - { - "uuid": "cdc01f69-5ca3-4f11-b6b4-44aec17c3b0d", - "control-id": "cis_rhel10_2-2.4", - "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -6184,8 +6243,8 @@ ] }, { - "uuid": "1c5fe78c-f486-4189-80e5-4ae2b043223e", - "control-id": "cis_rhel10_2-2.5", + "uuid": "0cfbfa7e-5ea9-444a-8ac8-fae71ab33bc7", + "control-id": "cis_rhel10_2-2.4", "description": "REPLACE_ME", "props": [ { @@ -6201,7 +6260,7 @@ ] }, { - "uuid": "78f2ef94-3825-4894-8cc0-83661b4f85e1", + "uuid": "8275b038-5ff6-418c-b110-691e67dceb03", "control-id": "cis_rhel10_2-3.1", "description": "REPLACE_ME", "props": [ @@ -6213,7 +6272,7 @@ ] }, { - "uuid": "95b78d17-8ee9-4df6-8cb9-65ce7fe99abd", + "uuid": "7f241ebd-150f-4443-871f-8378e64a6d54", "control-id": "cis_rhel10_2-3.2", "description": "REPLACE_ME", "props": [ @@ -6230,7 +6289,7 @@ ] }, { - "uuid": "b6e9d36b-96b2-4d94-bf34-44ef735a9c2d", + "uuid": "41bf1ea8-711c-4cef-8d16-595e854baecc", "control-id": "cis_rhel10_2-3.3", "description": "REPLACE_ME", "props": [ @@ -6247,7 +6306,7 @@ ] }, { - "uuid": "11fb1cb6-5459-42f4-a052-e690656bbd92", + "uuid": "31123679-fbd3-4c2a-b71d-e02d536f2206", "control-id": "cis_rhel10_2-4.1.1", "description": "REPLACE_ME", "props": [ @@ -6269,7 +6328,7 @@ ] }, { - "uuid": "a09d3723-3670-46d1-89c9-cdbfa33d1ca1", + "uuid": "11095043-b6d9-4d70-b473-fa87a40ae594", "control-id": "cis_rhel10_2-4.1.2", "description": "REPLACE_ME", "props": [ @@ -6296,7 +6355,7 @@ ] }, { - "uuid": "5b67d949-1ff0-45ae-9b0f-c60b066f5e92", + "uuid": "3f95f317-ab37-4f6b-b282-669ccb34aeb2", "control-id": "cis_rhel10_2-4.1.3", "description": "REPLACE_ME", "props": [ @@ -6323,7 +6382,7 @@ ] }, { - "uuid": "cdc75ec7-215a-47aa-b70d-c90b80339c8d", + "uuid": "4a342b58-feef-4072-8868-9ad015688e2e", "control-id": "cis_rhel10_2-4.1.4", "description": "REPLACE_ME", "props": [ @@ -6350,7 +6409,7 @@ ] }, { - "uuid": "a2fb5b99-5dff-46d4-aa52-e9d0e9fcd1c7", + "uuid": "a7ac28f9-11d9-40d1-a747-8723639e7198", "control-id": "cis_rhel10_2-4.1.5", "description": "REPLACE_ME", "props": [ @@ -6377,7 +6436,7 @@ ] }, { - "uuid": "5ad2badf-1934-423d-b79b-d7c69faaac87", + "uuid": "ca299622-5bb5-4a26-b4df-95d0b77e777e", "control-id": "cis_rhel10_2-4.1.6", "description": "REPLACE_ME", "props": [ @@ -6404,34 +6463,20 @@ ] }, { - "uuid": "a0319880-e9af-4647-9f78-39dde5b04015", + "uuid": "6ebcd789-0724-4813-aabf-3f20b871d090", "control-id": "cis_rhel10_2-4.1.7", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_d" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_d" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_d" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "b326cb8c-524c-41da-9495-792c7bf8243f", + "uuid": "f7834373-f7ed-486b-84a1-5d871af7b743", "control-id": "cis_rhel10_2-4.1.8", "description": "REPLACE_ME", "props": [ @@ -6443,32 +6488,22 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_cron_deny_not_exist" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_cron_allow_exists" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_allow" + "value": "file_groupowner_cron_d" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_allow" + "value": "file_owner_cron_d" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_allow" + "value": "file_permissions_cron_d" } ] }, { - "uuid": "50ed9be7-d9cf-46ab-9b78-0016b4ba91bd", + "uuid": "cbfaa9fb-73fb-4887-b112-de505019e41d", "control-id": "cis_rhel10_2-4.2.1", "description": "It is necessary to create a rule to ensure the existence of at.allow.\nfile_cron_allow_exists can be used as reference for a new templated rule.", "props": [ @@ -6500,7 +6535,7 @@ ] }, { - "uuid": "2b27ba20-5803-482f-b785-5ff5d8a6c6ba", + "uuid": "b60e6776-57f2-4b58-a245-87bf3c51bb8d", "control-id": "cis_rhel10_3-1.1", "description": "REPLACE_ME", "props": [ @@ -6513,7 +6548,7 @@ ] }, { - "uuid": "00ee65f1-5901-4b03-9805-703a46ddd0ec", + "uuid": "e8799611-c053-4ead-ba6c-f3099bc683e2", "control-id": "cis_rhel10_3-1.2", "description": "REPLACE_ME", "props": [ @@ -6530,7 +6565,7 @@ ] }, { - "uuid": "fcd78332-cb27-4076-a338-aae663771e76", + "uuid": "b67d23e7-58a4-402d-bdd3-c9f7ae146535", "control-id": "cis_rhel10_3-1.3", "description": "REPLACE_ME", "props": [ @@ -6547,8 +6582,8 @@ ] }, { - "uuid": "4e51fa4c-9623-403c-bac4-4ab66217e155", - "control-id": "cis_rhel10_3-3.1", + "uuid": "63396a10-7d72-41a9-9054-91fba6fd9822", + "control-id": "cis_rhel10_4-1.1", "description": "REPLACE_ME", "props": [ { @@ -6559,18 +6594,26 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_ip_forward" - }, + "value": "package_firewalld_installed" + } + ] + }, + { + "uuid": "da5d9da4-8da5-431d-a4cd-807bd001fd0d", + "control-id": "cis_rhel10_4-1.2", + "description": "REPLACE_ME", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_forwarding" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "657a7d32-36b8-4de5-b01c-511ae9055d36", - "control-id": "cis_rhel10_3-3.2", + "uuid": "2d16bc4e-2adc-48e0-84f4-907295dff250", + "control-id": "cis_rhel10_5-1.1", "description": "REPLACE_ME", "props": [ { @@ -6581,18 +6624,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_send_redirects" + "value": "file_groupowner_sshd_config" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_owner_sshd_config" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_send_redirects" + "value": "file_permissions_sshd_config" } ] }, { - "uuid": "22e43202-3090-4d72-a62a-96c2fb41753a", - "control-id": "cis_rhel10_3-3.3", + "uuid": "57aac11e-d794-424b-b9b1-931b2f84d879", + "control-id": "cis_rhel10_5-1.2", "description": "REPLACE_ME", "props": [ { @@ -6603,30 +6651,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses" - } - ] - }, - { - "uuid": "131415f9-9df4-4529-8eac-3ec0758744a3", - "control-id": "cis_rhel10_3-3.4", - "description": "REPLACE_ME", - "props": [ + "value": "file_groupownership_sshd_private_key" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "file_ownership_sshd_private_key" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts" + "value": "file_permissions_sshd_private_key" } ] }, { - "uuid": "76a04c1b-6b33-4711-a861-33d5d09ca91a", - "control-id": "cis_rhel10_3-3.5", + "uuid": "859bffc1-6d08-4a41-b941-0c16a37b307c", + "control-id": "cis_rhel10_5-1.3", "description": "REPLACE_ME", "props": [ { @@ -6637,28 +6678,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_accept_redirects" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_accept_redirects" + "value": "file_groupownership_sshd_pub_key" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_redirects" + "value": "file_ownership_sshd_pub_key" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_redirects" + "value": "file_permissions_sshd_pub_key" } ] }, { - "uuid": "b6a15b8f-523a-4712-98ca-81d23c8ce202", - "control-id": "cis_rhel10_3-3.6", + "uuid": "a19ef67b-80da-41ea-87a2-911a2829d072", + "control-id": "cis_rhel10_5-1.4", "description": "REPLACE_ME", "props": [ { @@ -6669,18 +6705,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_secure_redirects" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_secure_redirects" + "value": "sshd_limit_user_access" } ] }, { - "uuid": "7b525298-b1e7-468a-92ca-c6ad8f8ea485", - "control-id": "cis_rhel10_3-3.7", + "uuid": "6132249d-d919-4d3c-ba92-1ea567875c0e", + "control-id": "cis_rhel10_5-1.5", "description": "REPLACE_ME", "props": [ { @@ -6691,72 +6722,65 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_rp_filter" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_rp_filter" + "value": "sshd_enable_warning_banner_net" } ] }, { - "uuid": "e2e07ca2-dc2e-4182-bee7-78a086ca8309", - "control-id": "cis_rhel10_3-3.8", - "description": "REPLACE_ME", + "uuid": "e0eb6fdf-226c-4321-ba31-e610b1ff1661", + "control-id": "cis_rhel10_5-1.6", + "description": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_accept_source_route" - }, + } + ] + }, + { + "uuid": "6131cc6d-5bfd-4b37-bb17-f6d8524bcbbe", + "control-id": "cis_rhel10_5-1.7", + "description": "The requirement gives an example of 45 seconds, but is flexible about the values. It is only\nnecessary to ensure there is a timeout configured in alignment to the site policy.", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_accept_source_route" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_source_route" + "value": "sshd_set_idle_timeout" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_source_route" + "value": "sshd_set_keepalive" } ] }, { - "uuid": "2d3bc3bc-a841-4317-b319-0d21c8631681", - "control-id": "cis_rhel10_3-3.9", + "uuid": "d8626dc3-8dbb-431d-9dfe-a591e0de6262", + "control-id": "cis_rhel10_5-1.12", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_log_martians" + "value": "alternative", + "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_log_martians" + "value": "sshd_use_strong_kex" } ] }, { - "uuid": "e5e6245a-461c-42d1-9a9b-df716fd0ff39", - "control-id": "cis_rhel10_3-3.10", + "uuid": "9cff5cb6-cd1b-40bd-9d50-7023f3904c0e", + "control-id": "cis_rhel10_5-1.13", "description": "REPLACE_ME", "props": [ { @@ -6767,14 +6791,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_tcp_syncookies" + "value": "sshd_set_login_grace_time" } ] }, { - "uuid": "0daaae18-d8a7-4c60-90a9-5792f543505a", - "control-id": "cis_rhel10_3-3.11", - "description": "REPLACE_ME", + "uuid": "bc2bff2f-a02a-40d4-9435-c585ac279937", + "control-id": "cis_rhel10_5-1.14", + "description": "The CIS benchmark is not opinionated about which loglevel is selected here. Here, this\nprofile uses VERBOSE by default, as it allows for the capture of login and logout activity\nas well as key fingerprints.", "props": [ { "name": "implementation-status", @@ -6784,35 +6808,31 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_ra" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_ra" + "value": "sshd_set_loglevel_verbose" } ] }, { - "uuid": "b49160a0-b5a6-4fc1-bb92-5b3d8df69b2d", - "control-id": "cis_rhel10_4-1.1", + "uuid": "981cb52d-c730-4a61-be6b-48de73ef93c5", + "control-id": "cis_rhel10_5-1.15", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "alternative", + "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_nftables_installed" + "value": "sshd_use_strong_macs" } ] }, { - "uuid": "ceb080bf-570f-4765-a24d-97e01bd91a23", - "control-id": "cis_rhel10_4-1.2", + "uuid": "359444af-5f04-47d3-b283-00531c1d5737", + "control-id": "cis_rhel10_5-1.16", "description": "REPLACE_ME", "props": [ { @@ -6823,36 +6843,47 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_firewalld_enabled" - }, + "value": "sshd_set_max_auth_tries" + } + ] + }, + { + "uuid": "1e7acf42-3e17-4605-ba33-90e5e9240962", + "control-id": "cis_rhel10_5-1.17", + "description": "REPLACE_ME", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_firewalld_installed" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_nftables_disabled" + "value": "sshd_set_maxstartups" } ] }, { - "uuid": "ad72d5fb-aa5d-4902-abc3-48fc3b5442f2", - "control-id": "cis_rhel10_4-2.1", + "uuid": "a07739de-f6fc-4c3a-b039-c85fcfe0c3e1", + "control-id": "cis_rhel10_5-1.18", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_set_max_sessions" } ] }, { - "uuid": "5c4dd666-8675-4db9-8696-23a4870ccb0b", - "control-id": "cis_rhel10_4-2.2", + "uuid": "826e0fdb-ad2a-49f8-a578-42a592cab986", + "control-id": "cis_rhel10_5-1.19", "description": "REPLACE_ME", "props": [ { @@ -6863,67 +6894,81 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "firewalld_loopback_traffic_trusted" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "firewalld_loopback_traffic_restricted" + "value": "sshd_disable_empty_passwords" } ] }, { - "uuid": "58559e2c-1872-4511-b8cd-58a82f3278da", - "control-id": "cis_rhel10_4-3.1", - "description": "RHEL systems use firewalld for firewall management. Although nftables is the default\nback-end for firewalld, it is not recommended to use nftables directly when firewalld\nis in use. When using firewalld the base chains are installed by default.", + "uuid": "99a002e3-4fbb-4207-953a-43c89e1e5dcb", + "control-id": "cis_rhel10_5-1.20", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_disable_root_login" } ] }, { - "uuid": "16f80df7-b5cb-419a-b45e-b7a20f703226", - "control-id": "cis_rhel10_4-3.2", + "uuid": "99865752-d469-41b6-ad37-0d74b53a5858", + "control-id": "cis_rhel10_5-1.21", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_do_not_permit_user_env" } ] }, { - "uuid": "abf59cc8-fa13-4663-b293-768285a825eb", - "control-id": "cis_rhel10_4-3.3", - "description": "RHEL systems use firewalld for firewall management. Although nftables is the default\nback-end for firewalld, it is not recommended to use nftables directly when firewalld\nis in use.", + "uuid": "99f572ee-d797-424e-bba8-bc26df0e0137", + "control-id": "cis_rhel10_5-1.22", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_enable_pam" } ] }, { - "uuid": "aaf77db8-e88e-4f31-ab61-b453078a690a", - "control-id": "cis_rhel10_4-3.4", - "description": "RHEL systems use firewalld for firewall management. Although nftables is the default\nback-end for firewalld, it is not recommended to use nftables directly when firewalld\nis in use.", + "uuid": "8f59a05f-8cef-4789-99da-65de6e8143e8", + "control-id": "cis_rhel10_5-2.1", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "package_sudo_installed" } ] }, { - "uuid": "c18cf45b-208a-4586-9e80-d1d2db3a27dd", - "control-id": "cis_rhel10_5-1.1", + "uuid": "014258f7-0f3d-4323-83e0-bcc33c401f06", + "control-id": "cis_rhel10_5-2.2", "description": "REPLACE_ME", "props": [ { @@ -6934,23 +6979,30 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_sshd_config" - }, + "value": "sudo_add_use_pty" + } + ] + }, + { + "uuid": "bdd9d274-438d-43b1-820f-03a3d4e27106", + "control-id": "cis_rhel10_5-2.3", + "description": "REPLACE_ME", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_sshd_config" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_config" + "value": "sudo_custom_logfile" } ] }, { - "uuid": "8355e859-ab35-47e8-8e3a-d856a65226ca", - "control-id": "cis_rhel10_5-1.2", + "uuid": "373fb3ca-219c-40c0-8ea1-3717037d3bd6", + "control-id": "cis_rhel10_5-2.5", "description": "REPLACE_ME", "props": [ { @@ -6961,24 +7013,31 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_private_key" - }, + "value": "sudo_require_authentication" + } + ] + }, + { + "uuid": "a5f4f99a-f608-467f-ac6f-414c0301ca9b", + "control-id": "cis_rhel10_5-2.6", + "description": "REPLACE_ME", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_private_key" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_sshd_private_key" + "value": "sudo_require_reauthentication" } ] }, { - "uuid": "a193f26a-7951-4bff-a44d-055c46dfee00", - "control-id": "cis_rhel10_5-1.3", - "description": "REPLACE_ME", + "uuid": "126e93bd-ad27-4b2e-bfb5-d942ab7aa6a5", + "control-id": "cis_rhel10_5-2.7", + "description": "Members of \"wheel\" or GID 0 groups are checked by default if the group option is not set for\npam_wheel.so module. The recommendation states the group should be empty to reinforce the\nuse of \"sudo\" for privileged access. Therefore, members of these groups should be manually\nchecked or a different group should be informed.", "props": [ { "name": "implementation-status", @@ -6988,72 +7047,69 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_pub_key" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_pub_key" + "value": "use_pam_wheel_group_for_su" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_sshd_pub_key" + "value": "ensure_pam_wheel_group_empty" } ] }, { - "uuid": "bc0a14ea-d24f-4896-8660-7c8b6a418466", - "control-id": "cis_rhel10_5-1.4", - "description": "REPLACE_ME", + "uuid": "8b475c2d-ed03-45db-b997-f19d84cc5399", + "control-id": "cis_rhel10_5-3.1.1", + "description": "This requirement is hard to be automated without any specific requirement. The policy even\nstates that provided commands are examples, other custom settings might be in place and the\nsettings might be different depending on site policies. The other rules will already make\nsure there is a correct autheselect profile regardless of the existing settings. It is\nnecessary to better discuss with CIS Community.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." + "value": "partial" } ] }, { - "uuid": "59e1c5a9-d672-45d6-823a-0fd119a73b3c", - "control-id": "cis_rhel10_5-1.5", - "description": "REPLACE_ME", + "uuid": "01fe57d6-8974-440d-b770-8e06766992e5", + "control-id": "cis_rhel10_5-3.1.2", + "description": "This requirement is also indirectly satisfied by the requirement 5.3.2.1.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_kex" + "value": "account_password_pam_faillock_password_auth" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "account_password_pam_faillock_system_auth" } ] }, { - "uuid": "f5492bbc-1d8a-4861-999b-184d8c6df963", - "control-id": "cis_rhel10_5-1.6", - "description": "REPLACE_ME", + "uuid": "aa83d8cd-6bbe-4d9a-b25d-c9f3dfdde2bf", + "control-id": "cis_rhel10_5-3.1.3", + "description": "This requirement is also indirectly satisfied by the requirement 5.3.2.2.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_macs" + "value": "package_pam_pwquality_installed" } ] }, { - "uuid": "e9006081-5b0e-433d-999c-2fe2134cc476", - "control-id": "cis_rhel10_5-1.7", + "uuid": "46e6013a-82bc-40d9-a722-59562cf1a800", + "control-id": "cis_rhel10_5-4.1.1", "description": "REPLACE_ME", "props": [ { @@ -7064,13 +7120,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_limit_user_access" + "value": "accounts_maximum_age_login_defs" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_password_set_max_life_existing" } ] }, { - "uuid": "ce9f36ec-d430-42c8-9ec9-0c5901a2ea00", - "control-id": "cis_rhel10_5-1.8", + "uuid": "9c1dba52-9022-49f7-87ee-9181c526e06d", + "control-id": "cis_rhel10_5-4.1.3", "description": "REPLACE_ME", "props": [ { @@ -7081,14 +7142,19 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_enable_warning_banner_net" + "value": "accounts_password_warn_age_login_defs" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_password_set_warn_age_existing" } ] }, { - "uuid": "f100ea7f-c662-4109-b5a4-1ae173874566", - "control-id": "cis_rhel10_5-1.9", - "description": "The requirement gives an example of 45 seconds, but is flexible about the values. It is only\nnecessary to ensure there is a timeout configured in alignment to the site policy.", + "uuid": "233ae93b-6932-428c-b253-8eea4a490862", + "control-id": "cis_rhel10_5-4.1.4", + "description": "There's a \"new\" set of options in /etc/login.defs file to define the number of iterations\nperformed during the hashing process.", "props": [ { "name": "implementation-status", @@ -7098,18 +7164,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_idle_timeout" + "value": "set_password_hashing_algorithm_libuserconf" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_keepalive" + "value": "set_password_hashing_algorithm_logindefs" } ] }, { - "uuid": "cfc6d91d-4e64-479f-8c37-1b28ddfb078d", - "control-id": "cis_rhel10_5-1.12", + "uuid": "a5b61083-85ab-4ee4-bbfd-10ded5816a71", + "control-id": "cis_rhel10_5-4.1.5", "description": "REPLACE_ME", "props": [ { @@ -7120,13 +7186,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "disable_host_auth" + "value": "account_disable_post_pw_expiration" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_set_post_pw_existing" } ] }, { - "uuid": "6b2897eb-1ea6-4e96-aca3-91749aa61dc2", - "control-id": "cis_rhel10_5-1.13", + "uuid": "651c752f-fa00-4e9a-b4b2-2f0e12dce4b7", + "control-id": "cis_rhel10_5-4.1.6", "description": "REPLACE_ME", "props": [ { @@ -7137,13 +7208,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_rhosts" + "value": "accounts_password_last_change_is_in_past" } ] }, { - "uuid": "135c7a84-b1b7-4593-b329-ea725005f0a9", - "control-id": "cis_rhel10_5-1.14", + "uuid": "dc6a64dd-1ed8-493b-95d6-532e57d19e91", + "control-id": "cis_rhel10_5-4.2.1", "description": "REPLACE_ME", "props": [ { @@ -7154,30 +7225,30 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_login_grace_time" + "value": "accounts_no_uid_except_zero" } ] }, { - "uuid": "e6c22c0b-4870-4084-adbb-9a7b8bb9f974", - "control-id": "cis_rhel10_5-1.15", - "description": "The CIS benchmark is not opinionated about which loglevel is selected here. Here, this\nprofile uses VERBOSE by default, as it allows for the capture of login and logout activity\nas well as key fingerprints.", + "uuid": "135f0ba7-a7a2-4610-a559-1417211fd7f2", + "control-id": "cis_rhel10_5-4.2.2", + "description": "The rule confirms the primary group for root, but doesn't check if any other user are also\nusing GID 0. New rule is necessary.\nThere is assessment but no automated remediation for this rule and this sounds reasonable.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "partial" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_loglevel_verbose" + "value": "accounts_root_gid_zero" } ] }, { - "uuid": "54323988-9193-40ac-bb25-ea9459b12b02", - "control-id": "cis_rhel10_5-1.16", + "uuid": "38e9bfdd-25a0-43e0-ac64-1c22bda98512", + "control-id": "cis_rhel10_5-4.2.3", "description": "REPLACE_ME", "props": [ { @@ -7188,13 +7259,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_max_auth_tries" + "value": "groups_no_zero_gid_except_root" } ] }, { - "uuid": "b6a47c79-46a2-4866-9b0e-ed77394c7662", - "control-id": "cis_rhel10_5-1.17", + "uuid": "77195da4-1489-4d09-b965-0a71780cd66c", + "control-id": "cis_rhel10_5-4.2.4", "description": "REPLACE_ME", "props": [ { @@ -7205,13 +7276,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_maxstartups" + "value": "ensure_root_password_configured" } ] }, { - "uuid": "5093fb8b-91a6-4714-8281-446cc613a160", - "control-id": "cis_rhel10_5-1.18", + "uuid": "c9fd74b8-070d-4f93-a6a2-28030dbd80ee", + "control-id": "cis_rhel10_5-4.2.5", "description": "REPLACE_ME", "props": [ { @@ -7222,13 +7293,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_max_sessions" + "value": "accounts_root_path_dirs_no_write" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "root_path_no_dot" } ] }, { - "uuid": "4fc13a06-2e39-43c8-bccd-15e5662817ee", - "control-id": "cis_rhel10_5-1.19", + "uuid": "c0b12144-26b4-43e5-b98b-2c2180d5f415", + "control-id": "cis_rhel10_5-4.2.6", "description": "REPLACE_ME", "props": [ { @@ -7239,13 +7315,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_empty_passwords" + "value": "accounts_umask_root" } ] }, { - "uuid": "9b868dd7-987c-4bd7-b15f-21003fa7ecc9", - "control-id": "cis_rhel10_5-1.20", + "uuid": "7c2f7ffc-78d5-4f8e-ab29-91974199eeed", + "control-id": "cis_rhel10_5-4.2.7", "description": "REPLACE_ME", "props": [ { @@ -7256,47 +7332,30 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_root_login" - } - ] - }, - { - "uuid": "b466af35-ad13-4af9-8100-d77d3933c4ad", - "control-id": "cis_rhel10_5-1.21", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "no_password_auth_for_systemaccounts" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_do_not_permit_user_env" + "value": "no_shelllogin_for_systemaccounts" } ] }, { - "uuid": "58514288-5bc2-4149-85e0-d05007e14f17", - "control-id": "cis_rhel10_5-1.22", - "description": "REPLACE_ME", + "uuid": "4be4788b-9b88-40d5-b412-a384154700b4", + "control-id": "cis_rhel10_5-4.2.8", + "description": "New rule is necessary.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_enable_pam" } ] }, { - "uuid": "6f0da533-fb8d-489f-9fde-dc9e55e884e3", - "control-id": "cis_rhel10_5-2.1", + "uuid": "b6a16091-762f-460c-a897-588720b6026e", + "control-id": "cis_rhel10_5-4.3.2", "description": "REPLACE_ME", "props": [ { @@ -7307,13 +7366,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_sudo_installed" + "value": "accounts_tmout" } ] }, { - "uuid": "f8343913-3090-4a90-bd5c-4e803f9c033f", - "control-id": "cis_rhel10_5-2.2", + "uuid": "365ba39d-6fc1-48dc-aa59-ce9841c63745", + "control-id": "cis_rhel10_5-4.3.3", "description": "REPLACE_ME", "props": [ { @@ -7324,30 +7383,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_add_use_pty" - } - ] - }, - { - "uuid": "745213d8-93cd-4d1b-b5e4-a27117201712", - "control-id": "cis_rhel10_5-2.3", - "description": "REPLACE_ME", - "props": [ + "value": "accounts_umask_etc_bashrc" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "accounts_umask_etc_login_defs" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_custom_logfile" + "value": "accounts_umask_etc_profile" } ] }, { - "uuid": "ebe76270-6359-47c6-845d-acacc40553d1", - "control-id": "cis_rhel10_5-2.5", + "uuid": "3d0f3727-33c0-47e1-a63d-2e566d692d7f", + "control-id": "cis_rhel10_6-1.1", "description": "REPLACE_ME", "props": [ { @@ -7358,31 +7410,19 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_require_reauthentication" - } - ] - }, - { - "uuid": "7d3e88ae-76d3-44cd-854a-16634704d5d8", - "control-id": "cis_rhel10_5-2.6", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "package_aide_installed" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_require_reauthentication" + "value": "aide_build_database" } ] }, { - "uuid": "a1ed63aa-d74f-4c83-8e14-cbd571efaafa", - "control-id": "cis_rhel10_5-2.7", - "description": "Members of \"wheel\" or GID 0 groups are checked by default if the group option is not set for\npam_wheel.so module. The recommendation states the group should be empty to reinforce the\nuse of \"sudo\" for privileged access. Therefore, members of these groups should be manually\nchecked or a different group should be informed.", + "uuid": "d79fa188-6054-4c82-862f-d2060b76833f", + "control-id": "cis_rhel10_6-1.2", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -7392,132 +7432,99 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "use_pam_wheel_group_for_su" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_pam_wheel_group_empty" + "value": "aide_periodic_cron_checking" } ] }, { - "uuid": "d70e82f0-1641-45bd-ba8a-2187119b789c", - "control-id": "cis_rhel10_5-3.1.1", + "uuid": "f0fe9709-0560-41e2-826a-fa8caadcb23d", + "control-id": "cis_rhel10_6-1.3", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary a new rule to ensure PAM package is updated." - } - ] - }, - { - "uuid": "cbadcdf1-97af-4c4e-9ac9-9f22c8e2cf5f", - "control-id": "cis_rhel10_5-3.1.2", - "description": "REPLACE_ME", - "props": [ + "value": "implemented" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary a new rule to ensure authselect package is updated." + "value": "aide_check_audit_tools" } ] }, { - "uuid": "8803d7f6-11cc-4f62-8be4-2f9e300bc7f8", - "control-id": "cis_rhel10_5-3.1.3", + "uuid": "5e827877-4c64-4628-88af-386463316270", + "control-id": "cis_rhel10_6-2.1.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary a new rule to ensure libpwquality package is updated." + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_pam_pwquality_installed" - } - ] - }, - { - "uuid": "2740a94a-be4e-465c-8a25-7959503c7e15", - "control-id": "cis_rhel10_5-3.2.1", - "description": "This requirement is hard to be automated without any specific requirement. The policy even\nstates that provided commands are examples, other custom settings might be in place and the\nsettings might be different depending on site policies. The other rules will already make\nsure there is a correct autheselect profile regardless of the existing settings. It is\nnecessary to better discuss with CIS Community.", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "service_systemd-journald_enabled" } ] }, { - "uuid": "09da7f73-98da-4403-8006-a33cce5d0b37", - "control-id": "cis_rhel10_5-3.2.2", - "description": "This requirement is also indirectly satisfied by the requirement 5.3.3.1.", + "uuid": "83522e34-ea4c-4c72-9915-fe8b4d3612b2", + "control-id": "cis_rhel10_6-2.1.2", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_password_auth" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_system_auth" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "a29bf8ce-afe3-44c3-bbf4-6cbfcdc7a1b2", - "control-id": "cis_rhel10_5-3.2.3", - "description": "This requirement is also indirectly satisfied by the requirement 5.3.3.2.", + "uuid": "73577f04-494d-44c3-a011-01f59c2ff28f", + "control-id": "cis_rhel10_6-2.1.3", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "bc52b1d9-b2c4-4d00-be36-a3e81e68a9a0", - "control-id": "cis_rhel10_5-3.2.4", - "description": "The module is properly enabled by the rules mentioned in related_rules.\nRequirements in 5.3.3.3 use these rules.", + "uuid": "e643dbbb-d8da-406a-b1c8-f9c18293176f", + "control-id": "cis_rhel10_6-2.1.4", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "alternative", + "remarks": "It is necessary to create a new rule to check the status of journald and rsyslog.\nIt would also be necessary a new rule to disable or remove rsyslog." } ] }, { - "uuid": "4316625a-bda1-4478-9700-191c0e0aea80", - "control-id": "cis_rhel10_5-3.2.5", - "description": "This module is always present by default. It is necessary to investigate if a new rule to\ncheck its existence needs to be created. But so far the rule no_empty_passwords, used in\n5.3.3.4 can ensure this requirement is attended.", + "uuid": "490308f7-de4a-4447-b2da-53f77f9b55d8", + "control-id": "cis_rhel10_6-2.2.2", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "alternative", + "remarks": "This rule conflicts with 6.2.3.3. More investigation is needed to properly solve this." } ] }, { - "uuid": "42022335-fe5f-4a67-b5be-78be150ced54", - "control-id": "cis_rhel10_5-3.3.1.1", + "uuid": "3d2fd4ce-96f9-465e-9db7-5ee224ab7989", + "control-id": "cis_rhel10_6-2.2.3", "description": "REPLACE_ME", "props": [ { @@ -7528,14 +7535,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_deny" + "value": "journald_compress" } ] }, { - "uuid": "14ea15f0-b38d-475a-97df-75495fd1f302", - "control-id": "cis_rhel10_5-3.3.1.2", - "description": "The policy also accepts value 0, which means the locked accounts should be manually unlocked\nby an administrator. However, it also mentions that using value 0 can facilitate a DoS\nattack to legitimate users.", + "uuid": "2cf4304c-c0f4-417d-9f4d-ea4e510b62eb", + "control-id": "cis_rhel10_6-2.2.4", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -7545,13 +7552,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_unlock_time" + "value": "journald_storage" } ] }, { - "uuid": "84cee391-6584-4bcd-999b-ef219fd099e2", - "control-id": "cis_rhel10_5-3.3.2.1", + "uuid": "7e7c20bf-e336-4b0c-a338-855f7cdb5cd8", + "control-id": "cis_rhel10_6-2.2.1.1", "description": "REPLACE_ME", "props": [ { @@ -7562,47 +7569,39 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_difok" + "value": "package_systemd-journal-remote_installed" } ] }, { - "uuid": "25b0a59f-b7c8-4852-9c94-ce147fd5b5ec", - "control-id": "cis_rhel10_5-3.3.2.2", + "uuid": "e13ef0c2-4b19-4416-ac81-63b1ff6b94f4", + "control-id": "cis_rhel10_6-2.2.1.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_minlen" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "e4578b2e-b7e8-40e1-9fff-9910e1a0c44e", - "control-id": "cis_rhel10_5-3.3.2.3", - "description": "This requirement is expected to be manual. However, in previous versions of the policy\nit was already automated the configuration of \"minclass\" option. This posture was kept for\nRHEL 9 in this new version. Rules related to other options are informed in related_rules.\nIn short, minclass=4 alone can achieve the same result achieved by the combination of the\nother 4 options mentioned in the policy.", + "uuid": "c1c3ad38-1ff2-4a6b-8756-83528ee0c5e4", + "control-id": "cis_rhel10_6-2.2.1.3", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_minclass" + "value": "alternative", + "remarks": "New templated rule is necessary." } ] }, { - "uuid": "64302752-0e85-4aa2-96be-f3e36effcf7c", - "control-id": "cis_rhel10_5-3.3.2.4", + "uuid": "c84a8088-d3f4-4439-8919-3fa2998b3270", + "control-id": "cis_rhel10_6-2.2.1.4", "description": "REPLACE_ME", "props": [ { @@ -7613,138 +7612,113 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_maxrepeat" + "value": "socket_systemd-journal-remote_disabled" } ] }, { - "uuid": "5eb29eac-389b-4e61-9f72-204953ad8487", - "control-id": "cis_rhel10_5-3.3.2.5", + "uuid": "a1576cd5-3bb0-4959-b07b-4988eebd7568", + "control-id": "cis_rhel10_6-2.3.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "planned", - "remarks": "A new templated rule and variable are necessary for the maxsequence option." + "value": "implemented" } ] }, { - "uuid": "9789dfaf-4f4a-4522-8177-276b4caf6a62", - "control-id": "cis_rhel10_5-3.3.2.6", + "uuid": "f84fd6d0-bed6-47a9-9444-e14d4d62e266", + "control-id": "cis_rhel10_6-2.3.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_dictcheck" } ] }, { - "uuid": "295af592-0e6f-4358-85e8-ecbfadd3b8fb", - "control-id": "cis_rhel10_5-3.3.2.7", + "uuid": "1b219716-3f2c-4990-9c35-d83a7aa89eba", + "control-id": "cis_rhel10_6-2.3.3", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_enforce_root" } ] }, { - "uuid": "23b22e15-d804-442e-88a3-aa05ef8a60d6", - "control-id": "cis_rhel10_5-3.3.3.1", - "description": "Although mentioned in the section 5.3.3.3, there is no explicit requirement to configure\nretry option of pam_pwhistory. If come in the future, the rule accounts_password_pam_retry\ncan be used.", + "uuid": "85280635-90e0-4685-a005-fe827d8df13d", + "control-id": "cis_rhel10_6-2.3.4", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_pwhistory_remember_password_auth" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_pwhistory_remember_system_auth" } ] }, { - "uuid": "ff05c396-3212-44c3-912d-1da231010454", - "control-id": "cis_rhel10_5-3.3.3.2", + "uuid": "fca426b5-3d77-4709-af18-da4e992cc0f4", + "control-id": "cis_rhel10_6-2.3.5", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "planned", - "remarks": "A new rule needs to be created to check and remediate the enforce_for_root option in\n/etc/security/pwhistory.conf. accounts_password_pam_enforce_root can be used as reference." + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "e5662485-198b-4fee-9446-f3a06d11554f", - "control-id": "cis_rhel10_5-3.3.3.3", - "description": "In RHEL 9 pam_pwhistory is enabled via authselect feature, as required in 5.3.2.4. The\nfeature automatically set \"use_authok\" option. In any case, we don't have a rule to check\nthis option specifically.", + "uuid": "f8009c20-b38d-4575-9b97-6351295625dc", + "control-id": "cis_rhel10_6-2.3.6", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "3bda1d51-db8f-4bb2-af94-95ef04508730", - "control-id": "cis_rhel10_5-3.3.4.1", - "description": "The rule more specifically used in this requirement also satify the requirement 5.3.2.5.", + "uuid": "d5ba0177-be9c-41ed-8048-5c8419b25641", + "control-id": "cis_rhel10_6-2.3.7", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_empty_passwords" } ] }, { - "uuid": "a49bf018-de2f-47d7-8de1-adf0774bcbbb", - "control-id": "cis_rhel10_5-3.3.4.2", + "uuid": "9c83638a-913f-48a3-b158-36316c784975", + "control-id": "cis_rhel10_6-2.3.8", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "alternative", - "remarks": "Usage of pam_unix.so module together with \"remember\" option is deprecated and is not\nrecommened by this policy. Instead, it should be used remember option of pam_pwhistory\nmodule, as required in 5.3.3.3.1. See here for more details about pam_unix.so:\nhttps://bugzilla.redhat.com/show_bug.cgi?id=1778929\nA new rule needs to be created to remove the remember option from pam_unix module." + "remarks": "REPLACE_ME" } ] }, { - "uuid": "c691ef1a-2612-4e78-83a4-2414aae8c302", - "control-id": "cis_rhel10_5-3.3.4.3", - "description": "Changes in logindefs mentioned in this requirement are more specifically covered by 5.4.1.4", + "uuid": "546e80c4-a0d0-4599-8913-14ecebe7baf3", + "control-id": "cis_rhel10_6-2.4.1", + "description": "It is not harmful to run these rules even if rsyslog is not installed or active.", "props": [ { "name": "implementation-status", @@ -7754,30 +7728,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_systemauth" + "value": "rsyslog_files_groupownership" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_passwordauth" - } - ] - }, - { - "uuid": "238cd639-4d52-4dcd-a2ad-079adff894e9", - "control-id": "cis_rhel10_5-3.3.4.4", - "description": "In RHEL 9 pam_unix is enabled by default in all authselect profiles already with the\nuse_authtok option set. In any case, we don't have a rule to check this option specifically,\nlike in 5.3.3.3.3.", - "props": [ + "value": "rsyslog_files_ownership" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "rsyslog_files_permissions" } ] }, { - "uuid": "b972dc0b-359c-472e-8246-8ff041cd0cb8", - "control-id": "cis_rhel10_5-4.1.1", + "uuid": "12416d70-1ecd-4700-8b81-8d91deccdce0", + "control-id": "cis_rhel10_7-1.1", "description": "REPLACE_ME", "props": [ { @@ -7788,18 +7755,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_maximum_age_login_defs" + "value": "file_groupowner_etc_passwd" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_set_max_life_existing" + "value": "file_owner_etc_passwd" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_etc_passwd" } ] }, { - "uuid": "9ca1ecd5-21a3-42a1-9deb-8e96fc29179f", - "control-id": "cis_rhel10_5-4.1.3", + "uuid": "47ae6319-59be-449c-8f4d-75e6b926b5d1", + "control-id": "cis_rhel10_7-1.2", "description": "REPLACE_ME", "props": [ { @@ -7810,19 +7782,24 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_warn_age_login_defs" + "value": "file_groupowner_backup_etc_passwd" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_set_warn_age_existing" + "value": "file_owner_backup_etc_passwd" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_backup_etc_passwd" } ] }, { - "uuid": "fe03abb5-0990-4dbd-9b1f-e185c9a922ca", - "control-id": "cis_rhel10_5-4.1.4", - "description": "There's a \"new\" set of options in /etc/login.defs file to define the number of iterations\nperformed during the hashing process.", + "uuid": "f744a548-34d6-4ab6-a564-7ac38a7f61fb", + "control-id": "cis_rhel10_7-1.3", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -7832,18 +7809,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_libuserconf" + "value": "file_groupowner_etc_group" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_logindefs" + "value": "file_owner_etc_group" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_etc_group" } ] }, { - "uuid": "e2b7cbbb-eb1a-4c33-8536-512a260982eb", - "control-id": "cis_rhel10_5-4.1.5", + "uuid": "b13e96df-6bcc-407f-a2ed-bf4ead921b09", + "control-id": "cis_rhel10_7-1.4", "description": "REPLACE_ME", "props": [ { @@ -7854,18 +7836,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_disable_post_pw_expiration" + "value": "file_groupowner_backup_etc_group" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_set_post_pw_existing" + "value": "file_owner_backup_etc_group" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_backup_etc_group" } ] }, { - "uuid": "67e1c33d-ae5a-4806-9f3a-4c8afb27027e", - "control-id": "cis_rhel10_5-4.1.6", + "uuid": "73135aad-18a5-4db3-a8a2-24b959c3c007", + "control-id": "cis_rhel10_7-1.5", "description": "REPLACE_ME", "props": [ { @@ -7876,60 +7863,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_last_change_is_in_past" - } - ] - }, - { - "uuid": "c580782d-6488-4560-8b89-24112bf2ac6b", - "control-id": "cis_rhel10_5-4.2.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "file_owner_etc_shadow" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_no_uid_except_zero" - } - ] - }, - { - "uuid": "80a59064-c746-464c-a73f-ab8606c8af77", - "control-id": "cis_rhel10_5-4.2.2", - "description": "The rule confirms the primary group for root, but doesn't check if any other user are also\nusing GID 0. New rule is necessary.\nThere is assessment but no automated remediation for this rule and this sounds reasonable.", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "file_groupowner_etc_shadow" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_root_gid_zero" - } - ] - }, - { - "uuid": "9199e6b2-1c5d-468d-bb43-96707f8ac915", - "control-id": "cis_rhel10_5-4.2.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "New rule is necessary." + "value": "file_permissions_etc_shadow" } ] }, { - "uuid": "3a118bc4-367e-4342-89b0-fb2769b99a24", - "control-id": "cis_rhel10_5-4.2.4", + "uuid": "14457578-35f2-4604-a796-b3ceabe46cce", + "control-id": "cis_rhel10_7-1.6", "description": "REPLACE_ME", "props": [ { @@ -7940,48 +7890,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_root_password_configured" - } - ] - }, - { - "uuid": "80bd880d-fa1f-47c6-bdbc-8770127713f3", - "control-id": "cis_rhel10_5-4.2.5", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "file_groupowner_backup_etc_shadow" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_root_path_dirs_no_write" + "value": "file_owner_backup_etc_shadow" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "root_path_no_dot" - } - ] - }, - { - "uuid": "b5aa4ee3-828f-4947-b8ca-3cc43a86ec16", - "control-id": "cis_rhel10_5-4.2.6", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "There is no rule to ensure umask in /root/.bash_profile and /root/.bashrc. A new rule have\nto be created. It can be based on accounts_umask_interactive_users." + "value": "file_permissions_backup_etc_shadow" } ] }, { - "uuid": "9d848125-c210-4b78-a585-3e8f32985a8f", - "control-id": "cis_rhel10_5-4.2.7", + "uuid": "d3caa3dd-d2d4-40ec-9907-c76cf9887ab5", + "control-id": "cis_rhel10_7-1.7", "description": "REPLACE_ME", "props": [ { @@ -7992,48 +7917,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_password_auth_for_systemaccounts" + "value": "file_groupowner_etc_gshadow" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_shelllogin_for_systemaccounts" - } - ] - }, - { - "uuid": "08c5f3af-e06f-42d2-bddf-35e7d8073e43", - "control-id": "cis_rhel10_5-4.2.8", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "New rule is necessary." - } - ] - }, - { - "uuid": "4c7d1149-7631-44f9-88fa-796b277d0901", - "control-id": "cis_rhel10_5-4.3.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "file_owner_etc_gshadow" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_tmout" + "value": "file_permissions_etc_gshadow" } ] }, { - "uuid": "8104d20c-2610-4e7f-bcbb-f9aae69b1dc1", - "control-id": "cis_rhel10_5-4.3.3", + "uuid": "645f909a-44d0-47ed-a8fc-4f4995309f88", + "control-id": "cis_rhel10_7-1.8", "description": "REPLACE_ME", "props": [ { @@ -8044,23 +7944,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_umask_etc_bashrc" + "value": "file_groupowner_backup_etc_gshadow" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_umask_etc_login_defs" + "value": "file_owner_backup_etc_gshadow" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_umask_etc_profile" + "value": "file_permissions_backup_etc_gshadow" } ] }, { - "uuid": "6391cb51-a4fd-4303-b2f2-f752613f8d71", - "control-id": "cis_rhel10_6-1.1", + "uuid": "0d4d70dd-e7f2-461f-8dfb-9214e29935db", + "control-id": "cis_rhel10_7-1.9", "description": "REPLACE_ME", "props": [ { @@ -8071,18 +7971,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_aide_installed" + "value": "file_groupowner_etc_shells" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "aide_build_database" + "value": "file_owner_etc_shells" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_etc_shells" } ] }, { - "uuid": "0e958518-7da1-4a08-80df-efd8e89f1ed5", - "control-id": "cis_rhel10_6-1.2", + "uuid": "06c10745-3034-442f-839a-6326f61abfc2", + "control-id": "cis_rhel10_7-1.10", "description": "REPLACE_ME", "props": [ { @@ -8093,13 +7998,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "aide_periodic_cron_checking" + "value": "file_etc_security_opasswd" } ] }, { - "uuid": "aeb27474-6692-407b-927b-36a0b0c07789", - "control-id": "cis_rhel10_6-1.3", + "uuid": "4444bd92-ef6f-4aad-af9d-e177a4eac9d1", + "control-id": "cis_rhel10_7-1.11", "description": "REPLACE_ME", "props": [ { @@ -8110,43 +8015,40 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "aide_check_audit_tools" + "value": "file_permissions_unauthorized_world_writable" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "dir_perms_world_writable_sticky_bits" } ] }, { - "uuid": "43f77753-5c01-4755-ba06-c3c82d25802f", - "control-id": "cis_rhel10_6-2.1.1", + "uuid": "305222f5-910d-4899-b501-09cbdd64efeb", + "control-id": "cis_rhel10_7-1.12", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "partial" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_systemd-journald_enabled" - } - ] - }, - { - "uuid": "96add567-d7f0-41d9-ac75-c32068c0e4e3", - "control-id": "cis_rhel10_6-2.1.2", - "description": "REPLACE_ME", - "props": [ + "value": "no_files_unowned_by_user" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "file_permissions_ungroupowned" } ] }, { - "uuid": "5f76b9e9-630c-46f2-b2b3-e4e8c6773b8b", - "control-id": "cis_rhel10_6-2.1.3", + "uuid": "9c3dfb96-7d40-456d-aa30-fa527c2eafa6", + "control-id": "cis_rhel10_7-1.13", "description": "REPLACE_ME", "props": [ { @@ -8158,21 +8060,25 @@ ] }, { - "uuid": "ef17e2f2-d698-4c51-8f45-c8641c3e2e40", - "control-id": "cis_rhel10_6-2.1.4", + "uuid": "5384b15b-28ca-4f6d-aa3a-1b867434fb1a", + "control-id": "cis_rhel10_7-2.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary to create a new rule to check the status of journald and rsyslog.\nIt would also be necessary a new rule to disable or remove rsyslog." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_password_all_shadowed" } ] }, { - "uuid": "0c2a7c9c-5ce8-4fd1-90d5-da249091db73", - "control-id": "cis_rhel10_6-2.2.1.1", + "uuid": "bae4e0f3-b2db-4300-96d4-caf03d4384e8", + "control-id": "cis_rhel10_7-2.2", "description": "REPLACE_ME", "props": [ { @@ -8183,39 +8089,30 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_systemd-journal-remote_installed" + "value": "no_empty_passwords_etc_shadow" } ] }, { - "uuid": "e5a52494-77ee-491c-8d1b-6e2d0de2d55f", - "control-id": "cis_rhel10_6-2.2.1.2", + "uuid": "88248cc7-395d-44e2-a5eb-bd9986379ca1", + "control-id": "cis_rhel10_7-2.3", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } - ] - }, - { - "uuid": "7537a563-94af-4cd2-b19e-69dea5e8332f", - "control-id": "cis_rhel10_6-2.2.1.3", - "description": "REPLACE_ME", - "props": [ + "value": "implemented" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "New templated rule is necessary." + "value": "gid_passwd_group_same" } ] }, { - "uuid": "1eefcaec-4488-427f-802a-bd8a7ad2cb79", - "control-id": "cis_rhel10_6-2.2.1.4", + "uuid": "71a831d1-5d4f-4c16-81fa-d7a7304b4e66", + "control-id": "cis_rhel10_7-2.4", "description": "REPLACE_ME", "props": [ { @@ -8226,26 +8123,30 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "socket_systemd-journal-remote_disabled" + "value": "account_unique_id" } ] }, { - "uuid": "e77e4de0-a39f-4320-a751-2f07041860ee", - "control-id": "cis_rhel10_6-2.2.2", + "uuid": "008f8623-bd92-4809-bac9-40d9d4479621", + "control-id": "cis_rhel10_7-2.5", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "This rule conflicts with 6.2.3.3. More investigation is needed to properly solve this." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "group_unique_id" } ] }, { - "uuid": "38536c59-3e2e-4b1e-ae38-57277758a7db", - "control-id": "cis_rhel10_6-2.2.3", + "uuid": "6f2f9d82-ff42-4c90-b2a6-570653d82b1b", + "control-id": "cis_rhel10_7-2.6", "description": "REPLACE_ME", "props": [ { @@ -8256,13 +8157,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_compress" + "value": "account_unique_name" } ] }, { - "uuid": "7dbb0b8e-9e3c-4383-8c9f-1ec42a8af0e2", - "control-id": "cis_rhel10_6-2.2.4", + "uuid": "93deb0b8-1c4e-436f-ab10-8504f4da2e44", + "control-id": "cis_rhel10_7-2.7", "description": "REPLACE_ME", "props": [ { @@ -8273,603 +8174,41 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_storage" + "value": "group_unique_name" } ] }, { - "uuid": "82a184cc-e9e6-40eb-b75c-3a04b0d4d35a", - "control-id": "cis_rhel10_6-2.3.1", + "uuid": "ae0ba249-94e8-4eaa-ae00-77fd10902f7c", + "control-id": "cis_rhel10_7-2.8", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - } - ] - }, - { - "uuid": "2c619af5-a594-4ab8-ad5d-87b66220a307", - "control-id": "cis_rhel10_6-2.3.2", - "description": "REPLACE_ME", - "props": [ + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - } - ] - }, - { - "uuid": "5283e189-5a2b-4f8f-ba43-4e74a3c5423f", - "control-id": "cis_rhel10_6-2.3.3", - "description": "REPLACE_ME", - "props": [ + "value": "accounts_user_interactive_home_directory_exists" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - } - ] - }, - { - "uuid": "eb2e8a12-14c7-4d7c-990c-e50106619f2e", - "control-id": "cis_rhel10_6-2.3.4", - "description": "REPLACE_ME", - "props": [ + "value": "file_ownership_home_directories" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "file_permissions_home_directories" } ] }, { - "uuid": "69efa666-e0eb-4ae7-8091-4ae426fb7c66", - "control-id": "cis_rhel10_6-2.3.5", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } - ] - }, - { - "uuid": "5a35aa1f-3266-4476-9c92-962f2c061e9b", - "control-id": "cis_rhel10_6-2.3.6", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } - ] - }, - { - "uuid": "1b0cf3af-b92f-4bd2-8072-7a41442ff650", - "control-id": "cis_rhel10_6-2.3.7", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - } - ] - }, - { - "uuid": "78fad276-5d1d-4f0e-99f2-2ccab7737cd7", - "control-id": "cis_rhel10_6-2.3.8", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } - ] - }, - { - "uuid": "87e256d2-c3d2-4abc-9584-52caac7014b1", - "control-id": "cis_rhel10_6-2.4.1", - "description": "It is not harmful to run these rules even if rsyslog is not installed or active.", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "rsyslog_files_groupownership" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "rsyslog_files_ownership" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "rsyslog_files_permissions" - } - ] - }, - { - "uuid": "644b6a69-03ba-4c68-8a73-a2e1d59b1ff6", - "control-id": "cis_rhel10_7-1.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_passwd" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_passwd" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_passwd" - } - ] - }, - { - "uuid": "0049a4b6-3863-4b7f-8e11-cb4fdf32c309", - "control-id": "cis_rhel10_7-1.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_passwd" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_passwd" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_passwd" - } - ] - }, - { - "uuid": "ec7ef2ba-d78d-4a80-8104-26bb3817c740", - "control-id": "cis_rhel10_7-1.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_group" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_group" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_group" - } - ] - }, - { - "uuid": "c1cb95a6-c964-47f8-a28c-4ca5956a8cd3", - "control-id": "cis_rhel10_7-1.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_group" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_group" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_group" - } - ] - }, - { - "uuid": "a26aa4dd-f8c8-4839-8734-0c3306e0dd1f", - "control-id": "cis_rhel10_7-1.5", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_shadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_shadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_shadow" - } - ] - }, - { - "uuid": "ea4dbf2d-dcbd-4713-a754-2d4b89b3841f", - "control-id": "cis_rhel10_7-1.6", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_shadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_shadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_shadow" - } - ] - }, - { - "uuid": "ff5fe5e1-59bc-4147-8fa7-ad742eeaceb9", - "control-id": "cis_rhel10_7-1.7", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_gshadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_gshadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_gshadow" - } - ] - }, - { - "uuid": "38fbf40e-0fd3-44e3-b016-dcb7a30041b6", - "control-id": "cis_rhel10_7-1.8", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_gshadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_gshadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_gshadow" - } - ] - }, - { - "uuid": "05965dc2-5099-487d-8172-95c916fee29c", - "control-id": "cis_rhel10_7-1.9", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_shells" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_shells" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_shells" - } - ] - }, - { - "uuid": "e9d3d300-7ccb-4bac-8c23-c88d024bf2ee", - "control-id": "cis_rhel10_7-1.10", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_etc_security_opasswd" - } - ] - }, - { - "uuid": "8e2ea489-9aee-4d57-8054-27b05bca2327", - "control-id": "cis_rhel10_7-1.11", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_unauthorized_world_writable" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dir_perms_world_writable_sticky_bits" - } - ] - }, - { - "uuid": "9818d14d-06f8-40d0-a002-668884ffdb00", - "control-id": "cis_rhel10_7-1.12", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_files_unowned_by_user" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_ungroupowned" - } - ] - }, - { - "uuid": "67e71ead-1a9a-478e-b0f4-57a454568a9d", - "control-id": "cis_rhel10_7-1.13", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } - ] - }, - { - "uuid": "9e93b180-dcbe-4a75-9679-f8416262b83f", - "control-id": "cis_rhel10_7-2.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_all_shadowed" - } - ] - }, - { - "uuid": "6aff4acd-66e8-4357-91e7-8a8770f8f81e", - "control-id": "cis_rhel10_7-2.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_empty_passwords_etc_shadow" - } - ] - }, - { - "uuid": "9286b7ad-d22e-4e46-9991-8f67d91801ef", - "control-id": "cis_rhel10_7-2.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "gid_passwd_group_same" - } - ] - }, - { - "uuid": "81967d6d-37bd-4e8d-a22a-aff2e3839310", - "control-id": "cis_rhel10_7-2.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_unique_id" - } - ] - }, - { - "uuid": "01c10315-2cb2-44af-bb28-c2c67f58d55c", - "control-id": "cis_rhel10_7-2.5", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "group_unique_id" - } - ] - }, - { - "uuid": "6865094c-17f9-42a5-86e4-b577d48347ed", - "control-id": "cis_rhel10_7-2.6", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_unique_name" - } - ] - }, - { - "uuid": "12e54f23-befe-4eae-9952-a378bcd5da00", - "control-id": "cis_rhel10_7-2.7", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "group_unique_name" - } - ] - }, - { - "uuid": "fe881611-5e9c-4e95-b43f-85ad358bb706", - "control-id": "cis_rhel10_7-2.8", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_user_interactive_home_directory_exists" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_home_directories" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_home_directories" - } - ] - }, - { - "uuid": "c3ea8fa6-dae1-4568-89a3-722637fd7937", - "control-id": "cis_rhel10_7-2.9", - "description": "Missing a rule to check that .bash_history is mode 0600 or more restrictive.", + "uuid": "46e9ad21-4d88-4791-a930-2697f39aa4a8", + "control-id": "cis_rhel10_7-2.9", + "description": "Missing a rule to check that .bash_history is mode 0600 or more restrictive.", "props": [ { "name": "implementation-status", @@ -9047,7 +8386,7 @@ { "name": "Parameter_Value_Alternatives_5", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", + "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel10': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", "remarks": "rule_set_000" }, { @@ -9065,7 +8404,7 @@ { "name": "Parameter_Value_Alternatives_6", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", + "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel10': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", "remarks": "rule_set_000" }, { @@ -9431,8316 +8770,8018 @@ { "name": "Parameter_Id_27", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_account_disable_post_pw_expiration", + "value": "sysctl_net_ipv6_conf_default_forwarding_value", "remarks": "rule_set_000" }, { "name": "Parameter_Description_27", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The number of days to wait after a password expires, until the account will be permanently disabled.", + "value": "Toggle IPv6 default Forwarding", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_27", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'0': '0', 180: 180, 30: 30, 35: 35, 40: 40, 45: 45, 60: 60, 90: 90, 'default': 35}", + "value": "{'default': '0', 'disabled': '0', 'enabled': 1}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_28", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_maximum_age_login_defs", + "value": "var_account_disable_post_pw_expiration", "remarks": "rule_set_000" }, { "name": "Parameter_Description_28", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Maximum age of password in days", + "value": "The number of days to wait after a password expires, until the account will be permanently disabled.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_28", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{365: 365, 120: 120, 180: 180, 90: 90, 60: 60, 45: 45, 'default': 60}", + "value": "{'0': '0', 180: 180, 30: 30, 35: 35, 40: 40, 45: 45, 60: 60, 90: 90, 'default': 35}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_29", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_password_warn_age_login_defs", + "value": "var_accounts_maximum_age_login_defs", "remarks": "rule_set_000" }, { "name": "Parameter_Description_29", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The number of days' warning given before a password expires.", + "value": "Maximum age of password in days", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_29", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "{365: 365, 120: 120, 180: 180, 90: 90, 60: 60, 45: 45, 'default': 60}", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Id_30", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "var_accounts_password_warn_age_login_defs", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Description_30", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "The number of days' warning given before a password expires.", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Value_Alternatives_30", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'0': '0', 14: 14, 10: 10, 7: 7, 'default': 7}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_30", + "name": "Parameter_Id_31", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_accounts_passwords_pam_faillock_deny", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_30", + "name": "Parameter_Description_31", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Number of failed login attempts before account lockout", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_30", + "name": "Parameter_Value_Alternatives_31", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{10: 10, 3: 3, 4: 4, 5: 5, 6: 6, 8: 8, 'default': 3}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_31", + "name": "Parameter_Id_32", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_accounts_passwords_pam_faillock_unlock_time", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_31", + "name": "Parameter_Description_32", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Seconds before automatic unlocking or permanently locking after excessive failed logins", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_31", + "name": "Parameter_Value_Alternatives_32", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{1800: 1800, 3600: 3600, 600: 600, 604800: 604800, 86400: 86400, 900: 900, 300: 300, 'default': 0, 'never': 0}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_32", + "name": "Parameter_Id_33", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_accounts_tmout", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_32", + "name": "Parameter_Description_33", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "In an interactive shell, the value is interpreted as the number of seconds to wait for input after issuing the primary prompt. Bash terminates after waiting for that number of seconds if input does not arrive.", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_32", + "name": "Parameter_Value_Alternatives_33", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'30_min': 1800, '10_min': 600, '15_min': 900, '5_min': 300, 'default': 600}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_33", + "name": "Parameter_Id_34", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_accounts_user_umask", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_33", + "name": "Parameter_Description_34", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enter default user umask", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_33", + "name": "Parameter_Value_Alternatives_34", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'007': '007', '022': '022', '027': '027', '077': '077', 'default': '027'}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_34", + "name": "Parameter_Id_35", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_authselect_profile", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_34", + "name": "Parameter_Description_35", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Specify the authselect profile to select", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_34", + "name": "Parameter_Value_Alternatives_35", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'local': 'local', 'default': 'minimal', 'minimal': 'minimal', 'sssd': 'sssd'}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_35", + "name": "Parameter_Id_36", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_multiple_time_servers", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_35", + "name": "Parameter_Description_36", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "The list of vendor-approved time servers", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_35", + "name": "Parameter_Value_Alternatives_36", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'default': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'generic': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'stig': '0.us.pool.ntp.mil', 'fedora': '0.fedora.pool.ntp.org,1.fedora.pool.ntp.org,2.fedora.pool.ntp.org,3.fedora.pool.ntp.org', 'rhel': '0.rhel.pool.ntp.org,1.rhel.pool.ntp.org,2.rhel.pool.ntp.org,3.rhel.pool.ntp.org', 'ol': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'suse': '0.suse.pool.ntp.org,1.suse.pool.ntp.org,2.suse.pool.ntp.org,3.suse.pool.ntp.org', 'alinux': '0.ntp.cloud.aliyuncs.com,1.ntp.aliyun.com,2.ntp1.aliyun.com,3.ntp1.cloud.aliyuncs.com', 'amazon': '0.rhel.pool.ntp.org,1.rhel.pool.ntp.org,2.rhel.pool.ntp.org,3.rhel.pool.ntp.org', 'ubuntu': '0.ubuntu.pool.ntp.org,1.ubuntu.pool.ntp.org,2.ubuntu.pool.ntp.org,3.ubuntu.pool.ntp.org', 'almalinux': '0.almalinux.pool.ntp.org,1.almalinux.pool.ntp.org,2.almalinux.pool.ntp.org,3.almalinux.pool.ntp.org', 'debian': '0.debian.pool.ntp.org,1.debian.pool.ntp.org,2.debian.pool.ntp.org,3.debian.pool.ntp.org', 'nist': 'time.nist.gov,time-a-g.nist.gov,time-b-g.nist.gov,time-c-g.nist.gov'}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_36", + "name": "Parameter_Id_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_pam_wheel_group_for_su", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_36", + "name": "Parameter_Description_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "pam_wheel module has a parameter called group, which controls which groups can access the su command. This variable holds the valid value for the parameter.", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_36", + "name": "Parameter_Value_Alternatives_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'default': 'sugroup', 'cis': 'sugroup'}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_37", + "name": "Parameter_Id_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_password_hashing_algorithm", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_37", + "name": "Parameter_Description_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Specify the system default encryption algorithm for encrypting passwords. Defines the value set as ENCRYPT_METHOD in /etc/login.defs.", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_37", + "name": "Parameter_Value_Alternatives_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'default': 'SHA512', 'SHA512': 'SHA512', 'SHA256': 'SHA256', 'yescrypt': 'YESCRYPT', 'cis_ubuntu2404': 'SHA512|YESCRYPT'}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_38", + "name": "Parameter_Id_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_password_hashing_algorithm_pam", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_38", + "name": "Parameter_Description_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Specify the system default encryption algorithm for encrypting passwords. Defines the hashing algorithm to be used in pam_unix.so.", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_38", + "name": "Parameter_Value_Alternatives_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'default': 'sha512', 'sha512': 'sha512', 'yescrypt': 'yescrypt'}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_39", + "name": "Parameter_Id_40", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_password_pam_dictcheck", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_39", + "name": "Parameter_Description_40", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Prevent the use of dictionary words for passwords.", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_39", + "name": "Parameter_Value_Alternatives_40", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{1: 1, 'default': 1}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_40", + "name": "Parameter_Id_41", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_password_pam_difok", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_40", + "name": "Parameter_Description_41", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Minimum number of characters not present in old password", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_40", + "name": "Parameter_Value_Alternatives_41", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{15: 15, 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 8: 8, 'default': 8}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_41", + "name": "Parameter_Id_42", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_password_pam_maxrepeat", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_41", + "name": "Parameter_Description_42", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Maximum Number of Consecutive Repeating Characters in a Password", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_41", + "name": "Parameter_Value_Alternatives_42", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{1: 1, 2: 2, 3: 3, 'default': 3}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_42", + "name": "Parameter_Id_43", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_password_pam_minclass", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_42", + "name": "Parameter_Description_43", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Minimum number of categories of characters that must exist in a password", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_42", + "name": "Parameter_Value_Alternatives_43", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{1: 1, 2: 2, 3: 3, 4: 4, 'default': 3}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_43", + "name": "Parameter_Id_44", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_password_pam_minlen", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_43", + "name": "Parameter_Description_44", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Minimum number of characters in password", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_43", + "name": "Parameter_Value_Alternatives_44", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{10: 10, 12: 12, 14: 14, 15: 15, 17: 17, 18: 18, 20: 20, 6: 6, 7: 7, 8: 8, 'default': 15}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_44", + "name": "Parameter_Id_45", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_password_pam_remember", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_44", + "name": "Parameter_Description_45", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Prevent password re-use using password history lookup", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_44", + "name": "Parameter_Value_Alternatives_45", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'0': '0', 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 8: 8, 9: 9, 24: 24, 'default': 5}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_45", + "name": "Parameter_Id_46", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_password_pam_remember_control_flag", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_45", + "name": "Parameter_Description_46", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "'Specify the control flag required for password remember requirement. If multiple values are allowed write them separated by commas as in \"required,requisite\", for remediations the first value will be taken'", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_45", + "name": "Parameter_Value_Alternatives_46", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'required': 'required', 'optional': 'optional', 'requisite': 'requisite', 'sufficient': 'sufficient', 'binding': 'binding', 'ol8': 'required,requisite', 'requisite_or_required': 'requisite,required', 'default': 'requisite'}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_46", + "name": "Parameter_Id_47", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_postfix_inet_interfaces", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_46", + "name": "Parameter_Description_47", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "The setting for inet_interfaces in /etc/postfix/main.cf", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_46", + "name": "Parameter_Value_Alternatives_47", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'loopback-only': 'loopback-only', 'default': 'loopback-only', 'localhost': 'localhost'}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_47", + "name": "Parameter_Id_48", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_screensaver_lock_delay", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_47", + "name": "Parameter_Description_48", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Choose allowed duration (in seconds) after a screensaver becomes active before displaying an authentication prompt", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_47", + "name": "Parameter_Value_Alternatives_48", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'10_seconds': 10, '5_seconds': 5, 'default': '0', 'immediate': '0'}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_48", + "name": "Parameter_Id_49", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_selinux_policy_name", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_48", + "name": "Parameter_Description_49", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Type of policy in use. Possible values are:
targeted - Only targeted network daemons are protected.
strict - Full SELinux protection.
mls - Multiple levels of security", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_48", + "name": "Parameter_Value_Alternatives_49", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'default': 'targeted', 'mls': 'mls', 'targeted': 'targeted'}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_49", + "name": "Parameter_Id_50", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_sshd_max_sessions", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_49", + "name": "Parameter_Description_50", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Specify the maximum number of open sessions permitted.", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_49", + "name": "Parameter_Value_Alternatives_50", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{10: 10, 4: 4, 3: 3, 2: 2, 1: 1, 0: 0, 'default': 10}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_50", + "name": "Parameter_Id_51", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_sshd_set_keepalive", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_50", + "name": "Parameter_Description_51", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Specify the maximum number of idle message counts before session is terminated.", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_50", + "name": "Parameter_Value_Alternatives_51", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "{10: 10, 3: 3, 5: 5, 0: 0, 1: 1, 'default': 0}", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Id_52", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "var_sshd_set_login_grace_time", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Description_52", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Configure parameters for how long the servers stays connected before the user has successfully logged in", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Value_Alternatives_52", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "{'default': 60, 60: 60}", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Id_53", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "var_sshd_set_maxstartups", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Description_53", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Configure parameters for maximum concurrent unauthenticated connections to the SSH daemon.", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Value_Alternatives_53", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "{'default': '10:30:100', '10:30:60': '10:30:60'}", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Id_54", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "var_system_crypto_policy", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Description_54", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Specify the crypto policy for the system.", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Value_Alternatives_54", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Id_55", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "var_user_initialization_files_regex", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Description_55", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "'A regular expression describing a list of file names for files that are sourced at login time for interactive users'", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Value_Alternatives_55", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "{'default': '^(\\\\.bashrc|\\\\.zshrc|\\\\.cshrc|\\\\.profile|\\\\.bash_login|\\\\.bash_profile)$', 'all_dotfiles': '^\\\\.[\\\\w\\\\- ]+$'}", + "remarks": "rule_set_000" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "kernel_module_cramfs_disabled", + "remarks": "rule_set_001" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Disable Mounting of cramfs", + "remarks": "rule_set_001" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "kernel_module_cramfs_disabled", + "remarks": "rule_set_001" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Disable Mounting of cramfs", + "remarks": "rule_set_001" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "kernel_module_freevxfs_disabled", + "remarks": "rule_set_002" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Disable Mounting of freevxfs", + "remarks": "rule_set_002" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "kernel_module_freevxfs_disabled", + "remarks": "rule_set_002" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Disable Mounting of freevxfs", + "remarks": "rule_set_002" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "kernel_module_hfs_disabled", + "remarks": "rule_set_003" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Disable Mounting of hfs", + "remarks": "rule_set_003" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "kernel_module_hfs_disabled", + "remarks": "rule_set_003" + }, + { + "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{10: 10, 3: 3, 5: 5, 0: 0, 1: 1, 'default': 0}", - "remarks": "rule_set_000" + "value": "Disable Mounting of hfs", + "remarks": "rule_set_003" }, { - "name": "Parameter_Id_51", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_sshd_set_login_grace_time", - "remarks": "rule_set_000" + "value": "kernel_module_hfsplus_disabled", + "remarks": "rule_set_004" }, { - "name": "Parameter_Description_51", + "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure parameters for how long the servers stays connected before the user has successfully logged in", - "remarks": "rule_set_000" + "value": "Disable Mounting of hfsplus", + "remarks": "rule_set_004" }, { - "name": "Parameter_Value_Alternatives_51", + "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 60, 60: 60}", - "remarks": "rule_set_000" + "value": "kernel_module_hfsplus_disabled", + "remarks": "rule_set_004" }, { - "name": "Parameter_Id_52", + "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_sshd_set_maxstartups", - "remarks": "rule_set_000" + "value": "Disable Mounting of hfsplus", + "remarks": "rule_set_004" }, { - "name": "Parameter_Description_52", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure parameters for maximum concurrent unauthenticated connections to the SSH daemon.", - "remarks": "rule_set_000" + "value": "kernel_module_jffs2_disabled", + "remarks": "rule_set_005" }, { - "name": "Parameter_Value_Alternatives_52", + "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': '10:30:100', '10:30:60': '10:30:60'}", - "remarks": "rule_set_000" + "value": "Disable Mounting of jffs2", + "remarks": "rule_set_005" }, { - "name": "Parameter_Id_53", + "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_system_crypto_policy", - "remarks": "rule_set_000" + "value": "kernel_module_jffs2_disabled", + "remarks": "rule_set_005" }, { - "name": "Parameter_Description_53", + "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the crypto policy for the system.", - "remarks": "rule_set_000" + "value": "Disable Mounting of jffs2", + "remarks": "rule_set_005" }, { - "name": "Parameter_Value_Alternatives_53", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", - "remarks": "rule_set_000" + "value": "kernel_module_firewire-core_disabled", + "remarks": "rule_set_006" }, { - "name": "Parameter_Id_54", + "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_user_initialization_files_regex", - "remarks": "rule_set_000" + "value": "Disable IEEE 1394 (FireWire) Support", + "remarks": "rule_set_006" }, { - "name": "Parameter_Description_54", + "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "'A regular expression describing a list of file names for files that are sourced at login time for interactive users'", - "remarks": "rule_set_000" + "value": "kernel_module_firewire-core_disabled", + "remarks": "rule_set_006" }, { - "name": "Parameter_Value_Alternatives_54", + "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': '^(\\\\.bashrc|\\\\.zshrc|\\\\.cshrc|\\\\.profile|\\\\.bash_login|\\\\.bash_profile)$', 'all_dotfiles': '^\\\\.[\\\\w\\\\- ]+$'}", - "remarks": "rule_set_000" + "value": "Disable IEEE 1394 (FireWire) Support", + "remarks": "rule_set_006" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "kernel_module_usb-storage_disabled", - "remarks": "rule_set_001" + "remarks": "rule_set_007" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Modprobe Loading of USB Storage Driver", - "remarks": "rule_set_001" + "remarks": "rule_set_007" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "kernel_module_usb-storage_disabled", - "remarks": "rule_set_001" + "remarks": "rule_set_007" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Modprobe Loading of USB Storage Driver", - "remarks": "rule_set_001" + "remarks": "rule_set_007" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "partition_for_tmp", - "remarks": "rule_set_002" + "remarks": "rule_set_008" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure /tmp Located On Separate Partition", - "remarks": "rule_set_002" + "remarks": "rule_set_008" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "partition_for_tmp", - "remarks": "rule_set_002" + "remarks": "rule_set_008" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure /tmp Located On Separate Partition", - "remarks": "rule_set_002" + "remarks": "rule_set_008" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_tmp_nodev", - "remarks": "rule_set_003" + "remarks": "rule_set_009" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nodev Option to /tmp", - "remarks": "rule_set_003" + "remarks": "rule_set_009" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_tmp_nodev", - "remarks": "rule_set_003" + "remarks": "rule_set_009" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nodev Option to /tmp", - "remarks": "rule_set_003" + "remarks": "rule_set_009" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_tmp_nosuid", - "remarks": "rule_set_004" + "remarks": "rule_set_010" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nosuid Option to /tmp", - "remarks": "rule_set_004" + "remarks": "rule_set_010" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_tmp_nosuid", - "remarks": "rule_set_004" + "remarks": "rule_set_010" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nosuid Option to /tmp", - "remarks": "rule_set_004" + "remarks": "rule_set_010" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_tmp_noexec", - "remarks": "rule_set_005" + "remarks": "rule_set_011" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add noexec Option to /tmp", - "remarks": "rule_set_005" + "remarks": "rule_set_011" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_tmp_noexec", - "remarks": "rule_set_005" + "remarks": "rule_set_011" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add noexec Option to /tmp", - "remarks": "rule_set_005" + "remarks": "rule_set_011" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "partition_for_dev_shm", - "remarks": "rule_set_006" + "remarks": "rule_set_012" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure /dev/shm is configured", - "remarks": "rule_set_006" + "remarks": "rule_set_012" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "partition_for_dev_shm", - "remarks": "rule_set_006" + "remarks": "rule_set_012" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure /dev/shm is configured", - "remarks": "rule_set_006" + "remarks": "rule_set_012" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_dev_shm_nodev", - "remarks": "rule_set_007" + "remarks": "rule_set_013" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nodev Option to /dev/shm", - "remarks": "rule_set_007" + "remarks": "rule_set_013" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_dev_shm_nodev", - "remarks": "rule_set_007" + "remarks": "rule_set_013" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nodev Option to /dev/shm", - "remarks": "rule_set_007" + "remarks": "rule_set_013" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_dev_shm_nosuid", - "remarks": "rule_set_008" + "remarks": "rule_set_014" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nosuid Option to /dev/shm", - "remarks": "rule_set_008" + "remarks": "rule_set_014" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_dev_shm_nosuid", - "remarks": "rule_set_008" + "remarks": "rule_set_014" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nosuid Option to /dev/shm", - "remarks": "rule_set_008" + "remarks": "rule_set_014" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_dev_shm_noexec", - "remarks": "rule_set_009" + "remarks": "rule_set_015" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add noexec Option to /dev/shm", - "remarks": "rule_set_009" + "remarks": "rule_set_015" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_dev_shm_noexec", - "remarks": "rule_set_009" + "remarks": "rule_set_015" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add noexec Option to /dev/shm", - "remarks": "rule_set_009" + "remarks": "rule_set_015" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_home_nodev", - "remarks": "rule_set_010" + "remarks": "rule_set_016" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nodev Option to /home", - "remarks": "rule_set_010" + "remarks": "rule_set_016" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_home_nodev", - "remarks": "rule_set_010" + "remarks": "rule_set_016" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nodev Option to /home", - "remarks": "rule_set_010" + "remarks": "rule_set_016" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_home_nosuid", - "remarks": "rule_set_011" + "remarks": "rule_set_017" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nosuid Option to /home", - "remarks": "rule_set_011" + "remarks": "rule_set_017" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_home_nosuid", - "remarks": "rule_set_011" + "remarks": "rule_set_017" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nosuid Option to /home", - "remarks": "rule_set_011" + "remarks": "rule_set_017" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_nodev", - "remarks": "rule_set_012" + "remarks": "rule_set_018" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nodev Option to /var", - "remarks": "rule_set_012" + "remarks": "rule_set_018" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_nodev", - "remarks": "rule_set_012" + "remarks": "rule_set_018" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nodev Option to /var", - "remarks": "rule_set_012" + "remarks": "rule_set_018" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_nosuid", - "remarks": "rule_set_013" + "remarks": "rule_set_019" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nosuid Option to /var", - "remarks": "rule_set_013" + "remarks": "rule_set_019" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_nosuid", - "remarks": "rule_set_013" + "remarks": "rule_set_019" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nosuid Option to /var", - "remarks": "rule_set_013" + "remarks": "rule_set_019" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_tmp_nodev", - "remarks": "rule_set_014" + "remarks": "rule_set_020" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nodev Option to /var/tmp", - "remarks": "rule_set_014" + "remarks": "rule_set_020" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_tmp_nodev", - "remarks": "rule_set_014" + "remarks": "rule_set_020" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nodev Option to /var/tmp", - "remarks": "rule_set_014" + "remarks": "rule_set_020" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_tmp_nosuid", - "remarks": "rule_set_015" + "remarks": "rule_set_021" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nosuid Option to /var/tmp", - "remarks": "rule_set_015" + "remarks": "rule_set_021" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_tmp_nosuid", - "remarks": "rule_set_015" + "remarks": "rule_set_021" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nosuid Option to /var/tmp", - "remarks": "rule_set_015" + "remarks": "rule_set_021" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_tmp_noexec", - "remarks": "rule_set_016" + "remarks": "rule_set_022" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add noexec Option to /var/tmp", - "remarks": "rule_set_016" + "remarks": "rule_set_022" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_tmp_noexec", - "remarks": "rule_set_016" + "remarks": "rule_set_022" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add noexec Option to /var/tmp", - "remarks": "rule_set_016" + "remarks": "rule_set_022" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_nodev", - "remarks": "rule_set_017" + "remarks": "rule_set_023" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nodev Option to /var/log", - "remarks": "rule_set_017" + "remarks": "rule_set_023" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_nodev", - "remarks": "rule_set_017" + "remarks": "rule_set_023" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nodev Option to /var/log", - "remarks": "rule_set_017" + "remarks": "rule_set_023" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_nosuid", - "remarks": "rule_set_018" + "remarks": "rule_set_024" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nosuid Option to /var/log", - "remarks": "rule_set_018" + "remarks": "rule_set_024" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_nosuid", - "remarks": "rule_set_018" + "remarks": "rule_set_024" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nosuid Option to /var/log", - "remarks": "rule_set_018" + "remarks": "rule_set_024" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_noexec", - "remarks": "rule_set_019" + "remarks": "rule_set_025" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add noexec Option to /var/log", - "remarks": "rule_set_019" + "remarks": "rule_set_025" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_noexec", - "remarks": "rule_set_019" + "remarks": "rule_set_025" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add noexec Option to /var/log", - "remarks": "rule_set_019" + "remarks": "rule_set_025" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_audit_nodev", - "remarks": "rule_set_020" + "remarks": "rule_set_026" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nodev Option to /var/log/audit", - "remarks": "rule_set_020" + "remarks": "rule_set_026" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_audit_nodev", - "remarks": "rule_set_020" + "remarks": "rule_set_026" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nodev Option to /var/log/audit", - "remarks": "rule_set_020" + "remarks": "rule_set_026" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_audit_nosuid", - "remarks": "rule_set_021" + "remarks": "rule_set_027" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nosuid Option to /var/log/audit", - "remarks": "rule_set_021" + "remarks": "rule_set_027" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_audit_nosuid", - "remarks": "rule_set_021" + "remarks": "rule_set_027" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nosuid Option to /var/log/audit", - "remarks": "rule_set_021" + "remarks": "rule_set_027" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_audit_noexec", - "remarks": "rule_set_022" + "remarks": "rule_set_028" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add noexec Option to /var/log/audit", - "remarks": "rule_set_022" + "remarks": "rule_set_028" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_audit_noexec", - "remarks": "rule_set_022" + "remarks": "rule_set_028" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add noexec Option to /var/log/audit", - "remarks": "rule_set_022" + "remarks": "rule_set_028" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "ensure_gpgcheck_globally_activated", - "remarks": "rule_set_023" + "remarks": "rule_set_029" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure gpgcheck Enabled In Main dnf Configuration", - "remarks": "rule_set_023" + "remarks": "rule_set_029" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "ensure_gpgcheck_globally_activated", - "remarks": "rule_set_023" + "remarks": "rule_set_029" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure gpgcheck Enabled In Main dnf Configuration", - "remarks": "rule_set_023" + "remarks": "rule_set_029" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_libselinux_installed", - "remarks": "rule_set_024" + "remarks": "rule_set_030" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Install libselinux Package", - "remarks": "rule_set_024" + "remarks": "rule_set_030" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_libselinux_installed", - "remarks": "rule_set_024" + "remarks": "rule_set_030" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Install libselinux Package", - "remarks": "rule_set_024" + "remarks": "rule_set_030" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "grub2_enable_selinux", - "remarks": "rule_set_025" + "remarks": "rule_set_031" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure SELinux Not Disabled in /etc/default/grub", - "remarks": "rule_set_025" + "remarks": "rule_set_031" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "grub2_enable_selinux", - "remarks": "rule_set_025" + "remarks": "rule_set_031" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure SELinux Not Disabled in /etc/default/grub", - "remarks": "rule_set_025" + "remarks": "rule_set_031" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "selinux_policytype", - "remarks": "rule_set_026" + "remarks": "rule_set_032" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure SELinux Policy", - "remarks": "rule_set_026" + "remarks": "rule_set_032" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "selinux_policytype", - "remarks": "rule_set_026" + "remarks": "rule_set_032" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure SELinux Policy", - "remarks": "rule_set_026" + "remarks": "rule_set_032" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "selinux_not_disabled", - "remarks": "rule_set_027" + "remarks": "rule_set_033" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure SELinux is Not Disabled", - "remarks": "rule_set_027" + "remarks": "rule_set_033" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "selinux_not_disabled", - "remarks": "rule_set_027" + "remarks": "rule_set_033" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure SELinux is Not Disabled", - "remarks": "rule_set_027" + "remarks": "rule_set_033" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_mcstrans_removed", - "remarks": "rule_set_028" + "remarks": "rule_set_034" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall mcstrans Package", - "remarks": "rule_set_028" + "remarks": "rule_set_034" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_mcstrans_removed", - "remarks": "rule_set_028" + "remarks": "rule_set_034" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall mcstrans Package", - "remarks": "rule_set_028" + "remarks": "rule_set_034" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_setroubleshoot_removed", - "remarks": "rule_set_029" + "remarks": "rule_set_035" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall setroubleshoot Package", - "remarks": "rule_set_029" + "remarks": "rule_set_035" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_setroubleshoot_removed", - "remarks": "rule_set_029" + "remarks": "rule_set_035" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall setroubleshoot Package", - "remarks": "rule_set_029" + "remarks": "rule_set_035" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "grub2_password", - "remarks": "rule_set_030" + "remarks": "rule_set_036" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Boot Loader Password in grub2", - "remarks": "rule_set_030" + "remarks": "rule_set_036" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "grub2_password", - "remarks": "rule_set_030" + "remarks": "rule_set_036" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Boot Loader Password in grub2", - "remarks": "rule_set_030" + "remarks": "rule_set_036" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_grub2_cfg", - "remarks": "rule_set_031" + "remarks": "rule_set_037" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify /boot/grub2/grub.cfg Group Ownership", - "remarks": "rule_set_031" + "remarks": "rule_set_037" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_grub2_cfg", - "remarks": "rule_set_031" + "remarks": "rule_set_037" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify /boot/grub2/grub.cfg Group Ownership", - "remarks": "rule_set_031" + "remarks": "rule_set_037" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_grub2_cfg", - "remarks": "rule_set_032" + "remarks": "rule_set_038" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify /boot/grub2/grub.cfg User Ownership", - "remarks": "rule_set_032" + "remarks": "rule_set_038" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_grub2_cfg", - "remarks": "rule_set_032" + "remarks": "rule_set_038" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify /boot/grub2/grub.cfg User Ownership", - "remarks": "rule_set_032" + "remarks": "rule_set_038" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_grub2_cfg", - "remarks": "rule_set_033" + "remarks": "rule_set_039" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify /boot/grub2/grub.cfg Permissions", - "remarks": "rule_set_033" + "remarks": "rule_set_039" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_grub2_cfg", - "remarks": "rule_set_033" + "remarks": "rule_set_039" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify /boot/grub2/grub.cfg Permissions", - "remarks": "rule_set_033" + "remarks": "rule_set_039" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_user_cfg", - "remarks": "rule_set_034" + "remarks": "rule_set_040" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify /boot/grub2/user.cfg Group Ownership", - "remarks": "rule_set_034" + "remarks": "rule_set_040" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_user_cfg", - "remarks": "rule_set_034" + "remarks": "rule_set_040" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify /boot/grub2/user.cfg Group Ownership", - "remarks": "rule_set_034" + "remarks": "rule_set_040" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_user_cfg", - "remarks": "rule_set_035" + "remarks": "rule_set_041" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify /boot/grub2/user.cfg User Ownership", - "remarks": "rule_set_035" + "remarks": "rule_set_041" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_user_cfg", - "remarks": "rule_set_035" + "remarks": "rule_set_041" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify /boot/grub2/user.cfg User Ownership", - "remarks": "rule_set_035" + "remarks": "rule_set_041" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_user_cfg", - "remarks": "rule_set_036" + "remarks": "rule_set_042" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify /boot/grub2/user.cfg Permissions", - "remarks": "rule_set_036" + "remarks": "rule_set_042" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_user_cfg", - "remarks": "rule_set_036" + "remarks": "rule_set_042" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify /boot/grub2/user.cfg Permissions", - "remarks": "rule_set_036" + "remarks": "rule_set_042" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_kernel_randomize_va_space", - "remarks": "rule_set_037" + "value": "disable_users_coredumps", + "remarks": "rule_set_043" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Randomized Layout of Virtual Address Space", - "remarks": "rule_set_037" + "value": "Disable Core Dumps for All Users", + "remarks": "rule_set_043" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_kernel_randomize_va_space", - "remarks": "rule_set_037" + "value": "disable_users_coredumps", + "remarks": "rule_set_043" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Randomized Layout of Virtual Address Space", - "remarks": "rule_set_037" + "value": "Disable Core Dumps for All Users", + "remarks": "rule_set_043" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sysctl_fs_protected_hardlinks", + "remarks": "rule_set_044" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Enable Kernel Parameter to Enforce DAC on Hardlinks", + "remarks": "rule_set_044" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sysctl_fs_protected_hardlinks", + "remarks": "rule_set_044" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Enable Kernel Parameter to Enforce DAC on Hardlinks", + "remarks": "rule_set_044" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sysctl_fs_suid_dumpable", + "remarks": "rule_set_045" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Disable Core Dumps for SUID programs", + "remarks": "rule_set_045" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sysctl_fs_suid_dumpable", + "remarks": "rule_set_045" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Disable Core Dumps for SUID programs", + "remarks": "rule_set_045" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sysctl_kernel_dmesg_restrict", + "remarks": "rule_set_046" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Restrict Access to Kernel Message Buffer", + "remarks": "rule_set_046" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sysctl_kernel_dmesg_restrict", + "remarks": "rule_set_046" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Restrict Access to Kernel Message Buffer", + "remarks": "rule_set_046" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sysctl_kernel_kptr_restrict", + "remarks": "rule_set_047" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Restrict Exposed Kernel Pointer Addresses Access", + "remarks": "rule_set_047" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sysctl_kernel_kptr_restrict", + "remarks": "rule_set_047" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Restrict Exposed Kernel Pointer Addresses Access", + "remarks": "rule_set_047" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_kernel_yama_ptrace_scope", - "remarks": "rule_set_038" + "remarks": "rule_set_048" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Restrict usage of ptrace to descendant processes", - "remarks": "rule_set_038" + "remarks": "rule_set_048" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_kernel_yama_ptrace_scope", - "remarks": "rule_set_038" + "remarks": "rule_set_048" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Restrict usage of ptrace to descendant processes", - "remarks": "rule_set_038" + "remarks": "rule_set_048" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_backtraces", - "remarks": "rule_set_039" + "value": "sysctl_kernel_randomize_va_space", + "remarks": "rule_set_049" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable core dump backtraces", - "remarks": "rule_set_039" + "value": "Enable Randomized Layout of Virtual Address Space", + "remarks": "rule_set_049" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_backtraces", - "remarks": "rule_set_039" + "value": "sysctl_kernel_randomize_va_space", + "remarks": "rule_set_049" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable core dump backtraces", - "remarks": "rule_set_039" + "value": "Enable Randomized Layout of Virtual Address Space", + "remarks": "rule_set_049" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_storage", - "remarks": "rule_set_040" + "value": "coredump_disable_backtraces", + "remarks": "rule_set_050" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable storing core dump", - "remarks": "rule_set_040" + "value": "Disable core dump backtraces", + "remarks": "rule_set_050" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_storage", - "remarks": "rule_set_040" + "value": "coredump_disable_backtraces", + "remarks": "rule_set_050" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable storing core dump", - "remarks": "rule_set_040" + "value": "Disable core dump backtraces", + "remarks": "rule_set_050" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_crypto_policy", - "remarks": "rule_set_041" + "value": "coredump_disable_storage", + "remarks": "rule_set_051" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure System Cryptography Policy", - "remarks": "rule_set_041" + "value": "Disable storing core dump", + "remarks": "rule_set_051" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_crypto_policy", - "remarks": "rule_set_041" + "value": "coredump_disable_storage", + "remarks": "rule_set_051" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure System Cryptography Policy", - "remarks": "rule_set_041" + "value": "Disable storing core dump", + "remarks": "rule_set_051" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_ssh_crypto_policy", - "remarks": "rule_set_042" + "value": "configure_crypto_policy", + "remarks": "rule_set_052" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure SSH to use System Crypto Policy", - "remarks": "rule_set_042" + "value": "Configure System Cryptography Policy", + "remarks": "rule_set_052" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_ssh_crypto_policy", - "remarks": "rule_set_042" + "value": "configure_crypto_policy", + "remarks": "rule_set_052" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure SSH to use System Crypto Policy", - "remarks": "rule_set_042" + "value": "Configure System Cryptography Policy", + "remarks": "rule_set_052" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "banner_etc_motd_cis", - "remarks": "rule_set_043" + "remarks": "rule_set_053" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Message Of The Day Is Configured Properly", - "remarks": "rule_set_043" + "remarks": "rule_set_053" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "banner_etc_motd_cis", - "remarks": "rule_set_043" + "remarks": "rule_set_053" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Message Of The Day Is Configured Properly", - "remarks": "rule_set_043" + "remarks": "rule_set_053" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "banner_etc_issue_cis", - "remarks": "rule_set_044" + "remarks": "rule_set_054" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Local Login Warning Banner Is Configured Properly", - "remarks": "rule_set_044" + "remarks": "rule_set_054" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "banner_etc_issue_cis", - "remarks": "rule_set_044" + "remarks": "rule_set_054" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Local Login Warning Banner Is Configured Properly", - "remarks": "rule_set_044" + "remarks": "rule_set_054" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "banner_etc_issue_net_cis", - "remarks": "rule_set_045" + "remarks": "rule_set_055" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Remote Login Warning Banner Is Configured Properly", - "remarks": "rule_set_045" + "remarks": "rule_set_055" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "banner_etc_issue_net_cis", - "remarks": "rule_set_045" + "remarks": "rule_set_055" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Remote Login Warning Banner Is Configured Properly", - "remarks": "rule_set_045" + "remarks": "rule_set_055" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_motd", - "remarks": "rule_set_046" + "remarks": "rule_set_056" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Ownership of Message of the Day Banner", - "remarks": "rule_set_046" + "remarks": "rule_set_056" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_motd", - "remarks": "rule_set_046" + "remarks": "rule_set_056" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Ownership of Message of the Day Banner", - "remarks": "rule_set_046" + "remarks": "rule_set_056" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_motd", - "remarks": "rule_set_047" + "remarks": "rule_set_057" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify ownership of Message of the Day Banner", - "remarks": "rule_set_047" + "remarks": "rule_set_057" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_motd", - "remarks": "rule_set_047" + "remarks": "rule_set_057" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify ownership of Message of the Day Banner", - "remarks": "rule_set_047" + "remarks": "rule_set_057" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_motd", - "remarks": "rule_set_048" + "remarks": "rule_set_058" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify permissions on Message of the Day Banner", - "remarks": "rule_set_048" + "remarks": "rule_set_058" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_motd", - "remarks": "rule_set_048" + "remarks": "rule_set_058" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify permissions on Message of the Day Banner", - "remarks": "rule_set_048" + "remarks": "rule_set_058" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_issue", - "remarks": "rule_set_049" + "remarks": "rule_set_059" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Ownership of System Login Banner", - "remarks": "rule_set_049" + "remarks": "rule_set_059" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_issue", - "remarks": "rule_set_049" + "remarks": "rule_set_059" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Ownership of System Login Banner", - "remarks": "rule_set_049" + "remarks": "rule_set_059" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_issue", - "remarks": "rule_set_050" + "remarks": "rule_set_060" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify ownership of System Login Banner", - "remarks": "rule_set_050" + "remarks": "rule_set_060" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_issue", - "remarks": "rule_set_050" + "remarks": "rule_set_060" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify ownership of System Login Banner", - "remarks": "rule_set_050" + "remarks": "rule_set_060" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_issue", - "remarks": "rule_set_051" + "remarks": "rule_set_061" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify permissions on System Login Banner", - "remarks": "rule_set_051" + "remarks": "rule_set_061" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_issue", - "remarks": "rule_set_051" + "remarks": "rule_set_061" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify permissions on System Login Banner", - "remarks": "rule_set_051" + "remarks": "rule_set_061" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_issue_net", - "remarks": "rule_set_052" + "remarks": "rule_set_062" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Ownership of System Login Banner for Remote Connections", - "remarks": "rule_set_052" + "remarks": "rule_set_062" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_issue_net", - "remarks": "rule_set_052" + "remarks": "rule_set_062" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Ownership of System Login Banner for Remote Connections", - "remarks": "rule_set_052" + "remarks": "rule_set_062" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_issue_net", - "remarks": "rule_set_053" + "remarks": "rule_set_063" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify ownership of System Login Banner for Remote Connections", - "remarks": "rule_set_053" + "remarks": "rule_set_063" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_issue_net", - "remarks": "rule_set_053" + "remarks": "rule_set_063" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify ownership of System Login Banner for Remote Connections", - "remarks": "rule_set_053" + "remarks": "rule_set_063" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_issue_net", - "remarks": "rule_set_054" + "remarks": "rule_set_064" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify permissions on System Login Banner for Remote Connections", - "remarks": "rule_set_054" + "remarks": "rule_set_064" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_issue_net", - "remarks": "rule_set_054" + "remarks": "rule_set_064" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify permissions on System Login Banner for Remote Connections", - "remarks": "rule_set_054" + "remarks": "rule_set_064" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_banner_enabled", - "remarks": "rule_set_055" + "remarks": "rule_set_065" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable GNOME3 Login Warning Banner", - "remarks": "rule_set_055" + "remarks": "rule_set_065" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_banner_enabled", - "remarks": "rule_set_055" + "remarks": "rule_set_065" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable GNOME3 Login Warning Banner", - "remarks": "rule_set_055" + "remarks": "rule_set_065" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_login_banner_text", - "remarks": "rule_set_056" + "remarks": "rule_set_066" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set the GNOME3 Login Warning Banner Text", - "remarks": "rule_set_056" + "remarks": "rule_set_066" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_login_banner_text", - "remarks": "rule_set_056" + "remarks": "rule_set_066" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set the GNOME3 Login Warning Banner Text", - "remarks": "rule_set_056" + "remarks": "rule_set_066" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_disable_user_list", - "remarks": "rule_set_057" + "remarks": "rule_set_067" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable the GNOME3 Login User List", - "remarks": "rule_set_057" + "remarks": "rule_set_067" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_disable_user_list", - "remarks": "rule_set_057" + "remarks": "rule_set_067" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable the GNOME3 Login User List", - "remarks": "rule_set_057" + "remarks": "rule_set_067" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_screensaver_idle_delay", - "remarks": "rule_set_058" + "remarks": "rule_set_068" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set GNOME3 Screensaver Inactivity Timeout", - "remarks": "rule_set_058" + "remarks": "rule_set_068" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_screensaver_idle_delay", - "remarks": "rule_set_058" + "remarks": "rule_set_068" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set GNOME3 Screensaver Inactivity Timeout", - "remarks": "rule_set_058" + "remarks": "rule_set_068" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_screensaver_lock_delay", - "remarks": "rule_set_059" + "remarks": "rule_set_069" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set GNOME3 Screensaver Lock Delay After Activation Period", - "remarks": "rule_set_059" + "remarks": "rule_set_069" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_screensaver_lock_delay", - "remarks": "rule_set_059" + "remarks": "rule_set_069" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set GNOME3 Screensaver Lock Delay After Activation Period", - "remarks": "rule_set_059" + "remarks": "rule_set_069" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_session_idle_user_locks", - "remarks": "rule_set_060" + "remarks": "rule_set_070" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Users Cannot Change GNOME3 Session Idle Settings", - "remarks": "rule_set_060" + "remarks": "rule_set_070" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_session_idle_user_locks", - "remarks": "rule_set_060" + "remarks": "rule_set_070" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Users Cannot Change GNOME3 Session Idle Settings", - "remarks": "rule_set_060" + "remarks": "rule_set_070" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_screensaver_user_locks", - "remarks": "rule_set_061" + "remarks": "rule_set_071" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Users Cannot Change GNOME3 Screensaver Settings", - "remarks": "rule_set_061" + "remarks": "rule_set_071" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_screensaver_user_locks", - "remarks": "rule_set_061" + "remarks": "rule_set_071" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Users Cannot Change GNOME3 Screensaver Settings", - "remarks": "rule_set_061" + "remarks": "rule_set_071" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_disable_automount", - "remarks": "rule_set_062" + "remarks": "rule_set_072" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable GNOME3 Automounting", - "remarks": "rule_set_062" + "remarks": "rule_set_072" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_disable_automount", - "remarks": "rule_set_062" + "remarks": "rule_set_072" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable GNOME3 Automounting", - "remarks": "rule_set_062" + "remarks": "rule_set_072" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_disable_automount_open", - "remarks": "rule_set_063" + "remarks": "rule_set_073" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable GNOME3 Automount Opening", - "remarks": "rule_set_063" + "remarks": "rule_set_073" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_disable_automount_open", - "remarks": "rule_set_063" + "remarks": "rule_set_073" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable GNOME3 Automount Opening", - "remarks": "rule_set_063" + "remarks": "rule_set_073" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_disable_autorun", - "remarks": "rule_set_064" + "remarks": "rule_set_074" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable GNOME3 Automount running", - "remarks": "rule_set_064" + "remarks": "rule_set_074" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_disable_autorun", - "remarks": "rule_set_064" + "remarks": "rule_set_074" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable GNOME3 Automount running", - "remarks": "rule_set_064" + "remarks": "rule_set_074" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_autofs_disabled", - "remarks": "rule_set_065" + "remarks": "rule_set_075" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable the Automounter", - "remarks": "rule_set_065" + "remarks": "rule_set_075" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_autofs_disabled", - "remarks": "rule_set_065" + "remarks": "rule_set_075" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable the Automounter", - "remarks": "rule_set_065" + "remarks": "rule_set_075" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_avahi-daemon_disabled", - "remarks": "rule_set_066" + "remarks": "rule_set_076" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Avahi Server Software", - "remarks": "rule_set_066" + "remarks": "rule_set_076" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_avahi-daemon_disabled", - "remarks": "rule_set_066" + "remarks": "rule_set_076" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Avahi Server Software", - "remarks": "rule_set_066" + "remarks": "rule_set_076" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_kea_removed", - "remarks": "rule_set_067" + "remarks": "rule_set_077" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall kea Package", - "remarks": "rule_set_067" + "remarks": "rule_set_077" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_kea_removed", - "remarks": "rule_set_067" + "remarks": "rule_set_077" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall kea Package", - "remarks": "rule_set_067" + "remarks": "rule_set_077" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_bind_removed", - "remarks": "rule_set_068" + "remarks": "rule_set_078" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall bind Package", - "remarks": "rule_set_068" + "remarks": "rule_set_078" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_bind_removed", - "remarks": "rule_set_068" + "remarks": "rule_set_078" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall bind Package", - "remarks": "rule_set_068" + "remarks": "rule_set_078" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_dnsmasq_removed", - "remarks": "rule_set_069" + "remarks": "rule_set_079" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall dnsmasq Package", - "remarks": "rule_set_069" + "remarks": "rule_set_079" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_dnsmasq_removed", - "remarks": "rule_set_069" + "remarks": "rule_set_079" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall dnsmasq Package", - "remarks": "rule_set_069" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_samba_removed", - "remarks": "rule_set_070" - }, - { - "name": "Rule_Description", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall Samba Package", - "remarks": "rule_set_070" - }, - { - "name": "Check_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_samba_removed", - "remarks": "rule_set_070" - }, - { - "name": "Check_Description", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall Samba Package", - "remarks": "rule_set_070" + "remarks": "rule_set_079" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_vsftpd_removed", - "remarks": "rule_set_071" + "remarks": "rule_set_080" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall vsftpd Package", - "remarks": "rule_set_071" + "remarks": "rule_set_080" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_vsftpd_removed", - "remarks": "rule_set_071" + "remarks": "rule_set_080" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall vsftpd Package", - "remarks": "rule_set_071" + "remarks": "rule_set_080" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_dovecot_removed", - "remarks": "rule_set_072" + "remarks": "rule_set_081" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall dovecot Package", - "remarks": "rule_set_072" + "remarks": "rule_set_081" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_dovecot_removed", - "remarks": "rule_set_072" + "remarks": "rule_set_081" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall dovecot Package", - "remarks": "rule_set_072" + "remarks": "rule_set_081" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_cyrus-imapd_removed", - "remarks": "rule_set_073" + "remarks": "rule_set_082" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall cyrus-imapd Package", - "remarks": "rule_set_073" + "remarks": "rule_set_082" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_cyrus-imapd_removed", - "remarks": "rule_set_073" + "remarks": "rule_set_082" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall cyrus-imapd Package", - "remarks": "rule_set_073" + "remarks": "rule_set_082" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_nfs_disabled", - "remarks": "rule_set_074" + "remarks": "rule_set_083" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Network File System (nfs)", - "remarks": "rule_set_074" + "remarks": "rule_set_083" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_nfs_disabled", - "remarks": "rule_set_074" + "remarks": "rule_set_083" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Network File System (nfs)", - "remarks": "rule_set_074" + "remarks": "rule_set_083" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_cups_disabled", - "remarks": "rule_set_075" + "remarks": "rule_set_084" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable the CUPS Service", - "remarks": "rule_set_075" + "remarks": "rule_set_084" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_cups_disabled", - "remarks": "rule_set_075" + "remarks": "rule_set_084" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable the CUPS Service", - "remarks": "rule_set_075" + "remarks": "rule_set_084" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_rpcbind_disabled", - "remarks": "rule_set_076" + "remarks": "rule_set_085" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable rpcbind Service", - "remarks": "rule_set_076" + "remarks": "rule_set_085" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_rpcbind_disabled", - "remarks": "rule_set_076" + "remarks": "rule_set_085" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable rpcbind Service", - "remarks": "rule_set_076" + "remarks": "rule_set_085" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_rsync_removed", - "remarks": "rule_set_077" + "remarks": "rule_set_086" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall rsync Package", - "remarks": "rule_set_077" + "remarks": "rule_set_086" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_rsync_removed", - "remarks": "rule_set_077" + "remarks": "rule_set_086" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall rsync Package", - "remarks": "rule_set_077" + "remarks": "rule_set_086" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "package_samba_removed", + "remarks": "rule_set_087" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Uninstall Samba Package", + "remarks": "rule_set_087" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "package_samba_removed", + "remarks": "rule_set_087" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Uninstall Samba Package", + "remarks": "rule_set_087" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_net-snmp_removed", - "remarks": "rule_set_078" + "remarks": "rule_set_088" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall net-snmp Package", - "remarks": "rule_set_078" + "remarks": "rule_set_088" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_net-snmp_removed", - "remarks": "rule_set_078" + "remarks": "rule_set_088" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall net-snmp Package", - "remarks": "rule_set_078" + "remarks": "rule_set_088" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_telnet-server_removed", - "remarks": "rule_set_079" + "remarks": "rule_set_089" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall telnet-server Package", - "remarks": "rule_set_079" + "remarks": "rule_set_089" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_telnet-server_removed", - "remarks": "rule_set_079" + "remarks": "rule_set_089" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall telnet-server Package", - "remarks": "rule_set_079" + "remarks": "rule_set_089" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_tftp-server_removed", - "remarks": "rule_set_080" + "remarks": "rule_set_090" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall tftp-server Package", - "remarks": "rule_set_080" + "remarks": "rule_set_090" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_tftp-server_removed", - "remarks": "rule_set_080" + "remarks": "rule_set_090" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall tftp-server Package", - "remarks": "rule_set_080" + "remarks": "rule_set_090" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_squid_removed", - "remarks": "rule_set_081" + "remarks": "rule_set_091" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall squid Package", - "remarks": "rule_set_081" + "remarks": "rule_set_091" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_squid_removed", - "remarks": "rule_set_081" + "remarks": "rule_set_091" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall squid Package", - "remarks": "rule_set_081" + "remarks": "rule_set_091" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_httpd_removed", - "remarks": "rule_set_082" + "remarks": "rule_set_092" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall httpd Package", - "remarks": "rule_set_082" + "remarks": "rule_set_092" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_httpd_removed", - "remarks": "rule_set_082" + "remarks": "rule_set_092" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall httpd Package", - "remarks": "rule_set_082" + "remarks": "rule_set_092" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_nginx_removed", - "remarks": "rule_set_083" + "remarks": "rule_set_093" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall nginx Package", - "remarks": "rule_set_083" + "remarks": "rule_set_093" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_nginx_removed", - "remarks": "rule_set_083" + "remarks": "rule_set_093" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall nginx Package", - "remarks": "rule_set_083" + "remarks": "rule_set_093" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "postfix_network_listening_disabled", - "remarks": "rule_set_084" + "remarks": "rule_set_094" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Postfix Network Listening", - "remarks": "rule_set_084" + "remarks": "rule_set_094" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "postfix_network_listening_disabled", - "remarks": "rule_set_084" + "remarks": "rule_set_094" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Postfix Network Listening", - "remarks": "rule_set_084" + "remarks": "rule_set_094" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "has_nonlocal_mta", - "remarks": "rule_set_085" + "remarks": "rule_set_095" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Mail Transfer Agent is not Listening on any non-loopback Address", - "remarks": "rule_set_085" + "remarks": "rule_set_095" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "has_nonlocal_mta", - "remarks": "rule_set_085" + "remarks": "rule_set_095" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Mail Transfer Agent is not Listening on any non-loopback Address", - "remarks": "rule_set_085" + "remarks": "rule_set_095" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_ftp_removed", - "remarks": "rule_set_086" + "remarks": "rule_set_096" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Remove ftp Package", - "remarks": "rule_set_086" + "remarks": "rule_set_096" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_ftp_removed", - "remarks": "rule_set_086" + "remarks": "rule_set_096" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Remove ftp Package", - "remarks": "rule_set_086" + "remarks": "rule_set_096" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_telnet_removed", - "remarks": "rule_set_087" + "remarks": "rule_set_097" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Remove telnet Clients", - "remarks": "rule_set_087" + "remarks": "rule_set_097" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_telnet_removed", - "remarks": "rule_set_087" + "remarks": "rule_set_097" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Remove telnet Clients", - "remarks": "rule_set_087" + "remarks": "rule_set_097" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_tftp_removed", - "remarks": "rule_set_088" + "remarks": "rule_set_098" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Remove tftp Daemon", - "remarks": "rule_set_088" + "remarks": "rule_set_098" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_tftp_removed", - "remarks": "rule_set_088" + "remarks": "rule_set_098" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Remove tftp Daemon", - "remarks": "rule_set_088" + "remarks": "rule_set_098" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "chronyd_specify_remote_server", - "remarks": "rule_set_089" + "remarks": "rule_set_099" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "A remote time server for Chrony is configured", - "remarks": "rule_set_089" + "remarks": "rule_set_099" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "chronyd_specify_remote_server", - "remarks": "rule_set_089" + "remarks": "rule_set_099" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "A remote time server for Chrony is configured", - "remarks": "rule_set_089" + "remarks": "rule_set_099" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "chronyd_run_as_chrony_user", - "remarks": "rule_set_090" + "remarks": "rule_set_100" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that chronyd is running under chrony user account", - "remarks": "rule_set_090" + "remarks": "rule_set_100" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "chronyd_run_as_chrony_user", - "remarks": "rule_set_090" + "remarks": "rule_set_100" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that chronyd is running under chrony user account", - "remarks": "rule_set_090" + "remarks": "rule_set_100" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_cron_installed", - "remarks": "rule_set_091" + "remarks": "rule_set_101" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Install the cron service", - "remarks": "rule_set_091" + "remarks": "rule_set_101" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_cron_installed", - "remarks": "rule_set_091" + "remarks": "rule_set_101" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Install the cron service", - "remarks": "rule_set_091" + "remarks": "rule_set_101" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_crond_enabled", - "remarks": "rule_set_092" + "remarks": "rule_set_102" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable cron Service", - "remarks": "rule_set_092" + "remarks": "rule_set_102" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_crond_enabled", - "remarks": "rule_set_092" + "remarks": "rule_set_102" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable cron Service", - "remarks": "rule_set_092" + "remarks": "rule_set_102" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_crontab", - "remarks": "rule_set_093" + "remarks": "rule_set_103" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns Crontab", - "remarks": "rule_set_093" + "remarks": "rule_set_103" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_crontab", - "remarks": "rule_set_093" + "remarks": "rule_set_103" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns Crontab", - "remarks": "rule_set_093" + "remarks": "rule_set_103" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_crontab", - "remarks": "rule_set_094" + "remarks": "rule_set_104" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on crontab", - "remarks": "rule_set_094" + "remarks": "rule_set_104" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_crontab", - "remarks": "rule_set_094" + "remarks": "rule_set_104" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on crontab", - "remarks": "rule_set_094" + "remarks": "rule_set_104" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_crontab", - "remarks": "rule_set_095" + "remarks": "rule_set_105" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on crontab", - "remarks": "rule_set_095" + "remarks": "rule_set_105" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_crontab", - "remarks": "rule_set_095" + "remarks": "rule_set_105" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on crontab", - "remarks": "rule_set_095" + "remarks": "rule_set_105" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_cron_hourly", - "remarks": "rule_set_096" + "remarks": "rule_set_106" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns cron.hourly", - "remarks": "rule_set_096" + "remarks": "rule_set_106" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_cron_hourly", - "remarks": "rule_set_096" + "remarks": "rule_set_106" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns cron.hourly", - "remarks": "rule_set_096" + "remarks": "rule_set_106" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_cron_hourly", - "remarks": "rule_set_097" + "remarks": "rule_set_107" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on cron.hourly", - "remarks": "rule_set_097" + "remarks": "rule_set_107" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_cron_hourly", - "remarks": "rule_set_097" + "remarks": "rule_set_107" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on cron.hourly", - "remarks": "rule_set_097" + "remarks": "rule_set_107" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_cron_hourly", - "remarks": "rule_set_098" + "remarks": "rule_set_108" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on cron.hourly", - "remarks": "rule_set_098" + "remarks": "rule_set_108" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_cron_hourly", - "remarks": "rule_set_098" + "remarks": "rule_set_108" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on cron.hourly", - "remarks": "rule_set_098" + "remarks": "rule_set_108" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_cron_daily", - "remarks": "rule_set_099" + "remarks": "rule_set_109" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns cron.daily", - "remarks": "rule_set_099" + "remarks": "rule_set_109" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_cron_daily", - "remarks": "rule_set_099" + "remarks": "rule_set_109" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns cron.daily", - "remarks": "rule_set_099" + "remarks": "rule_set_109" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_cron_daily", - "remarks": "rule_set_100" + "remarks": "rule_set_110" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on cron.daily", - "remarks": "rule_set_100" + "remarks": "rule_set_110" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_cron_daily", - "remarks": "rule_set_100" + "remarks": "rule_set_110" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on cron.daily", - "remarks": "rule_set_100" + "remarks": "rule_set_110" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_cron_daily", - "remarks": "rule_set_101" + "remarks": "rule_set_111" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on cron.daily", - "remarks": "rule_set_101" + "remarks": "rule_set_111" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_cron_daily", - "remarks": "rule_set_101" + "remarks": "rule_set_111" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on cron.daily", - "remarks": "rule_set_101" + "remarks": "rule_set_111" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_cron_weekly", - "remarks": "rule_set_102" + "remarks": "rule_set_112" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns cron.weekly", - "remarks": "rule_set_102" + "remarks": "rule_set_112" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_cron_weekly", - "remarks": "rule_set_102" + "remarks": "rule_set_112" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns cron.weekly", - "remarks": "rule_set_102" + "remarks": "rule_set_112" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_cron_weekly", - "remarks": "rule_set_103" + "remarks": "rule_set_113" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on cron.weekly", - "remarks": "rule_set_103" + "remarks": "rule_set_113" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_cron_weekly", - "remarks": "rule_set_103" + "remarks": "rule_set_113" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on cron.weekly", - "remarks": "rule_set_103" + "remarks": "rule_set_113" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_cron_weekly", - "remarks": "rule_set_104" + "remarks": "rule_set_114" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on cron.weekly", - "remarks": "rule_set_104" + "remarks": "rule_set_114" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_cron_weekly", - "remarks": "rule_set_104" + "remarks": "rule_set_114" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on cron.weekly", - "remarks": "rule_set_104" + "remarks": "rule_set_114" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_cron_monthly", - "remarks": "rule_set_105" + "remarks": "rule_set_115" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns cron.monthly", - "remarks": "rule_set_105" + "remarks": "rule_set_115" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_cron_monthly", - "remarks": "rule_set_105" + "remarks": "rule_set_115" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns cron.monthly", - "remarks": "rule_set_105" + "remarks": "rule_set_115" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_cron_monthly", - "remarks": "rule_set_106" + "remarks": "rule_set_116" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on cron.monthly", - "remarks": "rule_set_106" + "remarks": "rule_set_116" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_cron_monthly", - "remarks": "rule_set_106" + "remarks": "rule_set_116" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on cron.monthly", - "remarks": "rule_set_106" + "remarks": "rule_set_116" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_cron_monthly", - "remarks": "rule_set_107" + "remarks": "rule_set_117" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on cron.monthly", - "remarks": "rule_set_107" + "remarks": "rule_set_117" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_cron_monthly", - "remarks": "rule_set_107" + "remarks": "rule_set_117" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on cron.monthly", - "remarks": "rule_set_107" + "remarks": "rule_set_117" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_cron_d", - "remarks": "rule_set_108" + "remarks": "rule_set_118" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns cron.d", - "remarks": "rule_set_108" + "remarks": "rule_set_118" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_cron_d", - "remarks": "rule_set_108" + "remarks": "rule_set_118" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns cron.d", - "remarks": "rule_set_108" + "remarks": "rule_set_118" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_cron_d", - "remarks": "rule_set_109" + "remarks": "rule_set_119" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on cron.d", - "remarks": "rule_set_109" + "remarks": "rule_set_119" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_cron_d", - "remarks": "rule_set_109" + "remarks": "rule_set_119" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on cron.d", - "remarks": "rule_set_109" + "remarks": "rule_set_119" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_cron_d", - "remarks": "rule_set_110" + "remarks": "rule_set_120" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on cron.d", - "remarks": "rule_set_110" + "remarks": "rule_set_120" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_cron_d", - "remarks": "rule_set_110" + "remarks": "rule_set_120" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on cron.d", - "remarks": "rule_set_110" + "remarks": "rule_set_120" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_cron_deny_not_exist", - "remarks": "rule_set_111" + "remarks": "rule_set_121" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that /etc/cron.deny does not exist", - "remarks": "rule_set_111" + "remarks": "rule_set_121" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_cron_deny_not_exist", - "remarks": "rule_set_111" + "remarks": "rule_set_121" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that /etc/cron.deny does not exist", - "remarks": "rule_set_111" + "remarks": "rule_set_121" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_cron_allow_exists", - "remarks": "rule_set_112" + "remarks": "rule_set_122" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that /etc/cron.allow exists", - "remarks": "rule_set_112" + "remarks": "rule_set_122" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_cron_allow_exists", - "remarks": "rule_set_112" + "remarks": "rule_set_122" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that /etc/cron.allow exists", - "remarks": "rule_set_112" + "remarks": "rule_set_122" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_cron_allow", - "remarks": "rule_set_113" + "remarks": "rule_set_123" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns /etc/cron.allow file", - "remarks": "rule_set_113" + "remarks": "rule_set_123" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_cron_allow", - "remarks": "rule_set_113" + "remarks": "rule_set_123" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns /etc/cron.allow file", - "remarks": "rule_set_113" + "remarks": "rule_set_123" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_cron_allow", - "remarks": "rule_set_114" + "remarks": "rule_set_124" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns /etc/cron.allow file", - "remarks": "rule_set_114" + "remarks": "rule_set_124" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_cron_allow", - "remarks": "rule_set_114" + "remarks": "rule_set_124" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns /etc/cron.allow file", - "remarks": "rule_set_114" + "remarks": "rule_set_124" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_cron_allow", - "remarks": "rule_set_115" + "remarks": "rule_set_125" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on /etc/cron.allow file", - "remarks": "rule_set_115" + "remarks": "rule_set_125" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_cron_allow", - "remarks": "rule_set_115" + "remarks": "rule_set_125" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on /etc/cron.allow file", - "remarks": "rule_set_115" + "remarks": "rule_set_125" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_at_deny_not_exist", - "remarks": "rule_set_116" + "remarks": "rule_set_126" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that /etc/at.deny does not exist", - "remarks": "rule_set_116" + "remarks": "rule_set_126" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_at_deny_not_exist", - "remarks": "rule_set_116" + "remarks": "rule_set_126" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that /etc/at.deny does not exist", - "remarks": "rule_set_116" + "remarks": "rule_set_126" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_at_allow", - "remarks": "rule_set_117" + "remarks": "rule_set_127" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns /etc/at.allow file", - "remarks": "rule_set_117" + "remarks": "rule_set_127" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_at_allow", - "remarks": "rule_set_117" + "remarks": "rule_set_127" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns /etc/at.allow file", - "remarks": "rule_set_117" + "remarks": "rule_set_127" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_at_allow", - "remarks": "rule_set_118" + "remarks": "rule_set_128" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns /etc/at.allow file", - "remarks": "rule_set_118" + "remarks": "rule_set_128" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_at_allow", - "remarks": "rule_set_118" + "remarks": "rule_set_128" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns /etc/at.allow file", - "remarks": "rule_set_118" + "remarks": "rule_set_128" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_at_allow", - "remarks": "rule_set_119" + "remarks": "rule_set_129" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on /etc/at.allow file", - "remarks": "rule_set_119" + "remarks": "rule_set_129" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_at_allow", - "remarks": "rule_set_119" + "remarks": "rule_set_129" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on /etc/at.allow file", - "remarks": "rule_set_119" + "remarks": "rule_set_129" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "wireless_disable_interfaces", - "remarks": "rule_set_120" + "remarks": "rule_set_130" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Deactivate Wireless Network Interfaces", - "remarks": "rule_set_120" + "remarks": "rule_set_130" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "wireless_disable_interfaces", - "remarks": "rule_set_120" + "remarks": "rule_set_130" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Deactivate Wireless Network Interfaces", - "remarks": "rule_set_120" + "remarks": "rule_set_130" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_bluetooth_disabled", - "remarks": "rule_set_121" + "remarks": "rule_set_131" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Bluetooth Service", - "remarks": "rule_set_121" + "remarks": "rule_set_131" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_bluetooth_disabled", - "remarks": "rule_set_121" + "remarks": "rule_set_131" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Bluetooth Service", - "remarks": "rule_set_121" + "remarks": "rule_set_131" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "kernel_module_atm_disabled", + "remarks": "rule_set_132" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Disable ATM Support", + "remarks": "rule_set_132" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "kernel_module_atm_disabled", + "remarks": "rule_set_132" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Disable ATM Support", + "remarks": "rule_set_132" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "kernel_module_can_disabled", + "remarks": "rule_set_133" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Disable CAN Support", + "remarks": "rule_set_133" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "kernel_module_can_disabled", + "remarks": "rule_set_133" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Disable CAN Support", + "remarks": "rule_set_133" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "kernel_module_dccp_disabled", + "remarks": "rule_set_134" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Disable DCCP Support", + "remarks": "rule_set_134" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "kernel_module_dccp_disabled", + "remarks": "rule_set_134" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Disable DCCP Support", + "remarks": "rule_set_134" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "kernel_module_tipc_disabled", + "remarks": "rule_set_135" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Disable TIPC Support", + "remarks": "rule_set_135" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "kernel_module_tipc_disabled", + "remarks": "rule_set_135" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Disable TIPC Support", + "remarks": "rule_set_135" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "kernel_module_rds_disabled", + "remarks": "rule_set_136" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Disable RDS Support", + "remarks": "rule_set_136" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "kernel_module_rds_disabled", + "remarks": "rule_set_136" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Disable RDS Support", + "remarks": "rule_set_136" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_ip_forward", - "remarks": "rule_set_122" + "value": "kernel_module_sctp_disabled", + "remarks": "rule_set_137" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for IP Forwarding on IPv4 Interfaces", - "remarks": "rule_set_122" + "value": "Disable SCTP Support", + "remarks": "rule_set_137" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_ip_forward", - "remarks": "rule_set_122" + "value": "kernel_module_sctp_disabled", + "remarks": "rule_set_137" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for IP Forwarding on IPv4 Interfaces", - "remarks": "rule_set_122" + "value": "Disable SCTP Support", + "remarks": "rule_set_137" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_forwarding", - "remarks": "rule_set_123" + "value": "sysctl_net_ipv4_conf_all_forwarding", + "remarks": "rule_set_138" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for IPv6 Forwarding", - "remarks": "rule_set_123" + "value": "Disable Kernel Parameter for IPv4 Forwarding on all IPv4 Interfaces", + "remarks": "rule_set_138" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_forwarding", - "remarks": "rule_set_123" + "value": "sysctl_net_ipv4_conf_all_forwarding", + "remarks": "rule_set_138" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for IPv6 Forwarding", - "remarks": "rule_set_123" + "value": "Disable Kernel Parameter for IPv4 Forwarding on all IPv4 Interfaces", + "remarks": "rule_set_138" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_conf_all_send_redirects", - "remarks": "rule_set_124" + "remarks": "rule_set_139" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces", - "remarks": "rule_set_124" + "remarks": "rule_set_139" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_conf_all_send_redirects", - "remarks": "rule_set_124" + "remarks": "rule_set_139" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces", - "remarks": "rule_set_124" + "remarks": "rule_set_139" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_conf_default_send_redirects", - "remarks": "rule_set_125" + "remarks": "rule_set_140" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces by Default", - "remarks": "rule_set_125" + "remarks": "rule_set_140" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_conf_default_send_redirects", - "remarks": "rule_set_125" + "remarks": "rule_set_140" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces by Default", - "remarks": "rule_set_125" + "remarks": "rule_set_140" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses", - "remarks": "rule_set_126" + "remarks": "rule_set_141" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable Kernel Parameter to Ignore Bogus ICMP Error Responses on IPv4 Interfaces", - "remarks": "rule_set_126" + "remarks": "rule_set_141" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses", - "remarks": "rule_set_126" + "remarks": "rule_set_141" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable Kernel Parameter to Ignore Bogus ICMP Error Responses on IPv4 Interfaces", - "remarks": "rule_set_126" + "remarks": "rule_set_141" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts", - "remarks": "rule_set_127" + "remarks": "rule_set_142" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable Kernel Parameter to Ignore ICMP Broadcast Echo Requests on IPv4 Interfaces", - "remarks": "rule_set_127" + "remarks": "rule_set_142" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts", - "remarks": "rule_set_127" + "remarks": "rule_set_142" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable Kernel Parameter to Ignore ICMP Broadcast Echo Requests on IPv4 Interfaces", - "remarks": "rule_set_127" + "remarks": "rule_set_142" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_conf_all_accept_redirects", - "remarks": "rule_set_128" + "remarks": "rule_set_143" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Accepting ICMP Redirects for All IPv4 Interfaces", - "remarks": "rule_set_128" + "remarks": "rule_set_143" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_conf_all_accept_redirects", - "remarks": "rule_set_128" + "remarks": "rule_set_143" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Accepting ICMP Redirects for All IPv4 Interfaces", - "remarks": "rule_set_128" + "remarks": "rule_set_143" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_conf_default_accept_redirects", - "remarks": "rule_set_129" + "remarks": "rule_set_144" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 Interfaces", - "remarks": "rule_set_129" + "remarks": "rule_set_144" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_conf_default_accept_redirects", - "remarks": "rule_set_129" + "remarks": "rule_set_144" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 Interfaces", - "remarks": "rule_set_129" + "remarks": "rule_set_144" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_redirects", - "remarks": "rule_set_130" + "value": "sysctl_net_ipv4_conf_all_secure_redirects", + "remarks": "rule_set_145" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Accepting ICMP Redirects for All IPv6 Interfaces", - "remarks": "rule_set_130" + "value": "Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces", + "remarks": "rule_set_145" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_redirects", - "remarks": "rule_set_130" + "value": "sysctl_net_ipv4_conf_all_secure_redirects", + "remarks": "rule_set_145" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Accepting ICMP Redirects for All IPv6 Interfaces", - "remarks": "rule_set_130" + "value": "Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces", + "remarks": "rule_set_145" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_redirects", - "remarks": "rule_set_131" + "value": "sysctl_net_ipv4_conf_default_secure_redirects", + "remarks": "rule_set_146" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces", - "remarks": "rule_set_131" + "value": "Configure Kernel Parameter for Accepting Secure Redirects By Default", + "remarks": "rule_set_146" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_redirects", - "remarks": "rule_set_131" + "value": "sysctl_net_ipv4_conf_default_secure_redirects", + "remarks": "rule_set_146" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces", - "remarks": "rule_set_131" + "value": "Configure Kernel Parameter for Accepting Secure Redirects By Default", + "remarks": "rule_set_146" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_secure_redirects", - "remarks": "rule_set_132" + "value": "sysctl_net_ipv4_conf_all_rp_filter", + "remarks": "rule_set_147" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces", - "remarks": "rule_set_132" + "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces", + "remarks": "rule_set_147" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_secure_redirects", - "remarks": "rule_set_132" + "value": "sysctl_net_ipv4_conf_all_rp_filter", + "remarks": "rule_set_147" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces", - "remarks": "rule_set_132" + "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces", + "remarks": "rule_set_147" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_secure_redirects", - "remarks": "rule_set_133" + "value": "sysctl_net_ipv4_conf_default_rp_filter", + "remarks": "rule_set_148" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Kernel Parameter for Accepting Secure Redirects By Default", - "remarks": "rule_set_133" + "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces by Default", + "remarks": "rule_set_148" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_secure_redirects", - "remarks": "rule_set_133" + "value": "sysctl_net_ipv4_conf_default_rp_filter", + "remarks": "rule_set_148" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Kernel Parameter for Accepting Secure Redirects By Default", - "remarks": "rule_set_133" + "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces by Default", + "remarks": "rule_set_148" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_rp_filter", - "remarks": "rule_set_134" + "value": "sysctl_net_ipv4_conf_all_accept_source_route", + "remarks": "rule_set_149" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces", - "remarks": "rule_set_134" + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces", + "remarks": "rule_set_149" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_rp_filter", - "remarks": "rule_set_134" + "value": "sysctl_net_ipv4_conf_all_accept_source_route", + "remarks": "rule_set_149" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces", - "remarks": "rule_set_134" + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces", + "remarks": "rule_set_149" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_rp_filter", - "remarks": "rule_set_135" + "value": "sysctl_net_ipv4_conf_default_accept_source_route", + "remarks": "rule_set_150" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces by Default", - "remarks": "rule_set_135" + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces by Default", + "remarks": "rule_set_150" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_rp_filter", - "remarks": "rule_set_135" + "value": "sysctl_net_ipv4_conf_default_accept_source_route", + "remarks": "rule_set_150" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces by Default", - "remarks": "rule_set_135" + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces by Default", + "remarks": "rule_set_150" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_accept_source_route", - "remarks": "rule_set_136" + "value": "sysctl_net_ipv4_conf_all_log_martians", + "remarks": "rule_set_151" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces", - "remarks": "rule_set_136" + "value": "Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces", + "remarks": "rule_set_151" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_accept_source_route", - "remarks": "rule_set_136" + "value": "sysctl_net_ipv4_conf_all_log_martians", + "remarks": "rule_set_151" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces", - "remarks": "rule_set_136" + "value": "Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces", + "remarks": "rule_set_151" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_accept_source_route", - "remarks": "rule_set_137" + "value": "sysctl_net_ipv4_conf_default_log_martians", + "remarks": "rule_set_152" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces by Default", - "remarks": "rule_set_137" + "value": "Enable Kernel Paremeter to Log Martian Packets on all IPv4 Interfaces by Default", + "remarks": "rule_set_152" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_accept_source_route", - "remarks": "rule_set_137" + "value": "sysctl_net_ipv4_conf_default_log_martians", + "remarks": "rule_set_152" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces by Default", - "remarks": "rule_set_137" + "value": "Enable Kernel Paremeter to Log Martian Packets on all IPv4 Interfaces by Default", + "remarks": "rule_set_152" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_source_route", - "remarks": "rule_set_138" + "value": "sysctl_net_ipv4_tcp_syncookies", + "remarks": "rule_set_153" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces", - "remarks": "rule_set_138" + "value": "Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces", + "remarks": "rule_set_153" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_source_route", - "remarks": "rule_set_138" + "value": "sysctl_net_ipv4_tcp_syncookies", + "remarks": "rule_set_153" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces", - "remarks": "rule_set_138" + "value": "Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces", + "remarks": "rule_set_153" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_source_route", - "remarks": "rule_set_139" + "value": "sysctl_net_ipv6_conf_all_forwarding", + "remarks": "rule_set_154" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces by Default", - "remarks": "rule_set_139" + "value": "Disable Kernel Parameter for IPv6 Forwarding", + "remarks": "rule_set_154" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_source_route", - "remarks": "rule_set_139" + "value": "sysctl_net_ipv6_conf_all_forwarding", + "remarks": "rule_set_154" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces by Default", - "remarks": "rule_set_139" + "value": "Disable Kernel Parameter for IPv6 Forwarding", + "remarks": "rule_set_154" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_log_martians", - "remarks": "rule_set_140" + "value": "sysctl_net_ipv6_conf_default_forwarding", + "remarks": "rule_set_155" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces", - "remarks": "rule_set_140" + "value": "Disable Kernel Parameter for IPv6 Forwarding by default", + "remarks": "rule_set_155" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_log_martians", - "remarks": "rule_set_140" + "value": "sysctl_net_ipv6_conf_default_forwarding", + "remarks": "rule_set_155" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces", - "remarks": "rule_set_140" + "value": "Disable Kernel Parameter for IPv6 Forwarding by default", + "remarks": "rule_set_155" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_log_martians", - "remarks": "rule_set_141" + "value": "sysctl_net_ipv6_conf_all_accept_redirects", + "remarks": "rule_set_156" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Paremeter to Log Martian Packets on all IPv4 Interfaces by Default", - "remarks": "rule_set_141" + "value": "Disable Accepting ICMP Redirects for All IPv6 Interfaces", + "remarks": "rule_set_156" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_log_martians", - "remarks": "rule_set_141" + "value": "sysctl_net_ipv6_conf_all_accept_redirects", + "remarks": "rule_set_156" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Paremeter to Log Martian Packets on all IPv4 Interfaces by Default", - "remarks": "rule_set_141" + "value": "Disable Accepting ICMP Redirects for All IPv6 Interfaces", + "remarks": "rule_set_156" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_tcp_syncookies", - "remarks": "rule_set_142" + "value": "sysctl_net_ipv6_conf_default_accept_redirects", + "remarks": "rule_set_157" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces", - "remarks": "rule_set_142" + "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces", + "remarks": "rule_set_157" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_tcp_syncookies", - "remarks": "rule_set_142" + "value": "sysctl_net_ipv6_conf_default_accept_redirects", + "remarks": "rule_set_157" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces", - "remarks": "rule_set_142" + "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces", + "remarks": "rule_set_157" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_ra", - "remarks": "rule_set_143" + "value": "sysctl_net_ipv6_conf_all_accept_source_route", + "remarks": "rule_set_158" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Accepting Router Advertisements on All IPv6 Interfaces", - "remarks": "rule_set_143" + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces", + "remarks": "rule_set_158" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_ra", - "remarks": "rule_set_143" + "value": "sysctl_net_ipv6_conf_all_accept_source_route", + "remarks": "rule_set_158" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Accepting Router Advertisements on All IPv6 Interfaces", - "remarks": "rule_set_143" + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces", + "remarks": "rule_set_158" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_ra", - "remarks": "rule_set_144" + "value": "sysctl_net_ipv6_conf_default_accept_source_route", + "remarks": "rule_set_159" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Accepting Router Advertisements on all IPv6 Interfaces by Default", - "remarks": "rule_set_144" + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces by Default", + "remarks": "rule_set_159" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_ra", - "remarks": "rule_set_144" + "value": "sysctl_net_ipv6_conf_default_accept_source_route", + "remarks": "rule_set_159" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Accepting Router Advertisements on all IPv6 Interfaces by Default", - "remarks": "rule_set_144" + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces by Default", + "remarks": "rule_set_159" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_nftables_installed", - "remarks": "rule_set_145" + "value": "sysctl_net_ipv6_conf_all_accept_ra", + "remarks": "rule_set_160" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install nftables Package", - "remarks": "rule_set_145" + "value": "Configure Accepting Router Advertisements on All IPv6 Interfaces", + "remarks": "rule_set_160" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_nftables_installed", - "remarks": "rule_set_145" + "value": "sysctl_net_ipv6_conf_all_accept_ra", + "remarks": "rule_set_160" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install nftables Package", - "remarks": "rule_set_145" + "value": "Configure Accepting Router Advertisements on All IPv6 Interfaces", + "remarks": "rule_set_160" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_firewalld_enabled", - "remarks": "rule_set_146" + "value": "sysctl_net_ipv6_conf_default_accept_ra", + "remarks": "rule_set_161" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify firewalld Enabled", - "remarks": "rule_set_146" + "value": "Disable Accepting Router Advertisements on all IPv6 Interfaces by Default", + "remarks": "rule_set_161" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_firewalld_enabled", - "remarks": "rule_set_146" + "value": "sysctl_net_ipv6_conf_default_accept_ra", + "remarks": "rule_set_161" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify firewalld Enabled", - "remarks": "rule_set_146" + "value": "Disable Accepting Router Advertisements on all IPv6 Interfaces by Default", + "remarks": "rule_set_161" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_firewalld_installed", - "remarks": "rule_set_147" + "remarks": "rule_set_162" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Install firewalld Package", - "remarks": "rule_set_147" + "remarks": "rule_set_162" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_firewalld_installed", - "remarks": "rule_set_147" + "remarks": "rule_set_162" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Install firewalld Package", - "remarks": "rule_set_147" + "remarks": "rule_set_162" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_nftables_disabled", - "remarks": "rule_set_148" + "value": "service_firewalld_enabled", + "remarks": "rule_set_163" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify nftables Service is Disabled", - "remarks": "rule_set_148" + "value": "Verify firewalld Enabled", + "remarks": "rule_set_163" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_nftables_disabled", - "remarks": "rule_set_148" + "value": "service_firewalld_enabled", + "remarks": "rule_set_163" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify nftables Service is Disabled", - "remarks": "rule_set_148" + "value": "Verify firewalld Enabled", + "remarks": "rule_set_163" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "firewalld_loopback_traffic_trusted", - "remarks": "rule_set_149" + "remarks": "rule_set_164" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure Firewalld to Trust Loopback Traffic", - "remarks": "rule_set_149" + "remarks": "rule_set_164" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "firewalld_loopback_traffic_trusted", - "remarks": "rule_set_149" + "remarks": "rule_set_164" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure Firewalld to Trust Loopback Traffic", - "remarks": "rule_set_149" + "remarks": "rule_set_164" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "firewalld_loopback_traffic_restricted", - "remarks": "rule_set_150" + "remarks": "rule_set_165" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure Firewalld to Restrict Loopback Traffic", - "remarks": "rule_set_150" + "remarks": "rule_set_165" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "firewalld_loopback_traffic_restricted", - "remarks": "rule_set_150" + "remarks": "rule_set_165" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure Firewalld to Restrict Loopback Traffic", - "remarks": "rule_set_150" + "remarks": "rule_set_165" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_sshd_config", - "remarks": "rule_set_151" + "remarks": "rule_set_166" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns SSH Server config file", - "remarks": "rule_set_151" + "remarks": "rule_set_166" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_sshd_config", - "remarks": "rule_set_151" + "remarks": "rule_set_166" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns SSH Server config file", - "remarks": "rule_set_151" + "remarks": "rule_set_166" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_sshd_config", - "remarks": "rule_set_152" + "remarks": "rule_set_167" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on SSH Server config file", - "remarks": "rule_set_152" + "remarks": "rule_set_167" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_sshd_config", - "remarks": "rule_set_152" + "remarks": "rule_set_167" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on SSH Server config file", - "remarks": "rule_set_152" + "remarks": "rule_set_167" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_sshd_config", - "remarks": "rule_set_153" + "remarks": "rule_set_168" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on SSH Server config file", - "remarks": "rule_set_153" + "remarks": "rule_set_168" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_sshd_config", - "remarks": "rule_set_153" + "remarks": "rule_set_168" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on SSH Server config file", - "remarks": "rule_set_153" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_private_key", - "remarks": "rule_set_154" - }, - { - "name": "Rule_Description", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on SSH Server Private *_key Key Files", - "remarks": "rule_set_154" - }, - { - "name": "Check_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_private_key", - "remarks": "rule_set_154" - }, - { - "name": "Check_Description", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on SSH Server Private *_key Key Files", - "remarks": "rule_set_154" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_private_key", - "remarks": "rule_set_155" - }, - { - "name": "Rule_Description", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Ownership on SSH Server Private *_key Key Files", - "remarks": "rule_set_155" - }, - { - "name": "Check_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_private_key", - "remarks": "rule_set_155" - }, - { - "name": "Check_Description", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Ownership on SSH Server Private *_key Key Files", - "remarks": "rule_set_155" + "remarks": "rule_set_168" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupownership_sshd_private_key", - "remarks": "rule_set_156" + "remarks": "rule_set_169" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Ownership on SSH Server Private *_key Key Files", - "remarks": "rule_set_156" + "remarks": "rule_set_169" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupownership_sshd_private_key", - "remarks": "rule_set_156" + "remarks": "rule_set_169" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Ownership on SSH Server Private *_key Key Files", - "remarks": "rule_set_156" + "remarks": "rule_set_169" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_pub_key", - "remarks": "rule_set_157" + "value": "file_ownership_sshd_private_key", + "remarks": "rule_set_170" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on SSH Server Public *.pub Key Files", - "remarks": "rule_set_157" + "value": "Verify Ownership on SSH Server Private *_key Key Files", + "remarks": "rule_set_170" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_pub_key", - "remarks": "rule_set_157" + "value": "file_ownership_sshd_private_key", + "remarks": "rule_set_170" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on SSH Server Public *.pub Key Files", - "remarks": "rule_set_157" + "value": "Verify Ownership on SSH Server Private *_key Key Files", + "remarks": "rule_set_170" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_pub_key", - "remarks": "rule_set_158" + "value": "file_permissions_sshd_private_key", + "remarks": "rule_set_171" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Ownership on SSH Server Public *.pub Key Files", - "remarks": "rule_set_158" + "value": "Verify Permissions on SSH Server Private *_key Key Files", + "remarks": "rule_set_171" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_pub_key", - "remarks": "rule_set_158" + "value": "file_permissions_sshd_private_key", + "remarks": "rule_set_171" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Ownership on SSH Server Public *.pub Key Files", - "remarks": "rule_set_158" + "value": "Verify Permissions on SSH Server Private *_key Key Files", + "remarks": "rule_set_171" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupownership_sshd_pub_key", - "remarks": "rule_set_159" + "remarks": "rule_set_172" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Ownership on SSH Server Public *.pub Key Files", - "remarks": "rule_set_159" + "remarks": "rule_set_172" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupownership_sshd_pub_key", - "remarks": "rule_set_159" + "remarks": "rule_set_172" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Ownership on SSH Server Public *.pub Key Files", - "remarks": "rule_set_159" + "remarks": "rule_set_172" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_kex", - "remarks": "rule_set_160" + "value": "file_ownership_sshd_pub_key", + "remarks": "rule_set_173" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Use Only Strong Key Exchange algorithms", - "remarks": "rule_set_160" + "value": "Verify Ownership on SSH Server Public *.pub Key Files", + "remarks": "rule_set_173" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_kex", - "remarks": "rule_set_160" + "value": "file_ownership_sshd_pub_key", + "remarks": "rule_set_173" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Use Only Strong Key Exchange algorithms", - "remarks": "rule_set_160" + "value": "Verify Ownership on SSH Server Public *.pub Key Files", + "remarks": "rule_set_173" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_macs", - "remarks": "rule_set_161" + "value": "file_permissions_sshd_pub_key", + "remarks": "rule_set_174" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Use Only Strong MACs", - "remarks": "rule_set_161" + "value": "Verify Permissions on SSH Server Public *.pub Key Files", + "remarks": "rule_set_174" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_macs", - "remarks": "rule_set_161" + "value": "file_permissions_sshd_pub_key", + "remarks": "rule_set_174" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Use Only Strong MACs", - "remarks": "rule_set_161" + "value": "Verify Permissions on SSH Server Public *.pub Key Files", + "remarks": "rule_set_174" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_limit_user_access", - "remarks": "rule_set_162" + "remarks": "rule_set_175" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Limit Users' SSH Access", - "remarks": "rule_set_162" + "remarks": "rule_set_175" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_limit_user_access", - "remarks": "rule_set_162" + "remarks": "rule_set_175" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Limit Users' SSH Access", - "remarks": "rule_set_162" + "remarks": "rule_set_175" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_enable_warning_banner_net", - "remarks": "rule_set_163" + "remarks": "rule_set_176" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable SSH Warning Banner", - "remarks": "rule_set_163" + "remarks": "rule_set_176" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_enable_warning_banner_net", - "remarks": "rule_set_163" + "remarks": "rule_set_176" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable SSH Warning Banner", - "remarks": "rule_set_163" + "remarks": "rule_set_176" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_idle_timeout", - "remarks": "rule_set_164" + "remarks": "rule_set_177" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set SSH Client Alive Interval", - "remarks": "rule_set_164" + "remarks": "rule_set_177" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_idle_timeout", - "remarks": "rule_set_164" + "remarks": "rule_set_177" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set SSH Client Alive Interval", - "remarks": "rule_set_164" + "remarks": "rule_set_177" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_keepalive", - "remarks": "rule_set_165" + "remarks": "rule_set_178" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set SSH Client Alive Count Max", - "remarks": "rule_set_165" + "remarks": "rule_set_178" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_keepalive", - "remarks": "rule_set_165" + "remarks": "rule_set_178" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set SSH Client Alive Count Max", - "remarks": "rule_set_165" + "remarks": "rule_set_178" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "disable_host_auth", - "remarks": "rule_set_166" + "remarks": "rule_set_179" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Host-Based Authentication", - "remarks": "rule_set_166" + "remarks": "rule_set_179" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "disable_host_auth", - "remarks": "rule_set_166" + "remarks": "rule_set_179" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Host-Based Authentication", - "remarks": "rule_set_166" + "remarks": "rule_set_179" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_disable_rhosts", - "remarks": "rule_set_167" + "remarks": "rule_set_180" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable SSH Support for .rhosts Files", - "remarks": "rule_set_167" + "remarks": "rule_set_180" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_disable_rhosts", - "remarks": "rule_set_167" + "remarks": "rule_set_180" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable SSH Support for .rhosts Files", - "remarks": "rule_set_167" + "remarks": "rule_set_180" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_use_strong_kex", + "remarks": "rule_set_181" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Use Only Strong Key Exchange algorithms", + "remarks": "rule_set_181" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_use_strong_kex", + "remarks": "rule_set_181" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Use Only Strong Key Exchange algorithms", + "remarks": "rule_set_181" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_login_grace_time", - "remarks": "rule_set_168" + "remarks": "rule_set_182" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure SSH LoginGraceTime is configured", - "remarks": "rule_set_168" + "remarks": "rule_set_182" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_login_grace_time", - "remarks": "rule_set_168" + "remarks": "rule_set_182" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure SSH LoginGraceTime is configured", - "remarks": "rule_set_168" + "remarks": "rule_set_182" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_loglevel_verbose", - "remarks": "rule_set_169" + "remarks": "rule_set_183" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set SSH Daemon LogLevel to VERBOSE", - "remarks": "rule_set_169" + "remarks": "rule_set_183" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_loglevel_verbose", - "remarks": "rule_set_169" + "remarks": "rule_set_183" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set SSH Daemon LogLevel to VERBOSE", - "remarks": "rule_set_169" + "remarks": "rule_set_183" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_use_strong_macs", + "remarks": "rule_set_184" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Use Only Strong MACs", + "remarks": "rule_set_184" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_use_strong_macs", + "remarks": "rule_set_184" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Use Only Strong MACs", + "remarks": "rule_set_184" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_max_auth_tries", - "remarks": "rule_set_170" + "remarks": "rule_set_185" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set SSH authentication attempt limit", - "remarks": "rule_set_170" + "remarks": "rule_set_185" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_max_auth_tries", - "remarks": "rule_set_170" + "remarks": "rule_set_185" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set SSH authentication attempt limit", - "remarks": "rule_set_170" + "remarks": "rule_set_185" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_maxstartups", - "remarks": "rule_set_171" + "remarks": "rule_set_186" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure SSH MaxStartups is configured", - "remarks": "rule_set_171" + "remarks": "rule_set_186" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_maxstartups", - "remarks": "rule_set_171" + "remarks": "rule_set_186" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure SSH MaxStartups is configured", - "remarks": "rule_set_171" + "remarks": "rule_set_186" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_max_sessions", - "remarks": "rule_set_172" + "remarks": "rule_set_187" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set SSH MaxSessions limit", - "remarks": "rule_set_172" + "remarks": "rule_set_187" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_max_sessions", - "remarks": "rule_set_172" + "remarks": "rule_set_187" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set SSH MaxSessions limit", - "remarks": "rule_set_172" + "remarks": "rule_set_187" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_disable_empty_passwords", - "remarks": "rule_set_173" + "remarks": "rule_set_188" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable SSH Access via Empty Passwords", - "remarks": "rule_set_173" + "remarks": "rule_set_188" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_disable_empty_passwords", - "remarks": "rule_set_173" + "remarks": "rule_set_188" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable SSH Access via Empty Passwords", - "remarks": "rule_set_173" + "remarks": "rule_set_188" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_disable_root_login", - "remarks": "rule_set_174" + "remarks": "rule_set_189" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable SSH Root Login", - "remarks": "rule_set_174" + "remarks": "rule_set_189" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_disable_root_login", - "remarks": "rule_set_174" + "remarks": "rule_set_189" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable SSH Root Login", - "remarks": "rule_set_174" + "remarks": "rule_set_189" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_do_not_permit_user_env", - "remarks": "rule_set_175" + "remarks": "rule_set_190" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Do Not Allow SSH Environment Options", - "remarks": "rule_set_175" + "remarks": "rule_set_190" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_do_not_permit_user_env", - "remarks": "rule_set_175" + "remarks": "rule_set_190" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Do Not Allow SSH Environment Options", - "remarks": "rule_set_175" + "remarks": "rule_set_190" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_enable_pam", - "remarks": "rule_set_176" + "remarks": "rule_set_191" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable PAM", - "remarks": "rule_set_176" + "remarks": "rule_set_191" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_enable_pam", - "remarks": "rule_set_176" + "remarks": "rule_set_191" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable PAM", - "remarks": "rule_set_176" + "remarks": "rule_set_191" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_sudo_installed", - "remarks": "rule_set_177" + "remarks": "rule_set_192" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Install sudo Package", - "remarks": "rule_set_177" + "remarks": "rule_set_192" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_sudo_installed", - "remarks": "rule_set_177" + "remarks": "rule_set_192" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Install sudo Package", - "remarks": "rule_set_177" + "remarks": "rule_set_192" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sudo_add_use_pty", - "remarks": "rule_set_178" + "remarks": "rule_set_193" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Only Users Logged In To Real tty Can Execute Sudo - sudo use_pty", - "remarks": "rule_set_178" + "remarks": "rule_set_193" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sudo_add_use_pty", - "remarks": "rule_set_178" + "remarks": "rule_set_193" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Only Users Logged In To Real tty Can Execute Sudo - sudo use_pty", - "remarks": "rule_set_178" + "remarks": "rule_set_193" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sudo_custom_logfile", - "remarks": "rule_set_179" + "remarks": "rule_set_194" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Sudo Logfile Exists - sudo logfile", - "remarks": "rule_set_179" + "remarks": "rule_set_194" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sudo_custom_logfile", - "remarks": "rule_set_179" + "remarks": "rule_set_194" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Sudo Logfile Exists - sudo logfile", - "remarks": "rule_set_179" + "remarks": "rule_set_194" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_require_reauthentication", - "remarks": "rule_set_180" + "value": "sudo_require_authentication", + "remarks": "rule_set_195" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Require Re-Authentication When Using the sudo Command", - "remarks": "rule_set_180" + "value": "Ensure Users Re-Authenticate for Privilege Escalation - sudo", + "remarks": "rule_set_195" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_require_reauthentication", - "remarks": "rule_set_180" + "value": "sudo_require_authentication", + "remarks": "rule_set_195" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Require Re-Authentication When Using the sudo Command", - "remarks": "rule_set_180" + "value": "Ensure Users Re-Authenticate for Privilege Escalation - sudo", + "remarks": "rule_set_195" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "use_pam_wheel_group_for_su", - "remarks": "rule_set_181" + "value": "sudo_require_reauthentication", + "remarks": "rule_set_196" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enforce Usage of pam_wheel with Group Parameter for su Authentication", - "remarks": "rule_set_181" + "value": "Require Re-Authentication When Using the sudo Command", + "remarks": "rule_set_196" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "use_pam_wheel_group_for_su", - "remarks": "rule_set_181" + "value": "sudo_require_reauthentication", + "remarks": "rule_set_196" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enforce Usage of pam_wheel with Group Parameter for su Authentication", - "remarks": "rule_set_181" + "value": "Require Re-Authentication When Using the sudo Command", + "remarks": "rule_set_196" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_pam_wheel_group_empty", - "remarks": "rule_set_182" + "value": "use_pam_wheel_group_for_su", + "remarks": "rule_set_197" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure the Group Used by pam_wheel.so Module Exists on System and is Empty", - "remarks": "rule_set_182" + "value": "Enforce Usage of pam_wheel with Group Parameter for su Authentication", + "remarks": "rule_set_197" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_pam_wheel_group_empty", - "remarks": "rule_set_182" + "value": "use_pam_wheel_group_for_su", + "remarks": "rule_set_197" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure the Group Used by pam_wheel.so Module Exists on System and is Empty", - "remarks": "rule_set_182" + "value": "Enforce Usage of pam_wheel with Group Parameter for su Authentication", + "remarks": "rule_set_197" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_pam_pwquality_installed", - "remarks": "rule_set_183" + "value": "ensure_pam_wheel_group_empty", + "remarks": "rule_set_198" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install pam_pwquality Package", - "remarks": "rule_set_183" + "value": "Ensure the Group Used by pam_wheel.so Module Exists on System and is Empty", + "remarks": "rule_set_198" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_pam_pwquality_installed", - "remarks": "rule_set_183" + "value": "ensure_pam_wheel_group_empty", + "remarks": "rule_set_198" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install pam_pwquality Package", - "remarks": "rule_set_183" + "value": "Ensure the Group Used by pam_wheel.so Module Exists on System and is Empty", + "remarks": "rule_set_198" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "account_password_pam_faillock_password_auth", - "remarks": "rule_set_184" + "remarks": "rule_set_199" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth File.", - "remarks": "rule_set_184" + "remarks": "rule_set_199" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "account_password_pam_faillock_password_auth", - "remarks": "rule_set_184" + "remarks": "rule_set_199" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth File.", - "remarks": "rule_set_184" + "remarks": "rule_set_199" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "account_password_pam_faillock_system_auth", - "remarks": "rule_set_185" + "remarks": "rule_set_200" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth File.", - "remarks": "rule_set_185" + "remarks": "rule_set_200" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "account_password_pam_faillock_system_auth", - "remarks": "rule_set_185" + "remarks": "rule_set_200" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth File.", - "remarks": "rule_set_185" + "remarks": "rule_set_200" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "package_pam_pwquality_installed", + "remarks": "rule_set_201" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Install pam_pwquality Package", + "remarks": "rule_set_201" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "package_pam_pwquality_installed", + "remarks": "rule_set_201" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Install pam_pwquality Package", + "remarks": "rule_set_201" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_passwords_pam_faillock_deny", - "remarks": "rule_set_186" + "remarks": "rule_set_202" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Lock Accounts After Failed Password Attempts", - "remarks": "rule_set_186" + "remarks": "rule_set_202" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_passwords_pam_faillock_deny", - "remarks": "rule_set_186" + "remarks": "rule_set_202" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Lock Accounts After Failed Password Attempts", - "remarks": "rule_set_186" + "remarks": "rule_set_202" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_passwords_pam_faillock_unlock_time", - "remarks": "rule_set_187" + "remarks": "rule_set_203" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Lockout Time for Failed Password Attempts", - "remarks": "rule_set_187" + "remarks": "rule_set_203" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_passwords_pam_faillock_unlock_time", - "remarks": "rule_set_187" + "remarks": "rule_set_203" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Lockout Time for Failed Password Attempts", - "remarks": "rule_set_187" + "remarks": "rule_set_203" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_difok", - "remarks": "rule_set_188" + "remarks": "rule_set_204" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure PAM Enforces Password Requirements - Minimum Different Characters", - "remarks": "rule_set_188" + "remarks": "rule_set_204" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_difok", - "remarks": "rule_set_188" + "remarks": "rule_set_204" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure PAM Enforces Password Requirements - Minimum Different Characters", - "remarks": "rule_set_188" + "remarks": "rule_set_204" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_minlen", - "remarks": "rule_set_189" + "remarks": "rule_set_205" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure PAM Enforces Password Requirements - Minimum Length", - "remarks": "rule_set_189" + "remarks": "rule_set_205" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_minlen", - "remarks": "rule_set_189" + "remarks": "rule_set_205" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure PAM Enforces Password Requirements - Minimum Length", - "remarks": "rule_set_189" + "remarks": "rule_set_205" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_minclass", - "remarks": "rule_set_190" + "remarks": "rule_set_206" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure PAM Enforces Password Requirements - Minimum Different Categories", - "remarks": "rule_set_190" + "remarks": "rule_set_206" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_minclass", - "remarks": "rule_set_190" + "remarks": "rule_set_206" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure PAM Enforces Password Requirements - Minimum Different Categories", - "remarks": "rule_set_190" + "remarks": "rule_set_206" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_maxrepeat", - "remarks": "rule_set_191" + "remarks": "rule_set_207" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Password Maximum Consecutive Repeating Characters", - "remarks": "rule_set_191" + "remarks": "rule_set_207" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_maxrepeat", - "remarks": "rule_set_191" + "remarks": "rule_set_207" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Password Maximum Consecutive Repeating Characters", - "remarks": "rule_set_191" + "remarks": "rule_set_207" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_dictcheck", - "remarks": "rule_set_192" + "remarks": "rule_set_208" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure PAM Enforces Password Requirements - Prevent the Use of Dictionary Words", - "remarks": "rule_set_192" + "remarks": "rule_set_208" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_dictcheck", - "remarks": "rule_set_192" + "remarks": "rule_set_208" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure PAM Enforces Password Requirements - Prevent the Use of Dictionary Words", - "remarks": "rule_set_192" + "remarks": "rule_set_208" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_enforce_root", - "remarks": "rule_set_193" + "remarks": "rule_set_209" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure PAM Enforces Password Requirements - Enforce for root User", - "remarks": "rule_set_193" + "remarks": "rule_set_209" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_enforce_root", - "remarks": "rule_set_193" + "remarks": "rule_set_209" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure PAM Enforces Password Requirements - Enforce for root User", - "remarks": "rule_set_193" + "remarks": "rule_set_209" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_pwhistory_remember_password_auth", - "remarks": "rule_set_194" + "remarks": "rule_set_210" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Limit Password Reuse: password-auth", - "remarks": "rule_set_194" + "remarks": "rule_set_210" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_pwhistory_remember_password_auth", - "remarks": "rule_set_194" + "remarks": "rule_set_210" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Limit Password Reuse: password-auth", - "remarks": "rule_set_194" + "remarks": "rule_set_210" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_pwhistory_remember_system_auth", - "remarks": "rule_set_195" + "remarks": "rule_set_211" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Limit Password Reuse: system-auth", - "remarks": "rule_set_195" + "remarks": "rule_set_211" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_pwhistory_remember_system_auth", - "remarks": "rule_set_195" + "remarks": "rule_set_211" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Limit Password Reuse: system-auth", - "remarks": "rule_set_195" + "remarks": "rule_set_211" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_empty_passwords", - "remarks": "rule_set_196" + "remarks": "rule_set_212" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Prevent Login to Accounts With Empty Password", - "remarks": "rule_set_196" + "remarks": "rule_set_212" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_empty_passwords", - "remarks": "rule_set_196" + "remarks": "rule_set_212" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Prevent Login to Accounts With Empty Password", - "remarks": "rule_set_196" + "remarks": "rule_set_212" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "set_password_hashing_algorithm_systemauth", - "remarks": "rule_set_197" + "remarks": "rule_set_213" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set PAM''s Password Hashing Algorithm", - "remarks": "rule_set_197" + "remarks": "rule_set_213" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "set_password_hashing_algorithm_systemauth", - "remarks": "rule_set_197" + "remarks": "rule_set_213" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set PAM''s Password Hashing Algorithm", - "remarks": "rule_set_197" + "remarks": "rule_set_213" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "set_password_hashing_algorithm_passwordauth", - "remarks": "rule_set_198" + "remarks": "rule_set_214" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set PAM''s Password Hashing Algorithm - password-auth", - "remarks": "rule_set_198" + "remarks": "rule_set_214" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "set_password_hashing_algorithm_passwordauth", - "remarks": "rule_set_198" + "remarks": "rule_set_214" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set PAM''s Password Hashing Algorithm - password-auth", - "remarks": "rule_set_198" + "remarks": "rule_set_214" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_maximum_age_login_defs", - "remarks": "rule_set_199" + "remarks": "rule_set_215" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Password Maximum Age", - "remarks": "rule_set_199" + "remarks": "rule_set_215" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_maximum_age_login_defs", - "remarks": "rule_set_199" + "remarks": "rule_set_215" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Password Maximum Age", - "remarks": "rule_set_199" + "remarks": "rule_set_215" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_set_max_life_existing", - "remarks": "rule_set_200" + "remarks": "rule_set_216" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Existing Passwords Maximum Age", - "remarks": "rule_set_200" + "remarks": "rule_set_216" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_set_max_life_existing", - "remarks": "rule_set_200" + "remarks": "rule_set_216" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Existing Passwords Maximum Age", - "remarks": "rule_set_200" + "remarks": "rule_set_216" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_warn_age_login_defs", - "remarks": "rule_set_201" + "remarks": "rule_set_217" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Password Warning Age", - "remarks": "rule_set_201" + "remarks": "rule_set_217" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_warn_age_login_defs", - "remarks": "rule_set_201" + "remarks": "rule_set_217" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Password Warning Age", - "remarks": "rule_set_201" + "remarks": "rule_set_217" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_set_warn_age_existing", - "remarks": "rule_set_202" + "remarks": "rule_set_218" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Existing Passwords Warning Age", - "remarks": "rule_set_202" + "remarks": "rule_set_218" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_set_warn_age_existing", - "remarks": "rule_set_202" + "remarks": "rule_set_218" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Existing Passwords Warning Age", - "remarks": "rule_set_202" + "remarks": "rule_set_218" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "set_password_hashing_algorithm_libuserconf", - "remarks": "rule_set_203" + "remarks": "rule_set_219" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Password Hashing Algorithm in /etc/libuser.conf", - "remarks": "rule_set_203" + "remarks": "rule_set_219" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "set_password_hashing_algorithm_libuserconf", - "remarks": "rule_set_203" + "remarks": "rule_set_219" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Password Hashing Algorithm in /etc/libuser.conf", - "remarks": "rule_set_203" + "remarks": "rule_set_219" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "set_password_hashing_algorithm_logindefs", - "remarks": "rule_set_204" + "remarks": "rule_set_220" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Password Hashing Algorithm in /etc/login.defs", - "remarks": "rule_set_204" + "remarks": "rule_set_220" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "set_password_hashing_algorithm_logindefs", - "remarks": "rule_set_204" + "remarks": "rule_set_220" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Password Hashing Algorithm in /etc/login.defs", - "remarks": "rule_set_204" + "remarks": "rule_set_220" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "account_disable_post_pw_expiration", - "remarks": "rule_set_205" + "remarks": "rule_set_221" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Account Expiration Following Inactivity", - "remarks": "rule_set_205" + "remarks": "rule_set_221" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "account_disable_post_pw_expiration", - "remarks": "rule_set_205" + "remarks": "rule_set_221" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Account Expiration Following Inactivity", - "remarks": "rule_set_205" + "remarks": "rule_set_221" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_set_post_pw_existing", - "remarks": "rule_set_206" + "remarks": "rule_set_222" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set existing passwords a period of inactivity before they been locked", - "remarks": "rule_set_206" + "remarks": "rule_set_222" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_set_post_pw_existing", - "remarks": "rule_set_206" + "remarks": "rule_set_222" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set existing passwords a period of inactivity before they been locked", - "remarks": "rule_set_206" + "remarks": "rule_set_222" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_last_change_is_in_past", - "remarks": "rule_set_207" + "remarks": "rule_set_223" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure all users last password change date is in the past", - "remarks": "rule_set_207" + "remarks": "rule_set_223" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_last_change_is_in_past", - "remarks": "rule_set_207" + "remarks": "rule_set_223" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure all users last password change date is in the past", - "remarks": "rule_set_207" + "remarks": "rule_set_223" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_no_uid_except_zero", - "remarks": "rule_set_208" + "remarks": "rule_set_224" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Only Root Has UID 0", - "remarks": "rule_set_208" + "remarks": "rule_set_224" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_no_uid_except_zero", - "remarks": "rule_set_208" + "remarks": "rule_set_224" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Only Root Has UID 0", - "remarks": "rule_set_208" + "remarks": "rule_set_224" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_root_gid_zero", - "remarks": "rule_set_209" + "remarks": "rule_set_225" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Root Has A Primary GID 0", - "remarks": "rule_set_209" + "remarks": "rule_set_225" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_root_gid_zero", + "remarks": "rule_set_225" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify Root Has A Primary GID 0", + "remarks": "rule_set_225" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "groups_no_zero_gid_except_root", + "remarks": "rule_set_226" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify Only Group Root Has GID 0", + "remarks": "rule_set_226" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_root_gid_zero", - "remarks": "rule_set_209" + "value": "groups_no_zero_gid_except_root", + "remarks": "rule_set_226" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Root Has A Primary GID 0", - "remarks": "rule_set_209" + "value": "Verify Only Group Root Has GID 0", + "remarks": "rule_set_226" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "ensure_root_password_configured", - "remarks": "rule_set_210" + "remarks": "rule_set_227" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Authentication Required for Single User Mode", - "remarks": "rule_set_210" + "remarks": "rule_set_227" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "ensure_root_password_configured", - "remarks": "rule_set_210" + "remarks": "rule_set_227" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Authentication Required for Single User Mode", - "remarks": "rule_set_210" + "remarks": "rule_set_227" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_root_path_dirs_no_write", - "remarks": "rule_set_211" + "remarks": "rule_set_228" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that Root's Path Does Not Include World or Group-Writable Directories", - "remarks": "rule_set_211" + "remarks": "rule_set_228" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_root_path_dirs_no_write", - "remarks": "rule_set_211" + "remarks": "rule_set_228" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that Root's Path Does Not Include World or Group-Writable Directories", - "remarks": "rule_set_211" + "remarks": "rule_set_228" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "root_path_no_dot", - "remarks": "rule_set_212" + "remarks": "rule_set_229" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that Root's Path Does Not Include Relative Paths or Null Directories", - "remarks": "rule_set_212" + "remarks": "rule_set_229" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "root_path_no_dot", - "remarks": "rule_set_212" + "remarks": "rule_set_229" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that Root's Path Does Not Include Relative Paths or Null Directories", - "remarks": "rule_set_212" + "remarks": "rule_set_229" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_umask_root", + "remarks": "rule_set_230" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure the Root Bash Umask is Set Correctly", + "remarks": "rule_set_230" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_umask_root", + "remarks": "rule_set_230" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure the Root Bash Umask is Set Correctly", + "remarks": "rule_set_230" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_password_auth_for_systemaccounts", - "remarks": "rule_set_213" + "remarks": "rule_set_231" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that System Accounts Are Locked", - "remarks": "rule_set_213" + "remarks": "rule_set_231" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_password_auth_for_systemaccounts", - "remarks": "rule_set_213" + "remarks": "rule_set_231" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that System Accounts Are Locked", - "remarks": "rule_set_213" + "remarks": "rule_set_231" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_shelllogin_for_systemaccounts", - "remarks": "rule_set_214" + "remarks": "rule_set_232" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that System Accounts Do Not Run a Shell Upon Login", - "remarks": "rule_set_214" + "remarks": "rule_set_232" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_shelllogin_for_systemaccounts", - "remarks": "rule_set_214" + "remarks": "rule_set_232" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that System Accounts Do Not Run a Shell Upon Login", - "remarks": "rule_set_214" + "remarks": "rule_set_232" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_tmout", - "remarks": "rule_set_215" + "remarks": "rule_set_233" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Interactive Session Timeout", - "remarks": "rule_set_215" + "remarks": "rule_set_233" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_tmout", - "remarks": "rule_set_215" + "remarks": "rule_set_233" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Interactive Session Timeout", - "remarks": "rule_set_215" + "remarks": "rule_set_233" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_umask_etc_bashrc", - "remarks": "rule_set_216" + "remarks": "rule_set_234" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure the Default Bash Umask is Set Correctly", - "remarks": "rule_set_216" + "remarks": "rule_set_234" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_umask_etc_bashrc", - "remarks": "rule_set_216" + "remarks": "rule_set_234" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure the Default Bash Umask is Set Correctly", - "remarks": "rule_set_216" + "remarks": "rule_set_234" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_umask_etc_login_defs", - "remarks": "rule_set_217" + "remarks": "rule_set_235" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure the Default Umask is Set Correctly in login.defs", - "remarks": "rule_set_217" + "remarks": "rule_set_235" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_umask_etc_login_defs", - "remarks": "rule_set_217" + "remarks": "rule_set_235" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure the Default Umask is Set Correctly in login.defs", - "remarks": "rule_set_217" + "remarks": "rule_set_235" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_umask_etc_profile", - "remarks": "rule_set_218" + "remarks": "rule_set_236" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure the Default Umask is Set Correctly in /etc/profile", - "remarks": "rule_set_218" + "remarks": "rule_set_236" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_umask_etc_profile", - "remarks": "rule_set_218" + "remarks": "rule_set_236" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure the Default Umask is Set Correctly in /etc/profile", - "remarks": "rule_set_218" + "remarks": "rule_set_236" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_aide_installed", - "remarks": "rule_set_219" + "remarks": "rule_set_237" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Install AIDE", - "remarks": "rule_set_219" + "remarks": "rule_set_237" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_aide_installed", - "remarks": "rule_set_219" + "remarks": "rule_set_237" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Install AIDE", - "remarks": "rule_set_219" + "remarks": "rule_set_237" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "aide_build_database", - "remarks": "rule_set_220" + "remarks": "rule_set_238" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Build and Test AIDE Database", - "remarks": "rule_set_220" + "remarks": "rule_set_238" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "aide_build_database", - "remarks": "rule_set_220" + "remarks": "rule_set_238" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Build and Test AIDE Database", - "remarks": "rule_set_220" + "remarks": "rule_set_238" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "aide_periodic_cron_checking", - "remarks": "rule_set_221" + "remarks": "rule_set_239" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure Periodic Execution of AIDE", - "remarks": "rule_set_221" + "remarks": "rule_set_239" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "aide_periodic_cron_checking", - "remarks": "rule_set_221" + "remarks": "rule_set_239" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure Periodic Execution of AIDE", - "remarks": "rule_set_221" + "remarks": "rule_set_239" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "aide_check_audit_tools", - "remarks": "rule_set_222" + "remarks": "rule_set_240" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure AIDE to Verify the Audit Tools", - "remarks": "rule_set_222" + "remarks": "rule_set_240" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "aide_check_audit_tools", - "remarks": "rule_set_222" + "remarks": "rule_set_240" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure AIDE to Verify the Audit Tools", - "remarks": "rule_set_222" + "remarks": "rule_set_240" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_systemd-journald_enabled", - "remarks": "rule_set_223" + "remarks": "rule_set_241" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable systemd-journald Service", - "remarks": "rule_set_223" + "remarks": "rule_set_241" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_systemd-journald_enabled", - "remarks": "rule_set_223" + "remarks": "rule_set_241" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable systemd-journald Service", - "remarks": "rule_set_223" + "remarks": "rule_set_241" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_systemd-journal-remote_installed", - "remarks": "rule_set_224" + "value": "journald_compress", + "remarks": "rule_set_242" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install systemd-journal-remote Package", - "remarks": "rule_set_224" + "value": "Ensure journald is configured to compress large log files", + "remarks": "rule_set_242" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_systemd-journal-remote_installed", - "remarks": "rule_set_224" + "value": "journald_compress", + "remarks": "rule_set_242" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install systemd-journal-remote Package", - "remarks": "rule_set_224" + "value": "Ensure journald is configured to compress large log files", + "remarks": "rule_set_242" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "socket_systemd-journal-remote_disabled", - "remarks": "rule_set_225" + "value": "journald_storage", + "remarks": "rule_set_243" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable systemd-journal-remote Socket", - "remarks": "rule_set_225" + "value": "Ensure journald is configured to write log files to persistent disk", + "remarks": "rule_set_243" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "socket_systemd-journal-remote_disabled", - "remarks": "rule_set_225" + "value": "journald_storage", + "remarks": "rule_set_243" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable systemd-journal-remote Socket", - "remarks": "rule_set_225" + "value": "Ensure journald is configured to write log files to persistent disk", + "remarks": "rule_set_243" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_compress", - "remarks": "rule_set_226" + "value": "package_systemd-journal-remote_installed", + "remarks": "rule_set_244" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure journald is configured to compress large log files", - "remarks": "rule_set_226" + "value": "Install systemd-journal-remote Package", + "remarks": "rule_set_244" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_compress", - "remarks": "rule_set_226" + "value": "package_systemd-journal-remote_installed", + "remarks": "rule_set_244" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure journald is configured to compress large log files", - "remarks": "rule_set_226" + "value": "Install systemd-journal-remote Package", + "remarks": "rule_set_244" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_storage", - "remarks": "rule_set_227" + "value": "socket_systemd-journal-remote_disabled", + "remarks": "rule_set_245" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure journald is configured to write log files to persistent disk", - "remarks": "rule_set_227" + "value": "Disable systemd-journal-remote Socket", + "remarks": "rule_set_245" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_storage", - "remarks": "rule_set_227" + "value": "socket_systemd-journal-remote_disabled", + "remarks": "rule_set_245" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure journald is configured to write log files to persistent disk", - "remarks": "rule_set_227" + "value": "Disable systemd-journal-remote Socket", + "remarks": "rule_set_245" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "rsyslog_files_groupownership", - "remarks": "rule_set_228" + "remarks": "rule_set_246" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Log Files Are Owned By Appropriate Group", - "remarks": "rule_set_228" + "remarks": "rule_set_246" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "rsyslog_files_groupownership", - "remarks": "rule_set_228" + "remarks": "rule_set_246" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Log Files Are Owned By Appropriate Group", - "remarks": "rule_set_228" + "remarks": "rule_set_246" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "rsyslog_files_ownership", - "remarks": "rule_set_229" + "remarks": "rule_set_247" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Log Files Are Owned By Appropriate User", - "remarks": "rule_set_229" + "remarks": "rule_set_247" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "rsyslog_files_ownership", - "remarks": "rule_set_229" + "remarks": "rule_set_247" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Log Files Are Owned By Appropriate User", - "remarks": "rule_set_229" + "remarks": "rule_set_247" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "rsyslog_files_permissions", - "remarks": "rule_set_230" + "remarks": "rule_set_248" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure System Log Files Have Correct Permissions", - "remarks": "rule_set_230" + "remarks": "rule_set_248" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "rsyslog_files_permissions", - "remarks": "rule_set_230" + "remarks": "rule_set_248" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure System Log Files Have Correct Permissions", - "remarks": "rule_set_230" + "remarks": "rule_set_248" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_passwd", - "remarks": "rule_set_231" + "remarks": "rule_set_249" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns passwd File", - "remarks": "rule_set_231" + "remarks": "rule_set_249" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_passwd", - "remarks": "rule_set_231" + "remarks": "rule_set_249" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns passwd File", - "remarks": "rule_set_231" + "remarks": "rule_set_249" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_passwd", - "remarks": "rule_set_232" + "remarks": "rule_set_250" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns passwd File", - "remarks": "rule_set_232" + "remarks": "rule_set_250" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_passwd", - "remarks": "rule_set_232" + "remarks": "rule_set_250" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns passwd File", - "remarks": "rule_set_232" + "remarks": "rule_set_250" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_passwd", - "remarks": "rule_set_233" + "remarks": "rule_set_251" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on passwd File", - "remarks": "rule_set_233" + "remarks": "rule_set_251" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_passwd", - "remarks": "rule_set_233" + "remarks": "rule_set_251" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on passwd File", - "remarks": "rule_set_233" + "remarks": "rule_set_251" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_backup_etc_passwd", - "remarks": "rule_set_234" + "remarks": "rule_set_252" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns Backup passwd File", - "remarks": "rule_set_234" + "remarks": "rule_set_252" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_backup_etc_passwd", - "remarks": "rule_set_234" + "remarks": "rule_set_252" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns Backup passwd File", - "remarks": "rule_set_234" + "remarks": "rule_set_252" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_backup_etc_passwd", - "remarks": "rule_set_235" + "remarks": "rule_set_253" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns Backup passwd File", - "remarks": "rule_set_235" + "remarks": "rule_set_253" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_backup_etc_passwd", - "remarks": "rule_set_235" + "remarks": "rule_set_253" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns Backup passwd File", - "remarks": "rule_set_235" + "remarks": "rule_set_253" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_backup_etc_passwd", - "remarks": "rule_set_236" + "remarks": "rule_set_254" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on Backup passwd File", - "remarks": "rule_set_236" + "remarks": "rule_set_254" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_backup_etc_passwd", - "remarks": "rule_set_236" + "remarks": "rule_set_254" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on Backup passwd File", - "remarks": "rule_set_236" + "remarks": "rule_set_254" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_group", - "remarks": "rule_set_237" + "remarks": "rule_set_255" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns group File", - "remarks": "rule_set_237" + "remarks": "rule_set_255" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_group", - "remarks": "rule_set_237" + "remarks": "rule_set_255" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns group File", - "remarks": "rule_set_237" + "remarks": "rule_set_255" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_group", - "remarks": "rule_set_238" + "remarks": "rule_set_256" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns group File", - "remarks": "rule_set_238" + "remarks": "rule_set_256" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_group", - "remarks": "rule_set_238" + "remarks": "rule_set_256" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns group File", - "remarks": "rule_set_238" + "remarks": "rule_set_256" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_group", - "remarks": "rule_set_239" + "remarks": "rule_set_257" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on group File", - "remarks": "rule_set_239" + "remarks": "rule_set_257" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_group", - "remarks": "rule_set_239" + "remarks": "rule_set_257" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on group File", - "remarks": "rule_set_239" + "remarks": "rule_set_257" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_backup_etc_group", - "remarks": "rule_set_240" + "remarks": "rule_set_258" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns Backup group File", - "remarks": "rule_set_240" + "remarks": "rule_set_258" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_backup_etc_group", - "remarks": "rule_set_240" + "remarks": "rule_set_258" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns Backup group File", - "remarks": "rule_set_240" + "remarks": "rule_set_258" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_backup_etc_group", - "remarks": "rule_set_241" + "remarks": "rule_set_259" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns Backup group File", - "remarks": "rule_set_241" + "remarks": "rule_set_259" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_backup_etc_group", - "remarks": "rule_set_241" + "remarks": "rule_set_259" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns Backup group File", - "remarks": "rule_set_241" + "remarks": "rule_set_259" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_backup_etc_group", - "remarks": "rule_set_242" + "remarks": "rule_set_260" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on Backup group File", - "remarks": "rule_set_242" + "remarks": "rule_set_260" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_backup_etc_group", - "remarks": "rule_set_242" + "remarks": "rule_set_260" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on Backup group File", - "remarks": "rule_set_242" + "remarks": "rule_set_260" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_shadow", - "remarks": "rule_set_243" + "remarks": "rule_set_261" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns shadow File", - "remarks": "rule_set_243" + "remarks": "rule_set_261" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_shadow", - "remarks": "rule_set_243" + "remarks": "rule_set_261" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns shadow File", - "remarks": "rule_set_243" + "remarks": "rule_set_261" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_shadow", - "remarks": "rule_set_244" + "remarks": "rule_set_262" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns shadow File", - "remarks": "rule_set_244" + "remarks": "rule_set_262" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_shadow", - "remarks": "rule_set_244" + "remarks": "rule_set_262" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns shadow File", - "remarks": "rule_set_244" + "remarks": "rule_set_262" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_shadow", - "remarks": "rule_set_245" + "remarks": "rule_set_263" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on shadow File", - "remarks": "rule_set_245" + "remarks": "rule_set_263" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_shadow", - "remarks": "rule_set_245" + "remarks": "rule_set_263" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on shadow File", - "remarks": "rule_set_245" + "remarks": "rule_set_263" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_backup_etc_shadow", - "remarks": "rule_set_246" + "remarks": "rule_set_264" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns Backup shadow File", - "remarks": "rule_set_246" + "remarks": "rule_set_264" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_backup_etc_shadow", - "remarks": "rule_set_246" + "remarks": "rule_set_264" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns Backup shadow File", - "remarks": "rule_set_246" + "remarks": "rule_set_264" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_backup_etc_shadow", - "remarks": "rule_set_247" + "remarks": "rule_set_265" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns Backup shadow File", - "remarks": "rule_set_247" + "remarks": "rule_set_265" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_backup_etc_shadow", - "remarks": "rule_set_247" + "remarks": "rule_set_265" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns Backup shadow File", - "remarks": "rule_set_247" + "remarks": "rule_set_265" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_backup_etc_shadow", - "remarks": "rule_set_248" + "remarks": "rule_set_266" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on Backup shadow File", - "remarks": "rule_set_248" + "remarks": "rule_set_266" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_backup_etc_shadow", - "remarks": "rule_set_248" + "remarks": "rule_set_266" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on Backup shadow File", - "remarks": "rule_set_248" + "remarks": "rule_set_266" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_gshadow", - "remarks": "rule_set_249" + "remarks": "rule_set_267" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns gshadow File", - "remarks": "rule_set_249" + "remarks": "rule_set_267" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_gshadow", - "remarks": "rule_set_249" + "remarks": "rule_set_267" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns gshadow File", - "remarks": "rule_set_249" + "remarks": "rule_set_267" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_gshadow", - "remarks": "rule_set_250" + "remarks": "rule_set_268" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns gshadow File", - "remarks": "rule_set_250" + "remarks": "rule_set_268" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_gshadow", - "remarks": "rule_set_250" + "remarks": "rule_set_268" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns gshadow File", - "remarks": "rule_set_250" + "remarks": "rule_set_268" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_gshadow", - "remarks": "rule_set_251" + "remarks": "rule_set_269" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on gshadow File", - "remarks": "rule_set_251" + "remarks": "rule_set_269" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_gshadow", - "remarks": "rule_set_251" + "remarks": "rule_set_269" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on gshadow File", - "remarks": "rule_set_251" + "remarks": "rule_set_269" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_backup_etc_gshadow", - "remarks": "rule_set_252" + "remarks": "rule_set_270" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns Backup gshadow File", - "remarks": "rule_set_252" + "remarks": "rule_set_270" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_backup_etc_gshadow", - "remarks": "rule_set_252" + "remarks": "rule_set_270" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns Backup gshadow File", - "remarks": "rule_set_252" + "remarks": "rule_set_270" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_backup_etc_gshadow", - "remarks": "rule_set_253" + "remarks": "rule_set_271" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns Backup gshadow File", - "remarks": "rule_set_253" + "remarks": "rule_set_271" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_backup_etc_gshadow", - "remarks": "rule_set_253" + "remarks": "rule_set_271" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns Backup gshadow File", - "remarks": "rule_set_253" + "remarks": "rule_set_271" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_backup_etc_gshadow", - "remarks": "rule_set_254" + "remarks": "rule_set_272" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on Backup gshadow File", - "remarks": "rule_set_254" + "remarks": "rule_set_272" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_backup_etc_gshadow", - "remarks": "rule_set_254" + "remarks": "rule_set_272" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on Backup gshadow File", - "remarks": "rule_set_254" + "remarks": "rule_set_272" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_shells", - "remarks": "rule_set_255" + "remarks": "rule_set_273" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns /etc/shells File", - "remarks": "rule_set_255" + "remarks": "rule_set_273" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_shells", - "remarks": "rule_set_255" + "remarks": "rule_set_273" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns /etc/shells File", - "remarks": "rule_set_255" + "remarks": "rule_set_273" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_shells", - "remarks": "rule_set_256" + "remarks": "rule_set_274" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Who Owns /etc/shells File", - "remarks": "rule_set_256" + "remarks": "rule_set_274" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_shells", - "remarks": "rule_set_256" + "remarks": "rule_set_274" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Who Owns /etc/shells File", - "remarks": "rule_set_256" + "remarks": "rule_set_274" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_shells", - "remarks": "rule_set_257" + "remarks": "rule_set_275" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on /etc/shells File", - "remarks": "rule_set_257" + "remarks": "rule_set_275" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_shells", - "remarks": "rule_set_257" + "remarks": "rule_set_275" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on /etc/shells File", - "remarks": "rule_set_257" + "remarks": "rule_set_275" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_etc_security_opasswd", - "remarks": "rule_set_258" + "remarks": "rule_set_276" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions and Ownership of Old Passwords File", - "remarks": "rule_set_258" + "remarks": "rule_set_276" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_etc_security_opasswd", - "remarks": "rule_set_258" + "remarks": "rule_set_276" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions and Ownership of Old Passwords File", - "remarks": "rule_set_258" + "remarks": "rule_set_276" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_unauthorized_world_writable", - "remarks": "rule_set_259" + "remarks": "rule_set_277" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure No World-Writable Files Exist", - "remarks": "rule_set_259" + "remarks": "rule_set_277" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_unauthorized_world_writable", - "remarks": "rule_set_259" + "remarks": "rule_set_277" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure No World-Writable Files Exist", - "remarks": "rule_set_259" + "remarks": "rule_set_277" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dir_perms_world_writable_sticky_bits", - "remarks": "rule_set_260" + "remarks": "rule_set_278" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify that All World-Writable Directories Have Sticky Bits Set", - "remarks": "rule_set_260" + "remarks": "rule_set_278" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dir_perms_world_writable_sticky_bits", - "remarks": "rule_set_260" + "remarks": "rule_set_278" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify that All World-Writable Directories Have Sticky Bits Set", - "remarks": "rule_set_260" + "remarks": "rule_set_278" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_files_unowned_by_user", - "remarks": "rule_set_261" + "remarks": "rule_set_279" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Files Are Owned by a User", - "remarks": "rule_set_261" + "remarks": "rule_set_279" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_files_unowned_by_user", - "remarks": "rule_set_261" + "remarks": "rule_set_279" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Files Are Owned by a User", - "remarks": "rule_set_261" + "remarks": "rule_set_279" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_ungroupowned", - "remarks": "rule_set_262" + "remarks": "rule_set_280" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Files Are Owned by a Group", - "remarks": "rule_set_262" + "remarks": "rule_set_280" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_ungroupowned", - "remarks": "rule_set_262" + "remarks": "rule_set_280" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Files Are Owned by a Group", - "remarks": "rule_set_262" + "remarks": "rule_set_280" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_all_shadowed", - "remarks": "rule_set_263" + "remarks": "rule_set_281" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify All Account Password Hashes are Shadowed", - "remarks": "rule_set_263" + "remarks": "rule_set_281" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_all_shadowed", - "remarks": "rule_set_263" + "remarks": "rule_set_281" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify All Account Password Hashes are Shadowed", - "remarks": "rule_set_263" + "remarks": "rule_set_281" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_empty_passwords_etc_shadow", - "remarks": "rule_set_264" + "remarks": "rule_set_282" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure There Are No Accounts With Blank or Null Passwords", - "remarks": "rule_set_264" + "remarks": "rule_set_282" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_empty_passwords_etc_shadow", - "remarks": "rule_set_264" + "remarks": "rule_set_282" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure There Are No Accounts With Blank or Null Passwords", - "remarks": "rule_set_264" + "remarks": "rule_set_282" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "gid_passwd_group_same", - "remarks": "rule_set_265" + "remarks": "rule_set_283" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "All GIDs referenced in /etc/passwd must be defined in /etc/group", - "remarks": "rule_set_265" + "remarks": "rule_set_283" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "gid_passwd_group_same", - "remarks": "rule_set_265" + "remarks": "rule_set_283" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "All GIDs referenced in /etc/passwd must be defined in /etc/group", - "remarks": "rule_set_265" + "remarks": "rule_set_283" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "account_unique_id", - "remarks": "rule_set_266" + "remarks": "rule_set_284" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Accounts on the System Have Unique User IDs", - "remarks": "rule_set_266" + "remarks": "rule_set_284" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "account_unique_id", - "remarks": "rule_set_266" + "remarks": "rule_set_284" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Accounts on the System Have Unique User IDs", - "remarks": "rule_set_266" + "remarks": "rule_set_284" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "group_unique_id", - "remarks": "rule_set_267" + "remarks": "rule_set_285" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Groups on the System Have Unique Group ID", - "remarks": "rule_set_267" + "remarks": "rule_set_285" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "group_unique_id", - "remarks": "rule_set_267" + "remarks": "rule_set_285" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Groups on the System Have Unique Group ID", - "remarks": "rule_set_267" + "remarks": "rule_set_285" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "account_unique_name", - "remarks": "rule_set_268" + "remarks": "rule_set_286" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Accounts on the System Have Unique Names", - "remarks": "rule_set_268" + "remarks": "rule_set_286" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "account_unique_name", - "remarks": "rule_set_268" + "remarks": "rule_set_286" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Accounts on the System Have Unique Names", - "remarks": "rule_set_268" + "remarks": "rule_set_286" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "group_unique_name", - "remarks": "rule_set_269" + "remarks": "rule_set_287" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Groups on the System Have Unique Group Names", - "remarks": "rule_set_269" + "remarks": "rule_set_287" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "group_unique_name", - "remarks": "rule_set_269" + "remarks": "rule_set_287" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Groups on the System Have Unique Group Names", - "remarks": "rule_set_269" + "remarks": "rule_set_287" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_user_interactive_home_directory_exists", - "remarks": "rule_set_270" + "remarks": "rule_set_288" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "All Interactive Users Home Directories Must Exist", - "remarks": "rule_set_270" + "remarks": "rule_set_288" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_user_interactive_home_directory_exists", - "remarks": "rule_set_270" + "remarks": "rule_set_288" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "All Interactive Users Home Directories Must Exist", - "remarks": "rule_set_270" + "remarks": "rule_set_288" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_ownership_home_directories", - "remarks": "rule_set_271" + "remarks": "rule_set_289" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "All Interactive User Home Directories Must Be Owned By The Primary User", - "remarks": "rule_set_271" + "remarks": "rule_set_289" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_ownership_home_directories", - "remarks": "rule_set_271" + "remarks": "rule_set_289" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "All Interactive User Home Directories Must Be Owned By The Primary User", - "remarks": "rule_set_271" + "remarks": "rule_set_289" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_home_directories", - "remarks": "rule_set_272" + "remarks": "rule_set_290" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "All Interactive User Home Directories Must Have mode 0750 Or Less Permissive", - "remarks": "rule_set_272" + "remarks": "rule_set_290" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_home_directories", - "remarks": "rule_set_272" + "remarks": "rule_set_290" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "All Interactive User Home Directories Must Have mode 0750 Or Less Permissive", - "remarks": "rule_set_272" + "remarks": "rule_set_290" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_user_dot_group_ownership", - "remarks": "rule_set_273" + "remarks": "rule_set_291" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "User Initialization Files Must Be Group-Owned By The Primary Group", - "remarks": "rule_set_273" + "remarks": "rule_set_291" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_user_dot_group_ownership", - "remarks": "rule_set_273" + "remarks": "rule_set_291" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "User Initialization Files Must Be Group-Owned By The Primary Group", - "remarks": "rule_set_273" + "remarks": "rule_set_291" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_user_dot_user_ownership", - "remarks": "rule_set_274" + "remarks": "rule_set_292" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "User Initialization Files Must Be Owned By the Primary User", - "remarks": "rule_set_274" + "remarks": "rule_set_292" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_user_dot_user_ownership", - "remarks": "rule_set_274" + "remarks": "rule_set_292" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "User Initialization Files Must Be Owned By the Primary User", - "remarks": "rule_set_274" + "remarks": "rule_set_292" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_user_dot_no_world_writable_programs", - "remarks": "rule_set_275" + "remarks": "rule_set_293" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "User Initialization Files Must Not Run World-Writable Programs", - "remarks": "rule_set_275" + "remarks": "rule_set_293" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_user_dot_no_world_writable_programs", - "remarks": "rule_set_275" + "remarks": "rule_set_293" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "User Initialization Files Must Not Run World-Writable Programs", - "remarks": "rule_set_275" + "remarks": "rule_set_293" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permission_user_init_files", - "remarks": "rule_set_276" + "remarks": "rule_set_294" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All User Initialization Files Have Mode 0740 Or Less Permissive", - "remarks": "rule_set_276" + "remarks": "rule_set_294" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permission_user_init_files", - "remarks": "rule_set_276" + "remarks": "rule_set_294" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All User Initialization Files Have Mode 0740 Or Less Permissive", - "remarks": "rule_set_276" + "remarks": "rule_set_294" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_forward_files", - "remarks": "rule_set_277" + "remarks": "rule_set_295" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify No .forward Files Exist", - "remarks": "rule_set_277" + "remarks": "rule_set_295" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_forward_files", - "remarks": "rule_set_277" + "remarks": "rule_set_295" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify No .forward Files Exist", - "remarks": "rule_set_277" + "remarks": "rule_set_295" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_netrc_files", - "remarks": "rule_set_278" + "remarks": "rule_set_296" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify No netrc Files Exist", - "remarks": "rule_set_278" + "remarks": "rule_set_296" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_netrc_files", - "remarks": "rule_set_278" + "remarks": "rule_set_296" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify No netrc Files Exist", - "remarks": "rule_set_278" + "remarks": "rule_set_296" } ], "control-implementations": [ { - "uuid": "5b0ee555-ff6d-42b1-ba3a-a64b870cc1de", + "uuid": "66b6774b-0822-4bb1-9ec5-b605fb6823b8", "source": "trestle://profiles/rhel10-cis_rhel10-l1_server/profile.json", "description": "REPLACE_ME", "props": [ { "name": "Framework_Short_Name", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal", - "value": "cis_server_l1" - } - ], - "set-parameters": [ - { - "param-id": "cis_banner_text", - "values": [ - "cis" - ] - }, - { - "param-id": "inactivity_timeout_value", - "values": [ - "15_minutes" - ] - }, - { - "param-id": "login_banner_text", - "values": [ - "cis_banners" - ] - }, - { - "param-id": "sshd_idle_timeout_value", - "values": [ - "5_minutes" - ] - }, - { - "param-id": "sshd_max_auth_tries_value", - "values": [ - "4" - ] - }, - { - "param-id": "sshd_strong_kex", - "values": [ - "cis_rhel8" - ] - }, - { - "param-id": "sshd_strong_macs", - "values": [ - "cis_rhel8" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_all_accept_redirects_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_all_accept_source_route_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_all_log_martians_value", - "values": [ - "enabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_all_rp_filter_value", - "values": [ - "enabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_all_secure_redirects_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_default_accept_redirects_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_default_accept_source_route_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_default_log_martians_value", - "values": [ - "enabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_default_rp_filter_value", - "values": [ - "enabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_default_secure_redirects_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts_value", - "values": [ - "enabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses_value", - "values": [ - "enabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_tcp_syncookies_value", - "values": [ - "enabled" - ] - }, - { - "param-id": "sysctl_net_ipv6_conf_all_accept_ra_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv6_conf_all_accept_redirects_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv6_conf_all_accept_source_route_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv6_conf_all_forwarding_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv6_conf_default_accept_ra_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv6_conf_default_accept_redirects_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv6_conf_default_accept_source_route_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "var_account_disable_post_pw_expiration", - "values": [ - "30" - ] - }, - { - "param-id": "var_accounts_maximum_age_login_defs", - "values": [ - "365" - ] - }, - { - "param-id": "var_accounts_password_warn_age_login_defs", - "values": [ - "7" - ] - }, - { - "param-id": "var_accounts_passwords_pam_faillock_deny", - "values": [ - "5" - ] - }, - { - "param-id": "var_accounts_passwords_pam_faillock_unlock_time", - "values": [ - "900" - ] - }, - { - "param-id": "var_accounts_tmout", - "values": [ - "15_min" - ] - }, - { - "param-id": "var_accounts_user_umask", - "values": [ - "027" - ] - }, - { - "param-id": "var_authselect_profile", - "values": [ - "local" - ] - }, - { - "param-id": "var_multiple_time_servers", - "values": [ - "rhel" - ] - }, - { - "param-id": "var_pam_wheel_group_for_su", - "values": [ - "cis" - ] - }, - { - "param-id": "var_password_hashing_algorithm", - "values": [ - "yescrypt" - ] - }, + "value": "cis_server_l1" + } + ], + "set-parameters": [ { - "param-id": "var_password_hashing_algorithm_pam", + "param-id": "cis_banner_text", "values": [ - "yescrypt" + "cis" ] }, { - "param-id": "var_password_pam_dictcheck", + "param-id": "inactivity_timeout_value", "values": [ - "1" + "15_minutes" ] }, { - "param-id": "var_password_pam_difok", + "param-id": "login_banner_text", "values": [ - "2" + "cis_banners" ] }, { - "param-id": "var_password_pam_maxrepeat", + "param-id": "sshd_idle_timeout_value", "values": [ - "3" + "5_minutes" ] }, { - "param-id": "var_password_pam_minclass", + "param-id": "sshd_max_auth_tries_value", "values": [ "4" ] }, { - "param-id": "var_password_pam_minlen", + "param-id": "sshd_strong_kex", "values": [ - "14" + "cis_rhel10" ] }, { - "param-id": "var_password_pam_remember", + "param-id": "sshd_strong_macs", "values": [ - "24" + "cis_rhel10" ] }, { - "param-id": "var_password_pam_remember_control_flag", + "param-id": "sysctl_net_ipv4_conf_all_accept_redirects_value", "values": [ - "requisite_or_required" + "disabled" ] }, { - "param-id": "var_postfix_inet_interfaces", + "param-id": "sysctl_net_ipv4_conf_all_accept_source_route_value", "values": [ - "loopback-only" + "disabled" ] }, { - "param-id": "var_screensaver_lock_delay", + "param-id": "sysctl_net_ipv4_conf_all_log_martians_value", "values": [ - "5_seconds" + "enabled" ] }, { - "param-id": "var_selinux_policy_name", + "param-id": "sysctl_net_ipv4_conf_all_rp_filter_value", "values": [ - "targeted" + "enabled" ] }, { - "param-id": "var_sshd_max_sessions", + "param-id": "sysctl_net_ipv4_conf_all_secure_redirects_value", "values": [ - "10" + "disabled" ] }, { - "param-id": "var_sshd_set_keepalive", + "param-id": "sysctl_net_ipv4_conf_default_accept_redirects_value", "values": [ - "1" + "disabled" ] }, { - "param-id": "var_sshd_set_login_grace_time", + "param-id": "sysctl_net_ipv4_conf_default_accept_source_route_value", "values": [ - "60" + "disabled" ] }, { - "param-id": "var_sshd_set_maxstartups", + "param-id": "sysctl_net_ipv4_conf_default_log_martians_value", "values": [ - "10:30:60" + "enabled" ] }, { - "param-id": "var_system_crypto_policy", + "param-id": "sysctl_net_ipv4_conf_default_rp_filter_value", "values": [ - "default_policy" + "enabled" ] }, { - "param-id": "var_user_initialization_files_regex", + "param-id": "sysctl_net_ipv4_conf_default_secure_redirects_value", "values": [ - "all_dotfiles" - ] - } - ], - "implemented-requirements": [ - { - "uuid": "40c019d4-1bcc-4ee2-b21a-9280715cffda", - "control-id": "reload_dconf_db", - "description": "This is a helper rule to reload Dconf database correctly.", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_db_up_to_date" - } - ] - }, - { - "uuid": "84fe640c-c95c-4db8-a500-e8ff3016dd0b", - "control-id": "cis_rhel10_1-1.1.8", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_usb-storage_disabled" - } - ] - }, - { - "uuid": "17debc34-4faf-4d6b-84cc-2493066012f9", - "control-id": "cis_rhel10_1-1.1.9", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } - ] - }, - { - "uuid": "127ab9a3-d960-4680-85d9-4783c2ed567b", - "control-id": "cis_rhel10_1-1.2.1.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_tmp" - } - ] - }, - { - "uuid": "3e186959-48e0-4c4b-b71c-79e4aae405e6", - "control-id": "cis_rhel10_1-1.2.1.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_nodev" - } - ] - }, - { - "uuid": "5a43e81e-d1df-421e-8b2b-07bd6146940d", - "control-id": "cis_rhel10_1-1.2.1.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_nosuid" - } - ] - }, - { - "uuid": "cbd136ad-8eb2-4ca5-9c90-35610aeed547", - "control-id": "cis_rhel10_1-1.2.1.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_noexec" - } + "disabled" ] }, { - "uuid": "f934af66-9780-47d7-b57a-cbebd3003a20", - "control-id": "cis_rhel10_1-1.2.2.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_dev_shm" - } + "param-id": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts_value", + "values": [ + "enabled" ] }, { - "uuid": "80f9b787-b0b3-4e64-9e91-6cd6c485202d", - "control-id": "cis_rhel10_1-1.2.2.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_nodev" - } + "param-id": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses_value", + "values": [ + "enabled" ] }, { - "uuid": "019704b2-1b2b-485a-a9e6-adcac099c560", - "control-id": "cis_rhel10_1-1.2.2.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_nosuid" - } + "param-id": "sysctl_net_ipv4_tcp_syncookies_value", + "values": [ + "enabled" ] }, { - "uuid": "2737164e-e8df-41b6-ba25-4f0c6ed29b63", - "control-id": "cis_rhel10_1-1.2.2.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_noexec" - } + "param-id": "sysctl_net_ipv6_conf_all_accept_ra_value", + "values": [ + "disabled" ] }, { - "uuid": "8b82a22d-3955-40c6-bfc1-c848e11ece3c", - "control-id": "cis_rhel10_1-1.2.3.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_home_nodev" - } + "param-id": "sysctl_net_ipv6_conf_all_accept_redirects_value", + "values": [ + "disabled" ] }, { - "uuid": "6688509c-e66d-4724-b179-df8294ee7a70", - "control-id": "cis_rhel10_1-1.2.3.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_home_nosuid" - } + "param-id": "sysctl_net_ipv6_conf_all_accept_source_route_value", + "values": [ + "disabled" ] }, { - "uuid": "2116f44c-af76-4b0a-ae96-05e936191a11", - "control-id": "cis_rhel10_1-1.2.4.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_nodev" - } + "param-id": "sysctl_net_ipv6_conf_all_forwarding_value", + "values": [ + "disabled" ] }, { - "uuid": "c593a188-b24b-43a8-acbd-fd6c90283632", - "control-id": "cis_rhel10_1-1.2.4.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_nosuid" - } + "param-id": "sysctl_net_ipv6_conf_default_accept_ra_value", + "values": [ + "disabled" ] }, { - "uuid": "1dae033f-9b67-494f-8dde-b26c28c0f402", - "control-id": "cis_rhel10_1-1.2.5.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_tmp_nodev" - } + "param-id": "sysctl_net_ipv6_conf_default_accept_redirects_value", + "values": [ + "disabled" ] }, { - "uuid": "f3cfb42c-5cbb-4720-a62d-74916d752c2d", - "control-id": "cis_rhel10_1-1.2.5.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_tmp_nosuid" - } + "param-id": "sysctl_net_ipv6_conf_default_accept_source_route_value", + "values": [ + "disabled" ] }, { - "uuid": "7985c16b-c4eb-469b-a226-78d8855791bd", - "control-id": "cis_rhel10_1-1.2.5.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_tmp_noexec" - } + "param-id": "sysctl_net_ipv6_conf_default_forwarding_value", + "values": [ + "disabled" ] }, { - "uuid": "9aeb6f51-61d9-45b4-8bb0-b43f03f51369", - "control-id": "cis_rhel10_1-1.2.6.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_nodev" - } + "param-id": "var_account_disable_post_pw_expiration", + "values": [ + "30" ] }, { - "uuid": "3e9ca51f-088f-45ab-93d4-92f653b099c7", - "control-id": "cis_rhel10_1-1.2.6.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_nosuid" - } + "param-id": "var_accounts_maximum_age_login_defs", + "values": [ + "365" ] }, { - "uuid": "6a26792e-20f9-4cdb-9a1a-58927f3d6a8e", - "control-id": "cis_rhel10_1-1.2.6.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_noexec" - } + "param-id": "var_accounts_password_warn_age_login_defs", + "values": [ + "7" ] }, { - "uuid": "3a057485-2ba5-431d-a86a-9a35bf20298c", - "control-id": "cis_rhel10_1-1.2.7.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_audit_nodev" - } + "param-id": "var_accounts_passwords_pam_faillock_deny", + "values": [ + "5" ] }, { - "uuid": "773dd945-3d83-40c5-8416-2ed9cc14799e", - "control-id": "cis_rhel10_1-1.2.7.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_audit_nosuid" - } + "param-id": "var_accounts_passwords_pam_faillock_unlock_time", + "values": [ + "900" ] }, { - "uuid": "33d62256-332b-4efd-b784-3292d68653e9", - "control-id": "cis_rhel10_1-1.2.7.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_audit_noexec" - } + "param-id": "var_accounts_tmout", + "values": [ + "15_min" ] }, { - "uuid": "dab76520-3d6e-4857-8d9b-78143cd2a9c7", - "control-id": "cis_rhel10_1-2.1.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } + "param-id": "var_accounts_user_umask", + "values": [ + "027" ] }, { - "uuid": "150cc78a-04d3-4a92-9b02-b0ca1ac46031", - "control-id": "cis_rhel10_1-2.1.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_gpgcheck_globally_activated" - } + "param-id": "var_authselect_profile", + "values": [ + "local" ] }, { - "uuid": "c464decf-4afb-41b9-8b81-e658d0f2f678", - "control-id": "cis_rhel10_1-2.1.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } + "param-id": "var_multiple_time_servers", + "values": [ + "rhel" ] }, { - "uuid": "41e943e9-2a20-4e07-aaea-621ebd3ab56e", - "control-id": "cis_rhel10_1-2.2.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } + "param-id": "var_pam_wheel_group_for_su", + "values": [ + "cis" ] }, { - "uuid": "21d641a7-c262-42d0-828b-0345ccacaa56", - "control-id": "cis_rhel10_1-3.1.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_libselinux_installed" - } + "param-id": "var_password_hashing_algorithm", + "values": [ + "yescrypt" ] }, { - "uuid": "bfbb0c60-b09c-4ea8-83c9-3563d469c928", - "control-id": "cis_rhel10_1-3.1.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "grub2_enable_selinux" - } + "param-id": "var_password_hashing_algorithm_pam", + "values": [ + "yescrypt" ] }, { - "uuid": "8b4077a6-8263-45d2-aac8-e3955038996e", - "control-id": "cis_rhel10_1-3.1.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "selinux_policytype" - } + "param-id": "var_password_pam_dictcheck", + "values": [ + "1" ] }, { - "uuid": "c4893c28-4133-4b3f-a352-38d8592ecf3a", - "control-id": "cis_rhel10_1-3.1.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "selinux_not_disabled" - } + "param-id": "var_password_pam_difok", + "values": [ + "2" ] }, { - "uuid": "58fd86dd-ee43-4634-a322-ed49a825085c", - "control-id": "cis_rhel10_1-3.1.7", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_mcstrans_removed" - } + "param-id": "var_password_pam_maxrepeat", + "values": [ + "3" ] }, { - "uuid": "b4a4ca25-1e32-4d21-849d-6edf0e6cd1bb", - "control-id": "cis_rhel10_1-3.1.8", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_setroubleshoot_removed" - } + "param-id": "var_password_pam_minclass", + "values": [ + "4" ] }, { - "uuid": "67c12246-4903-4c90-a5cc-7c51fc72a8f2", - "control-id": "cis_rhel10_1-4.1", - "description": "There is no automated remediation for this rule and this is intentional.\nMore details in the rule description.", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "grub2_password" - } + "param-id": "var_password_pam_minlen", + "values": [ + "14" ] }, { - "uuid": "59ce353a-81b5-4ffd-836e-126a07bd4c81", - "control-id": "cis_rhel10_1-4.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "This requirement demands a deeper review of the rules." - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_grub2_cfg" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_grub2_cfg" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_grub2_cfg" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_user_cfg" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_user_cfg" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_user_cfg" - } + "param-id": "var_password_pam_remember", + "values": [ + "24" ] }, { - "uuid": "a96085f4-0d5f-4ea0-86fa-76cf9c116253", - "control-id": "cis_rhel10_1-5.1", - "description": "Address Space Layout Randomization (ASLR)", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_kernel_randomize_va_space" - } + "param-id": "var_password_pam_remember_control_flag", + "values": [ + "requisite_or_required" ] }, { - "uuid": "90648e10-dfb7-415f-98a0-d6ba53a5b713", - "control-id": "cis_rhel10_1-5.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_kernel_yama_ptrace_scope" - } + "param-id": "var_postfix_inet_interfaces", + "values": [ + "loopback-only" ] }, { - "uuid": "9ebed584-57e4-478d-99a4-07eb6a546001", - "control-id": "cis_rhel10_1-5.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_backtraces" - } + "param-id": "var_screensaver_lock_delay", + "values": [ + "5_seconds" ] }, { - "uuid": "dce47db7-de14-42a4-a72a-666515d84a5c", - "control-id": "cis_rhel10_1-5.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_storage" - } + "param-id": "var_selinux_policy_name", + "values": [ + "targeted" ] }, { - "uuid": "e8f2118b-3a20-4423-b3ad-019c98b72b04", - "control-id": "cis_rhel10_1-6.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_crypto_policy" - } + "param-id": "var_sshd_max_sessions", + "values": [ + "10" ] }, { - "uuid": "2c2aab38-bb50-4afe-8bc3-044e8b82c8d1", - "control-id": "cis_rhel10_1-6.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_ssh_crypto_policy" - } + "param-id": "var_sshd_set_keepalive", + "values": [ + "1" ] }, { - "uuid": "0bfa2dcf-8de3-4583-b82f-e696187448da", - "control-id": "cis_rhel10_1-6.3", - "description": "This requirement is already satisfied by 1.6.1.", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - } + "param-id": "var_sshd_set_login_grace_time", + "values": [ + "60" ] }, { - "uuid": "e4d86d9c-757d-4bb6-a2a5-82595e0d8349", - "control-id": "cis_rhel10_1-6.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary a new rule to ensure a module disabling weak MACs in\n/etc/crypto-policies/policies/modules/ so it can be used by update-crypto-policies command." - } + "param-id": "var_sshd_set_maxstartups", + "values": [ + "10:30:60" + ] + }, + { + "param-id": "var_system_crypto_policy", + "values": [ + "default_policy" ] }, { - "uuid": "49c9b5c3-aad7-4d7d-8de2-7f57390e7382", - "control-id": "cis_rhel10_1-6.5", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary a new rule to ensure a module disabling CBC in\n/etc/crypto-policies/policies/modules/ so it can be used by update-crypto-policies command." - } + "param-id": "var_user_initialization_files_regex", + "values": [ + "all_dotfiles" ] - }, + } + ], + "implemented-requirements": [ { - "uuid": "75ac5832-733e-481a-894c-dece7ee67336", - "control-id": "cis_rhel10_1-6.6", - "description": "REPLACE_ME", + "uuid": "d49ff82c-48b3-4241-a803-5da974aa4e57", + "control-id": "reload_dconf_db", + "description": "This is a helper rule to reload Dconf database correctly.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "dconf_db_up_to_date" } ] }, { - "uuid": "0c11c8e5-34c1-4f94-b551-baed72862e32", - "control-id": "cis_rhel10_1-6.7", + "uuid": "807f7841-4b17-43db-8e09-08eadb1aec3f", + "control-id": "cis_rhel10_1-1.1.9", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "kernel_module_firewire-core_disabled" } ] }, { - "uuid": "49efa7d9-a40e-4a2c-a494-06fa3b0f56c1", - "control-id": "cis_rhel10_1-7.1", + "uuid": "8e6b19f7-388c-408b-a5d8-8e81ddd406be", + "control-id": "cis_rhel10_1-1.2.1.1", "description": "REPLACE_ME", "props": [ { @@ -17751,13 +16792,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "banner_etc_motd_cis" + "value": "partition_for_tmp" } ] }, { - "uuid": "bff0d594-4a6f-4257-a793-1f7f7cf6613c", - "control-id": "cis_rhel10_1-7.2", + "uuid": "d0fea3cc-fcd5-423b-88ae-dc761ec55dcb", + "control-id": "cis_rhel10_1-1.2.1.2", "description": "REPLACE_ME", "props": [ { @@ -17768,13 +16809,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "banner_etc_issue_cis" + "value": "mount_option_tmp_nodev" } ] }, { - "uuid": "08de82b1-a730-4824-9c45-756a8453cda2", - "control-id": "cis_rhel10_1-7.3", + "uuid": "f00b74e3-7a67-4b77-9923-66e9a58c13be", + "control-id": "cis_rhel10_1-1.2.1.3", "description": "REPLACE_ME", "props": [ { @@ -17785,13 +16826,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "banner_etc_issue_net_cis" + "value": "mount_option_tmp_nosuid" } ] }, { - "uuid": "03a80c0e-b092-4c33-89dd-0096142fd056", - "control-id": "cis_rhel10_1-7.4", + "uuid": "62f267a3-0c5c-4c4a-a3e6-0da30ed0abae", + "control-id": "cis_rhel10_1-1.2.1.4", "description": "REPLACE_ME", "props": [ { @@ -17802,23 +16843,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_motd" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_motd" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_motd" + "value": "mount_option_tmp_noexec" } ] }, { - "uuid": "eaa5c9ca-46c0-46ec-8b4e-3fd870841c03", - "control-id": "cis_rhel10_1-7.5", + "uuid": "a9d72383-d814-466e-83ec-23f00c527228", + "control-id": "cis_rhel10_1-1.2.2.1", "description": "REPLACE_ME", "props": [ { @@ -17829,23 +16860,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_issue" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_issue" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_issue" + "value": "partition_for_dev_shm" } ] }, { - "uuid": "11d2bf62-1c4c-4fc6-af77-02f2a6491b2b", - "control-id": "cis_rhel10_1-7.6", + "uuid": "917459b0-0468-4dd7-a8fc-0214c59e3d85", + "control-id": "cis_rhel10_1-1.2.2.2", "description": "REPLACE_ME", "props": [ { @@ -17856,23 +16877,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_issue_net" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_issue_net" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_issue_net" + "value": "mount_option_dev_shm_nodev" } ] }, { - "uuid": "538a4894-f57e-474f-97dc-74d4c1a8f3e5", - "control-id": "cis_rhel10_1-8.2", + "uuid": "014da8d9-d11a-4d79-b78f-e3e7ee01a65c", + "control-id": "cis_rhel10_1-1.2.2.3", "description": "REPLACE_ME", "props": [ { @@ -17883,18 +16894,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_banner_enabled" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_login_banner_text" + "value": "mount_option_dev_shm_nosuid" } ] }, { - "uuid": "6ebe0f9d-3403-426c-8896-02b635e5f052", - "control-id": "cis_rhel10_1-8.3", + "uuid": "dcb90ff7-f17e-419c-abf8-2d014991d98a", + "control-id": "cis_rhel10_1-1.2.2.4", "description": "REPLACE_ME", "props": [ { @@ -17905,13 +16911,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_user_list" + "value": "mount_option_dev_shm_noexec" } ] }, { - "uuid": "15dde926-da8d-4efa-b119-437f5fe6d00f", - "control-id": "cis_rhel10_1-8.4", + "uuid": "c674344d-ff6d-4354-a6bc-908b45f4f89f", + "control-id": "cis_rhel10_1-1.2.3.2", "description": "REPLACE_ME", "props": [ { @@ -17922,18 +16928,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_screensaver_idle_delay" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_screensaver_lock_delay" + "value": "mount_option_home_nodev" } ] }, { - "uuid": "51a1a97d-2b74-408b-9ea5-68771c4c99fc", - "control-id": "cis_rhel10_1-8.5", + "uuid": "8415a561-dc1e-4069-9134-aecc283167ef", + "control-id": "cis_rhel10_1-1.2.3.3", "description": "REPLACE_ME", "props": [ { @@ -17944,18 +16945,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_session_idle_user_locks" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_screensaver_user_locks" + "value": "mount_option_home_nosuid" } ] }, { - "uuid": "6828347d-3697-407d-a685-b71591bfb26a", - "control-id": "cis_rhel10_1-8.6", + "uuid": "994265d0-cb11-4c42-9ca1-abf401d87873", + "control-id": "cis_rhel10_1-1.2.4.2", "description": "REPLACE_ME", "props": [ { @@ -17966,18 +16962,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_automount" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_automount_open" + "value": "mount_option_var_nodev" } ] }, { - "uuid": "17c4c06e-4006-4dc9-9323-197b5b8e0058", - "control-id": "cis_rhel10_1-8.7", + "uuid": "0de71f30-93d4-4df7-a6ad-83caebbc36e7", + "control-id": "cis_rhel10_1-1.2.4.3", "description": "REPLACE_ME", "props": [ { @@ -17988,18 +16979,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_automount" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_automount_open" + "value": "mount_option_var_nosuid" } ] }, { - "uuid": "dbefea9f-aa46-4dba-a5e0-b604efd9800c", - "control-id": "cis_rhel10_1-8.8", + "uuid": "ef701366-3966-4d7d-b490-44bb8b8cc1e3", + "control-id": "cis_rhel10_1-1.2.5.2", "description": "REPLACE_ME", "props": [ { @@ -18010,13 +16996,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_autorun" + "value": "mount_option_var_tmp_nodev" } ] }, { - "uuid": "ee9080ac-82f2-4d03-8aa2-22388bfb6f54", - "control-id": "cis_rhel10_1-8.9", + "uuid": "78cb3fb0-a0cf-4638-85ce-6d0b3b88d867", + "control-id": "cis_rhel10_1-1.2.5.3", "description": "REPLACE_ME", "props": [ { @@ -18027,25 +17013,30 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_autorun" + "value": "mount_option_var_tmp_nosuid" } ] }, { - "uuid": "9fe438da-281c-4760-aa26-2f0d25522768", - "control-id": "cis_rhel10_1-8.10", - "description": "This was inherited from the RHEL 9 profile.\nHowever, it was reported that XDMCP is no\nlonger in RHEL 10.", + "uuid": "56da6a1b-7603-4a94-9b9e-200f461d2822", + "control-id": "cis_rhel10_1-1.2.5.4", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "mount_option_var_tmp_noexec" } ] }, { - "uuid": "da5c7c50-314c-4aa1-8c27-2fb9023837e0", - "control-id": "cis_rhel10_2-1.1", + "uuid": "0cc9a10c-8185-44bf-b1a2-9d2bbd5dac10", + "control-id": "cis_rhel10_1-1.2.6.2", "description": "REPLACE_ME", "props": [ { @@ -18056,13 +17047,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_autofs_disabled" + "value": "mount_option_var_log_nodev" } ] }, { - "uuid": "a78c92f8-f8eb-45d5-a899-c210e3072c9e", - "control-id": "cis_rhel10_2-1.2", + "uuid": "c6b6b323-72bf-4b3b-9e1b-59d31eeb049f", + "control-id": "cis_rhel10_1-1.2.6.3", "description": "REPLACE_ME", "props": [ { @@ -18073,13 +17064,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_avahi-daemon_disabled" + "value": "mount_option_var_log_nosuid" } ] }, { - "uuid": "d66d6193-1f2a-42ca-b779-c2ea8864e06b", - "control-id": "cis_rhel10_2-1.3", + "uuid": "c324ea19-28a9-403e-9494-85b2993ef2e2", + "control-id": "cis_rhel10_1-1.2.6.4", "description": "REPLACE_ME", "props": [ { @@ -18090,13 +17081,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_kea_removed" + "value": "mount_option_var_log_noexec" } ] }, { - "uuid": "2fa891c8-0c31-4d94-9b78-41c5c03cbf72", - "control-id": "cis_rhel10_2-1.4", + "uuid": "8e4e0f05-478c-41f4-a45d-9ad642af4813", + "control-id": "cis_rhel10_1-1.2.7.2", "description": "REPLACE_ME", "props": [ { @@ -18107,13 +17098,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_bind_removed" + "value": "mount_option_var_log_audit_nodev" } ] }, { - "uuid": "3689c696-4c94-45be-b1f6-da89f95910aa", - "control-id": "cis_rhel10_2-1.5", + "uuid": "ae042233-2206-44e0-bb2d-40517c0aba49", + "control-id": "cis_rhel10_1-1.2.7.3", "description": "REPLACE_ME", "props": [ { @@ -18124,13 +17115,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_dnsmasq_removed" + "value": "mount_option_var_log_audit_nosuid" } ] }, { - "uuid": "b2a69b84-9f77-44f3-acbb-f88bd9429467", - "control-id": "cis_rhel10_2-1.6", + "uuid": "496e1a4a-748f-4943-b2a6-7b3e595c4e70", + "control-id": "cis_rhel10_1-1.2.7.4", "description": "REPLACE_ME", "props": [ { @@ -18141,30 +17132,26 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_samba_removed" + "value": "mount_option_var_log_audit_noexec" } ] }, { - "uuid": "7cc97bd9-1c9a-4312-991b-4267cc980cc5", - "control-id": "cis_rhel10_2-1.7", + "uuid": "54ea1bc8-426f-4556-bfcd-3fe9fa1a752b", + "control-id": "cis_rhel10_1-2.1.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_vsftpd_removed" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "53899c67-9c4c-41e8-ab94-9700d6235daf", - "control-id": "cis_rhel10_2-1.8", + "uuid": "b6e67b85-66ba-4f45-8e62-7f7cab10d58d", + "control-id": "cis_rhel10_1-2.1.2", "description": "REPLACE_ME", "props": [ { @@ -18175,47 +17162,39 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_dovecot_removed" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_cyrus-imapd_removed" + "value": "ensure_gpgcheck_globally_activated" } ] }, { - "uuid": "f0215f38-fac2-4163-9e82-1ba5cececd43", - "control-id": "cis_rhel10_2-1.9", - "description": "Many of the libvirt packages used by Enterprise Linux virtualization are dependent on the\nnfs-utils package.", + "uuid": "24d59bb4-dbcc-4228-b782-de14d5bbfaa1", + "control-id": "cis_rhel10_1-2.1.4", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_nfs_disabled" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "4e572d12-66ca-4968-aa22-3a7d5f8cf1b3", - "control-id": "cis_rhel10_2-1.10", + "uuid": "d006faa5-512f-41ae-b41d-ee1917976d99", + "control-id": "cis_rhel10_1-2.2.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "79b63733-0bd5-4cf6-8d19-52cda10de390", - "control-id": "cis_rhel10_2-1.11", + "uuid": "f79f5bc6-2c1f-448d-91c6-dce9dfada26e", + "control-id": "cis_rhel10_1-3.1.1", "description": "REPLACE_ME", "props": [ { @@ -18226,14 +17205,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_cups_disabled" + "value": "package_libselinux_installed" } ] }, { - "uuid": "f06c3f2d-425b-463b-b00c-c623025a0633", - "control-id": "cis_rhel10_2-1.12", - "description": "Many of the libvirt packages used by Enterprise Linux virtualization, and the nfs-utils\npackage used for The Network File System (NFS), are dependent on the rpcbind package.", + "uuid": "9c6eb221-afdb-45dc-9655-f1717ce1466c", + "control-id": "cis_rhel10_1-3.1.2", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -18243,13 +17222,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_rpcbind_disabled" + "value": "grub2_enable_selinux" } ] }, { - "uuid": "ab052443-942b-48fb-ae49-7cf5e8e1e2a1", - "control-id": "cis_rhel10_2-1.13", + "uuid": "7f053699-1b74-454b-bb02-b7dc59674c6c", + "control-id": "cis_rhel10_1-3.1.3", "description": "REPLACE_ME", "props": [ { @@ -18260,13 +17239,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_rsync_removed" + "value": "selinux_policytype" } ] }, { - "uuid": "22be3ba0-7336-464d-a676-bbe9d65e9306", - "control-id": "cis_rhel10_2-1.14", + "uuid": "ce09fd2d-a96e-4157-ad3d-8f8e003e2b41", + "control-id": "cis_rhel10_1-3.1.4", "description": "REPLACE_ME", "props": [ { @@ -18277,13 +17256,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_net-snmp_removed" + "value": "selinux_not_disabled" } ] }, { - "uuid": "50c03cf5-83c2-44f2-a452-eb7bd240325e", - "control-id": "cis_rhel10_2-1.15", + "uuid": "d3a8a5df-59a7-43bc-af82-2c610d751d56", + "control-id": "cis_rhel10_1-3.1.7", "description": "REPLACE_ME", "props": [ { @@ -18294,13 +17273,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_telnet-server_removed" + "value": "package_mcstrans_removed" } ] }, { - "uuid": "30a29217-1a62-4f1c-aebd-77564209c9d1", - "control-id": "cis_rhel10_2-1.16", + "uuid": "025aabe8-67d5-484f-b9e4-36cb08480f2a", + "control-id": "cis_rhel10_1-3.1.8", "description": "REPLACE_ME", "props": [ { @@ -18311,14 +17290,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_tftp-server_removed" + "value": "package_setroubleshoot_removed" } ] }, { - "uuid": "621fa3c0-1470-4ed2-b78e-fc95617756a1", - "control-id": "cis_rhel10_2-1.17", - "description": "REPLACE_ME", + "uuid": "f998f920-e41f-4b4a-b204-4568b2a23a0f", + "control-id": "cis_rhel10_1-4.1", + "description": "There is no automated remediation for this rule and this is intentional.\nMore details in the rule description.", "props": [ { "name": "implementation-status", @@ -18328,70 +17307,56 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_squid_removed" + "value": "grub2_password" } ] }, { - "uuid": "c2ab5493-ee56-4928-bb68-a0f28564beba", - "control-id": "cis_rhel10_2-1.18", + "uuid": "e3ae8b44-6fdf-48db-a517-889933f2e3f5", + "control-id": "cis_rhel10_1-4.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "alternative", + "remarks": "This requirement demands a deeper review of the rules." }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_httpd_removed" + "value": "file_groupowner_grub2_cfg" }, { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_nginx_removed" - } - ] - }, - { - "uuid": "2be05849-7a7f-4d16-990c-2956727cf9d2", - "control-id": "cis_rhel10_2-1.21", - "description": "The rule has_nonlocal_mta currently checks for services listening only on port 25,\nbut the policy checks also for ports 465 and 587", - "props": [ + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_owner_grub2_cfg" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "file_permissions_grub2_cfg" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "postfix_network_listening_disabled" + "value": "file_groupowner_user_cfg" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "has_nonlocal_mta" - } - ] - }, - { - "uuid": "e0056a1e-b2d3-4256-86df-f388a694f484", - "control-id": "cis_rhel10_2-1.22", - "description": "REPLACE_ME", - "props": [ + "value": "file_owner_user_cfg" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "file_permissions_user_cfg" } ] }, { - "uuid": "6fd9e4b7-f2fb-48e8-9634-5b65e280f4ab", - "control-id": "cis_rhel10_2-2.1", + "uuid": "707c3370-a6fe-4870-b329-a8481dcea483", + "control-id": "cis_rhel10_1-5.1", "description": "REPLACE_ME", "props": [ { @@ -18402,25 +17367,30 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_ftp_removed" + "value": "disable_users_coredumps" } ] }, { - "uuid": "4848fa3e-a194-41d6-917b-fe82948689b8", - "control-id": "cis_rhel10_2-2.3", + "uuid": "7bf3c309-9519-4815-be00-26bf5eae137c", + "control-id": "cis_rhel10_1-5.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sysctl_fs_protected_hardlinks" } ] }, { - "uuid": "df801286-b2b2-4bea-8e55-20b972437f92", - "control-id": "cis_rhel10_2-2.4", + "uuid": "5069391d-ad0d-41d4-aec8-b9638928d85e", + "control-id": "cis_rhel10_1-5.4", "description": "REPLACE_ME", "props": [ { @@ -18431,13 +17401,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_telnet_removed" + "value": "sysctl_fs_suid_dumpable" } ] }, { - "uuid": "c2e07774-1a50-4ea9-938d-91bd843f063c", - "control-id": "cis_rhel10_2-2.5", + "uuid": "d4dcfa01-96dd-4bfb-b09f-7e3adbbf932c", + "control-id": "cis_rhel10_1-6.1", "description": "REPLACE_ME", "props": [ { @@ -18448,59 +17418,52 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_tftp_removed" + "value": "configure_crypto_policy" } ] }, { - "uuid": "0d4c3fe8-613a-4995-aa1b-492bb24048de", - "control-id": "cis_rhel10_2-3.1", + "uuid": "fee0033c-2ad0-4731-9b73-a09aba5efd35", + "control-id": "cis_rhel10_1-6.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "alternative", + "remarks": "It is necessary a new rule to ensure a module disabling sha1 in\n/etc/crypto-policies/policies/modules/ so it can be used by update-crypto-policies command." } ] }, { - "uuid": "372d6bd1-24f4-4fdc-b52c-9edc6f15bf79", - "control-id": "cis_rhel10_2-3.2", + "uuid": "bae34ee8-6774-489c-a0bd-7d90208aefc9", + "control-id": "cis_rhel10_1-6.3", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "chronyd_specify_remote_server" + "value": "alternative", + "remarks": "It is necessary a new rule to ensure a module disabling weak MACs in\n/etc/crypto-policies/policies/modules/ so it can be used by update-crypto-policies command." } ] }, { - "uuid": "8cf4e3f6-17a8-4779-98ef-3414e756abe1", - "control-id": "cis_rhel10_2-3.3", + "uuid": "d9c55110-f402-45fa-9e27-f6bd3c7b52c7", + "control-id": "cis_rhel10_1-6.4", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "chronyd_run_as_chrony_user" + "value": "alternative", + "remarks": "It is necessary a new rule to ensure a module disabling CBC in\n/etc/crypto-policies/policies/modules/ so it can be used by update-crypto-policies command." } ] }, { - "uuid": "27ffae8f-399c-448a-8505-b6ec0e1ca199", - "control-id": "cis_rhel10_2-4.1.1", + "uuid": "efb25f6b-16d3-4a99-bda8-483f882e8f63", + "control-id": "cis_rhel10_1-7.1", "description": "REPLACE_ME", "props": [ { @@ -18511,18 +17474,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_cron_installed" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_crond_enabled" + "value": "banner_etc_motd_cis" } ] }, { - "uuid": "35508cfe-d941-4655-b244-0da9428c7e17", - "control-id": "cis_rhel10_2-4.1.2", + "uuid": "1ac2e302-3536-4d2a-9fd7-e075c1953c15", + "control-id": "cis_rhel10_1-7.2", "description": "REPLACE_ME", "props": [ { @@ -18533,23 +17491,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_crontab" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_crontab" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_crontab" + "value": "banner_etc_issue_cis" } ] }, { - "uuid": "77cb234d-dad8-495c-9ac1-ffeffc8fc4cb", - "control-id": "cis_rhel10_2-4.1.3", + "uuid": "1401b0f2-7a05-4edf-8808-296a4e23a718", + "control-id": "cis_rhel10_1-7.3", "description": "REPLACE_ME", "props": [ { @@ -18560,23 +17508,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_hourly" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_hourly" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_hourly" + "value": "banner_etc_issue_net_cis" } ] }, { - "uuid": "4f807325-e3a3-40a8-ae23-2bf897cb0495", - "control-id": "cis_rhel10_2-4.1.4", + "uuid": "7e46f06b-8911-4980-b59c-7740b9d388dd", + "control-id": "cis_rhel10_1-7.4", "description": "REPLACE_ME", "props": [ { @@ -18587,23 +17525,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_daily" + "value": "file_groupowner_etc_motd" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_daily" + "value": "file_owner_etc_motd" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_daily" + "value": "file_permissions_etc_motd" } ] }, { - "uuid": "ecf8546d-5bd5-4b5a-b341-d9b5bd0bad9d", - "control-id": "cis_rhel10_2-4.1.5", + "uuid": "1d3788da-cf33-428b-917e-0a12975190d8", + "control-id": "cis_rhel10_1-7.5", "description": "REPLACE_ME", "props": [ { @@ -18614,23 +17552,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_weekly" + "value": "file_groupowner_etc_issue" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_weekly" + "value": "file_owner_etc_issue" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_weekly" + "value": "file_permissions_etc_issue" } ] }, { - "uuid": "db899333-a9c3-487f-b18b-3388eb41ef6c", - "control-id": "cis_rhel10_2-4.1.6", + "uuid": "70e213b3-55b1-40dd-ae2d-011ec6603c10", + "control-id": "cis_rhel10_1-7.6", "description": "REPLACE_ME", "props": [ { @@ -18641,23 +17579,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_monthly" + "value": "file_groupowner_etc_issue_net" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_monthly" + "value": "file_owner_etc_issue_net" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_monthly" + "value": "file_permissions_etc_issue_net" } ] }, { - "uuid": "c981ece6-e336-45be-a205-66c891761a75", - "control-id": "cis_rhel10_2-4.1.7", + "uuid": "b9d23639-c2c3-4749-b6d8-d21791a57207", + "control-id": "cis_rhel10_1-8.2", "description": "REPLACE_ME", "props": [ { @@ -18668,23 +17606,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_d" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_d" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_d" + "value": "dconf_gnome_disable_user_list" } ] }, { - "uuid": "549e3400-2ce0-4cad-82be-47b44e9e2630", - "control-id": "cis_rhel10_2-4.1.8", + "uuid": "65812aa2-1b50-4562-acc2-e19813ff9abc", + "control-id": "cis_rhel10_1-8.3", "description": "REPLACE_ME", "props": [ { @@ -18695,78 +17623,67 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_cron_deny_not_exist" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_cron_allow_exists" + "value": "dconf_gnome_screensaver_idle_delay" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_allow" + "value": "dconf_gnome_screensaver_lock_delay" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_allow" + "value": "dconf_gnome_session_idle_user_locks" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_allow" + "value": "dconf_gnome_screensaver_user_locks" } ] }, { - "uuid": "47713348-7f21-45fe-a5f7-512afc9e24bd", - "control-id": "cis_rhel10_2-4.2.1", - "description": "It is necessary to create a rule to ensure the existence of at.allow.\nfile_cron_allow_exists can be used as reference for a new templated rule.", + "uuid": "1639c398-5cce-4734-9d3e-593846b7ca7c", + "control-id": "cis_rhel10_1-8.4", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_at_deny_not_exist" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_at_allow" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_at_allow" + "value": "dconf_gnome_disable_automount" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_at_allow" + "value": "dconf_gnome_disable_automount_open" } ] }, { - "uuid": "9de24637-5597-440b-85e7-4a20898c6518", - "control-id": "cis_rhel10_3-1.1", + "uuid": "6aa999b1-b66f-4df9-9501-ed1636a4cc35", + "control-id": "cis_rhel10_1-8.5", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "dconf_gnome_disable_autorun" } ] }, { - "uuid": "e6450b09-8360-439a-a36d-5f56a0946941", - "control-id": "cis_rhel10_3-1.2", + "uuid": "74f16e59-6110-4a9a-ab57-50bf0bb6cba5", + "control-id": "cis_rhel10_2-1.1", "description": "REPLACE_ME", "props": [ { @@ -18777,13 +17694,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "wireless_disable_interfaces" + "value": "service_autofs_disabled" } ] }, { - "uuid": "54b6e6c6-f00c-4f09-a4e0-b3a1f5a13c13", - "control-id": "cis_rhel10_3-1.3", + "uuid": "10623d37-9090-40e9-990b-df60d45dff8b", + "control-id": "cis_rhel10_2-1.2", "description": "REPLACE_ME", "props": [ { @@ -18794,13 +17711,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_bluetooth_disabled" + "value": "service_avahi-daemon_disabled" } ] }, { - "uuid": "2765cc16-4dd5-4dea-bcad-f7873485fc88", - "control-id": "cis_rhel10_3-3.1", + "uuid": "f7fe28e4-df85-40f5-bb62-f6cfa34fcd3f", + "control-id": "cis_rhel10_2-1.4", "description": "REPLACE_ME", "props": [ { @@ -18811,18 +17728,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_ip_forward" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_forwarding" + "value": "package_kea_removed" } ] }, { - "uuid": "95faf8ca-af7a-46dd-8681-c20c250ebaa6", - "control-id": "cis_rhel10_3-3.2", + "uuid": "4b7450a5-c3b0-4dc3-9743-317e2703799e", + "control-id": "cis_rhel10_2-1.5", "description": "REPLACE_ME", "props": [ { @@ -18833,18 +17745,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_send_redirects" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_send_redirects" + "value": "package_bind_removed" } ] }, { - "uuid": "b0d105bb-c749-41d1-b85a-d08bb6d74ad9", - "control-id": "cis_rhel10_3-3.3", + "uuid": "ada5d835-f250-495f-a8f9-0cd2fbb7bb1e", + "control-id": "cis_rhel10_2-1.6", "description": "REPLACE_ME", "props": [ { @@ -18855,13 +17762,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses" + "value": "package_dnsmasq_removed" } ] }, { - "uuid": "faea4860-9b9b-44e8-ad4c-1eff1edd1163", - "control-id": "cis_rhel10_3-3.4", + "uuid": "4d116665-a939-4092-8a96-f5ba29f3a4b7", + "control-id": "cis_rhel10_2-1.7", "description": "REPLACE_ME", "props": [ { @@ -18872,13 +17779,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts" + "value": "package_vsftpd_removed" } ] }, { - "uuid": "50044bff-41f5-416e-ba55-86a148b0d3fc", - "control-id": "cis_rhel10_3-3.5", + "uuid": "cc163962-3acf-4a5c-a61d-e09f3aaacd01", + "control-id": "cis_rhel10_2-1.8", "description": "REPLACE_ME", "props": [ { @@ -18889,28 +17796,35 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_accept_redirects" + "value": "package_dovecot_removed" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_accept_redirects" - }, + "value": "package_cyrus-imapd_removed" + } + ] + }, + { + "uuid": "7638ab29-ba59-4de1-802f-acac3a82eb9f", + "control-id": "cis_rhel10_2-1.9", + "description": "Many of the libvirt packages used by Enterprise Linux virtualization are dependent on the\nnfs-utils package.", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_redirects" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_redirects" + "value": "service_nfs_disabled" } ] }, { - "uuid": "541452ae-19b6-4773-ace5-b9fc7a1b56c2", - "control-id": "cis_rhel10_3-3.6", + "uuid": "68252c3c-db7f-4a61-9d00-e63cb7beb009", + "control-id": "cis_rhel10_2-1.10", "description": "REPLACE_ME", "props": [ { @@ -18921,19 +17835,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_secure_redirects" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_secure_redirects" + "value": "service_cups_disabled" } ] }, { - "uuid": "5c9deb38-89c6-45f6-beef-4b1f849f623e", - "control-id": "cis_rhel10_3-3.7", - "description": "REPLACE_ME", + "uuid": "3d096707-9368-4de7-b972-4632069f93d9", + "control-id": "cis_rhel10_2-1.11", + "description": "Many of the libvirt packages used by Enterprise Linux virtualization, and the nfs-utils\npackage used for The Network File System (NFS), are dependent on the rpcbind package.", "props": [ { "name": "implementation-status", @@ -18943,18 +17852,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_rp_filter" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_rp_filter" + "value": "service_rpcbind_disabled" } ] }, { - "uuid": "0b1a9baa-a735-47b5-a241-53c1bd2f8403", - "control-id": "cis_rhel10_3-3.8", + "uuid": "ba8a18df-c7d7-4cd2-9196-61c5f775c43d", + "control-id": "cis_rhel10_2-1.12", "description": "REPLACE_ME", "props": [ { @@ -18965,28 +17869,30 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_accept_source_route" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_accept_source_route" - }, + "value": "package_rsync_removed" + } + ] + }, + { + "uuid": "ad10629c-4ebe-4996-8afe-7a3b5b889a1b", + "control-id": "cis_rhel10_2-1.13", + "description": "REPLACE_ME", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_source_route" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_source_route" + "value": "package_samba_removed" } ] }, { - "uuid": "c18a8887-ffec-492f-b91c-6b1055b0be0d", - "control-id": "cis_rhel10_3-3.9", + "uuid": "5ef23753-aa01-4a6a-9a41-49c468da95d7", + "control-id": "cis_rhel10_2-1.14", "description": "REPLACE_ME", "props": [ { @@ -18997,18 +17903,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_log_martians" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_log_martians" + "value": "package_net-snmp_removed" } ] }, { - "uuid": "fb6b68be-39fd-4e67-a906-50417b2131ba", - "control-id": "cis_rhel10_3-3.10", + "uuid": "70846a43-5c73-4f55-bc3a-8006acf57b45", + "control-id": "cis_rhel10_2-1.15", "description": "REPLACE_ME", "props": [ { @@ -19019,13 +17920,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_tcp_syncookies" + "value": "package_telnet-server_removed" } ] }, { - "uuid": "01b5e980-e916-4839-a4ed-710648b50d2a", - "control-id": "cis_rhel10_3-3.11", + "uuid": "d0d41aef-3a9d-41ec-9d72-0aeafdf04e3e", + "control-id": "cis_rhel10_2-1.16", "description": "REPLACE_ME", "props": [ { @@ -19036,18 +17937,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_ra" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_ra" + "value": "package_tftp-server_removed" } ] }, { - "uuid": "cffef8ad-dc93-4c30-85a7-aab29beb97de", - "control-id": "cis_rhel10_4-1.1", + "uuid": "17b04006-331a-4cb5-9d45-59f365e46c89", + "control-id": "cis_rhel10_2-1.17", "description": "REPLACE_ME", "props": [ { @@ -19058,13 +17954,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_nftables_installed" + "value": "package_squid_removed" } ] }, { - "uuid": "fd6b3f85-b13e-4bb8-a8c3-fd3e6cf1214b", - "control-id": "cis_rhel10_4-1.2", + "uuid": "ce598bda-a605-454a-9299-c1dd09424fca", + "control-id": "cis_rhel10_2-1.18", "description": "REPLACE_ME", "props": [ { @@ -19075,23 +17971,40 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_firewalld_enabled" + "value": "package_httpd_removed" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_firewalld_installed" + "value": "package_nginx_removed" + } + ] + }, + { + "uuid": "9669ac9e-81da-4b30-931a-07c61344cfa9", + "control-id": "cis_rhel10_2-1.21", + "description": "The rule has_nonlocal_mta currently checks for services listening only on port 25,\nbut the policy checks also for ports 465 and 587", + "props": [ + { + "name": "implementation-status", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "partial" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "postfix_network_listening_disabled" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_nftables_disabled" + "value": "has_nonlocal_mta" } ] }, { - "uuid": "395e9a58-fbaa-4f06-a618-d8729a818cd5", - "control-id": "cis_rhel10_4-2.1", + "uuid": "186c15f6-2029-43a8-9d17-a652e049ae98", + "control-id": "cis_rhel10_2-1.22", "description": "REPLACE_ME", "props": [ { @@ -19103,8 +18016,8 @@ ] }, { - "uuid": "aa931d07-c30c-453d-8281-f8e3afdcd62a", - "control-id": "cis_rhel10_4-2.2", + "uuid": "7577bf13-cfa9-481b-bdae-62cf6d86df5d", + "control-id": "cis_rhel10_2-2.1", "description": "REPLACE_ME", "props": [ { @@ -19115,44 +18028,48 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "firewalld_loopback_traffic_trusted" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "firewalld_loopback_traffic_restricted" + "value": "package_ftp_removed" } ] }, { - "uuid": "59484e6a-8195-4b4e-a4ca-e19d439e7c15", - "control-id": "cis_rhel10_4-3.1", - "description": "RHEL systems use firewalld for firewall management. Although nftables is the default\nback-end for firewalld, it is not recommended to use nftables directly when firewalld\nis in use. When using firewalld the base chains are installed by default.", + "uuid": "d2cf105c-0e67-4fe7-ba30-078fa604867f", + "control-id": "cis_rhel10_2-2.3", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "package_telnet_removed" } ] }, { - "uuid": "9e4b1ff9-92d3-432a-99aa-7ae468ee1e1f", - "control-id": "cis_rhel10_4-3.2", + "uuid": "e12504ee-da47-4872-9c7d-a0b380e78126", + "control-id": "cis_rhel10_2-2.4", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "package_tftp_removed" } ] }, { - "uuid": "788c3967-9e34-4286-b3e1-b9f8e1f8100f", - "control-id": "cis_rhel10_4-3.3", - "description": "RHEL systems use firewalld for firewall management. Although nftables is the default\nback-end for firewalld, it is not recommended to use nftables directly when firewalld\nis in use.", + "uuid": "b4be59c2-a9f6-4c6d-b977-c6638b7b5b66", + "control-id": "cis_rhel10_2-3.1", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -19162,20 +18079,25 @@ ] }, { - "uuid": "4bb787f0-b406-4b2e-a4ac-8d18a8fc082f", - "control-id": "cis_rhel10_4-3.4", - "description": "RHEL systems use firewalld for firewall management. Although nftables is the default\nback-end for firewalld, it is not recommended to use nftables directly when firewalld\nis in use.", + "uuid": "3445d5e9-b953-4e73-ac2d-2b8a32cf8652", + "control-id": "cis_rhel10_2-3.2", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "chronyd_specify_remote_server" } ] }, { - "uuid": "4e3a6288-7bb6-4107-a11d-8a0f725d1ada", - "control-id": "cis_rhel10_5-1.1", + "uuid": "36d51343-5e97-4d3a-8dcb-80b61e3aa80c", + "control-id": "cis_rhel10_2-3.3", "description": "REPLACE_ME", "props": [ { @@ -19186,23 +18108,35 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_sshd_config" + "value": "chronyd_run_as_chrony_user" + } + ] + }, + { + "uuid": "b2107731-69cb-47f0-8a17-fd0991c52ff9", + "control-id": "cis_rhel10_2-4.1.1", + "description": "REPLACE_ME", + "props": [ + { + "name": "implementation-status", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_sshd_config" + "value": "package_cron_installed" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_config" + "value": "service_crond_enabled" } ] }, { - "uuid": "47a681df-5861-4398-9d43-56688ddb4356", - "control-id": "cis_rhel10_5-1.2", + "uuid": "852051d1-0871-4b68-889f-dea549738e23", + "control-id": "cis_rhel10_2-4.1.2", "description": "REPLACE_ME", "props": [ { @@ -19213,23 +18147,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_private_key" + "value": "file_groupowner_crontab" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_private_key" + "value": "file_owner_crontab" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_sshd_private_key" + "value": "file_permissions_crontab" } ] }, { - "uuid": "3f26881d-7f2f-4087-830c-2d83cd7606f7", - "control-id": "cis_rhel10_5-1.3", + "uuid": "192a0f75-e1b8-4026-8c3a-44803be40b26", + "control-id": "cis_rhel10_2-4.1.3", "description": "REPLACE_ME", "props": [ { @@ -19240,72 +18174,50 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_pub_key" + "value": "file_groupowner_cron_hourly" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_pub_key" + "value": "file_owner_cron_hourly" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_sshd_pub_key" - } - ] - }, - { - "uuid": "169e840f-7d7b-430c-a051-a2cf9ea9f981", - "control-id": "cis_rhel10_5-1.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." + "value": "file_permissions_cron_hourly" } ] }, { - "uuid": "a30bc5db-f4ab-4f15-98b6-8f0393bd2b68", - "control-id": "cis_rhel10_5-1.5", + "uuid": "d51ae4c8-2843-4b74-8aae-b9260169985d", + "control-id": "cis_rhel10_2-4.1.4", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_kex" - } - ] - }, - { - "uuid": "08afb49b-4861-4bc5-a1c0-950d84eea096", - "control-id": "cis_rhel10_5-1.6", - "description": "REPLACE_ME", - "props": [ + "value": "file_groupowner_cron_daily" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." + "value": "file_owner_cron_daily" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_macs" + "value": "file_permissions_cron_daily" } ] }, { - "uuid": "5faf9dbc-47fa-42ab-899c-1c9778a551df", - "control-id": "cis_rhel10_5-1.7", + "uuid": "24b2e41c-11ea-42f8-95aa-62acd7c7a925", + "control-id": "cis_rhel10_2-4.1.5", "description": "REPLACE_ME", "props": [ { @@ -19316,31 +18228,24 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_limit_user_access" - } - ] - }, - { - "uuid": "2f6a1141-7c55-4690-9d8e-fe9f5f96d36f", - "control-id": "cis_rhel10_5-1.8", - "description": "REPLACE_ME", - "props": [ + "value": "file_groupowner_cron_weekly" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "file_owner_cron_weekly" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_enable_warning_banner_net" + "value": "file_permissions_cron_weekly" } ] }, { - "uuid": "8bfd5c64-fbe3-403a-baf1-bf98efe08d6d", - "control-id": "cis_rhel10_5-1.9", - "description": "The requirement gives an example of 45 seconds, but is flexible about the values. It is only\nnecessary to ensure there is a timeout configured in alignment to the site policy.", + "uuid": "014e6caa-545f-4388-be78-8bc9aae88187", + "control-id": "cis_rhel10_2-4.1.6", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -19350,35 +18255,36 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_idle_timeout" + "value": "file_groupowner_cron_monthly" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_keepalive" + "value": "file_owner_cron_monthly" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_cron_monthly" } ] }, { - "uuid": "af175237-35bc-4874-b6f6-2e192d87c328", - "control-id": "cis_rhel10_5-1.12", + "uuid": "9f3b6f5e-17fa-429e-b93e-44ede1833186", + "control-id": "cis_rhel10_2-4.1.7", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "disable_host_auth" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "0d3c51c9-9b4f-4a12-8e49-b472ea9639f2", - "control-id": "cis_rhel10_5-1.13", + "uuid": "39c1b113-2b3a-44db-92a2-cc4d4163a151", + "control-id": "cis_rhel10_2-4.1.8", "description": "REPLACE_ME", "props": [ { @@ -19389,64 +18295,68 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_rhosts" - } - ] - }, - { - "uuid": "4c040704-fb98-41a4-b0d2-1d7e72df5474", - "control-id": "cis_rhel10_5-1.14", - "description": "REPLACE_ME", - "props": [ + "value": "file_groupowner_cron_d" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "file_owner_cron_d" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_login_grace_time" + "value": "file_permissions_cron_d" } ] }, { - "uuid": "f440e884-506f-45db-befe-6bbcb7bd627e", - "control-id": "cis_rhel10_5-1.15", - "description": "The CIS benchmark is not opinionated about which loglevel is selected here. Here, this\nprofile uses VERBOSE by default, as it allows for the capture of login and logout activity\nas well as key fingerprints.", + "uuid": "0aa52350-3e67-4156-a20e-71425ae46f25", + "control-id": "cis_rhel10_2-4.2.1", + "description": "It is necessary to create a rule to ensure the existence of at.allow.\nfile_cron_allow_exists can be used as reference for a new templated rule.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "partial" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_loglevel_verbose" + "value": "file_at_deny_not_exist" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_groupowner_at_allow" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_owner_at_allow" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_at_allow" } ] }, { - "uuid": "e9e86376-6a69-4965-9b9b-5f3cba6466bb", - "control-id": "cis_rhel10_5-1.16", + "uuid": "b80b0717-0870-476f-8ceb-f0e3335fa134", + "control-id": "cis_rhel10_3-1.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_max_auth_tries" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "c521398e-0bb2-41c1-b072-4374a9290997", - "control-id": "cis_rhel10_5-1.17", + "uuid": "49a5405a-fde8-4205-bd05-ec5a9fc4a62d", + "control-id": "cis_rhel10_3-1.2", "description": "REPLACE_ME", "props": [ { @@ -19457,13 +18367,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_maxstartups" + "value": "wireless_disable_interfaces" } ] }, { - "uuid": "3cfcf630-f88e-457c-9160-6589fa83bd3b", - "control-id": "cis_rhel10_5-1.18", + "uuid": "ccf30e32-2b86-473a-830b-4d881758a17e", + "control-id": "cis_rhel10_3-1.3", "description": "REPLACE_ME", "props": [ { @@ -19474,13 +18384,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_max_sessions" + "value": "service_bluetooth_disabled" } ] }, { - "uuid": "eed1cfdf-aa10-4c3d-9e5e-8f9fc95b99cf", - "control-id": "cis_rhel10_5-1.19", + "uuid": "c1774747-41d9-4c8f-aa56-03490279e5bf", + "control-id": "cis_rhel10_4-1.1", "description": "REPLACE_ME", "props": [ { @@ -19491,30 +18401,26 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_empty_passwords" + "value": "package_firewalld_installed" } ] }, { - "uuid": "3a0698d3-a00f-41e3-b5e4-b2d8d95a15f5", - "control-id": "cis_rhel10_5-1.20", + "uuid": "b197b737-151e-4af5-95bb-37836cc6ce04", + "control-id": "cis_rhel10_4-1.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_root_login" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "a5d27540-cde1-4dde-b0b7-228babd7be7e", - "control-id": "cis_rhel10_5-1.21", + "uuid": "c5a26e8c-f9ae-49de-93cb-68a2f07f4862", + "control-id": "cis_rhel10_5-1.1", "description": "REPLACE_ME", "props": [ { @@ -19525,13 +18431,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_do_not_permit_user_env" + "value": "file_groupowner_sshd_config" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_owner_sshd_config" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_sshd_config" } ] }, { - "uuid": "573ca106-7398-4f02-af24-23a5633e1f26", - "control-id": "cis_rhel10_5-1.22", + "uuid": "8aabba04-3dfd-4d26-ab71-8fee0ce7173f", + "control-id": "cis_rhel10_5-1.2", "description": "REPLACE_ME", "props": [ { @@ -19542,30 +18458,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_enable_pam" - } - ] - }, - { - "uuid": "276a71e1-d5cf-4977-a60d-9f07162eb974", - "control-id": "cis_rhel10_5-2.1", - "description": "REPLACE_ME", - "props": [ + "value": "file_groupownership_sshd_private_key" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "file_ownership_sshd_private_key" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_sudo_installed" + "value": "file_permissions_sshd_private_key" } ] }, { - "uuid": "d23e22e2-1dc8-413e-a67e-d4636b19e5bf", - "control-id": "cis_rhel10_5-2.2", + "uuid": "798d395d-adb8-4a72-a1ac-06daa42e6a6c", + "control-id": "cis_rhel10_5-1.3", "description": "REPLACE_ME", "props": [ { @@ -19576,13 +18485,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_add_use_pty" + "value": "file_groupownership_sshd_pub_key" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_ownership_sshd_pub_key" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_sshd_pub_key" } ] }, { - "uuid": "c1dfb3d1-7496-430f-9ca0-a13010a5a455", - "control-id": "cis_rhel10_5-2.3", + "uuid": "23d7e891-f18b-41f5-b95a-8fa7e89a864b", + "control-id": "cis_rhel10_5-1.4", "description": "REPLACE_ME", "props": [ { @@ -19593,13 +18512,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_custom_logfile" + "value": "sshd_limit_user_access" } ] }, { - "uuid": "976340f0-864f-45a1-9e3e-7da554613f6e", - "control-id": "cis_rhel10_5-2.5", + "uuid": "5c622bcd-327c-4bbb-ac8a-27799ce45bf8", + "control-id": "cis_rhel10_5-1.5", "description": "REPLACE_ME", "props": [ { @@ -19610,31 +18529,26 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_require_reauthentication" + "value": "sshd_enable_warning_banner_net" } ] }, { - "uuid": "38a07b80-b923-4f8c-ac0c-7703ecfdbcff", - "control-id": "cis_rhel10_5-2.6", - "description": "REPLACE_ME", + "uuid": "91d00171-b144-4a9e-9ea1-ff7ece8f3a69", + "control-id": "cis_rhel10_5-1.6", + "description": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_require_reauthentication" } ] }, { - "uuid": "eb18fc5b-3251-4ddd-91a5-8e3fd8a391eb", - "control-id": "cis_rhel10_5-2.7", - "description": "Members of \"wheel\" or GID 0 groups are checked by default if the group option is not set for\npam_wheel.so module. The recommendation states the group should be empty to reinforce the\nuse of \"sudo\" for privileged access. Therefore, members of these groups should be manually\nchecked or a different group should be informed.", + "uuid": "a0c42df9-47c9-4c98-a0ad-dc9bb54f64e7", + "control-id": "cis_rhel10_5-1.7", + "description": "The requirement gives an example of 45 seconds, but is flexible about the values. It is only\nnecessary to ensure there is a timeout configured in alignment to the site policy.", "props": [ { "name": "implementation-status", @@ -19644,75 +18558,54 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "use_pam_wheel_group_for_su" + "value": "sshd_set_idle_timeout" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_pam_wheel_group_empty" + "value": "sshd_set_keepalive" } ] }, { - "uuid": "f43fc128-55be-48ba-8183-91885870c241", - "control-id": "cis_rhel10_5-3.1.1", + "uuid": "8ce7ee50-335d-403e-af1e-5920e3ec996f", + "control-id": "cis_rhel10_5-1.12", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "alternative", - "remarks": "It is necessary a new rule to ensure PAM package is updated." - } - ] - }, - { - "uuid": "10e0d2e3-259e-4911-bd2c-b2d5cc9ef722", - "control-id": "cis_rhel10_5-3.1.2", - "description": "REPLACE_ME", - "props": [ + "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary a new rule to ensure authselect package is updated." + "value": "sshd_use_strong_kex" } ] }, { - "uuid": "d54e46ee-08b3-4485-9b14-b8bb32279c17", - "control-id": "cis_rhel10_5-3.1.3", + "uuid": "99d2022a-8bfb-45db-8bd2-78e4f644a056", + "control-id": "cis_rhel10_5-1.13", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary a new rule to ensure libpwquality package is updated." + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_pam_pwquality_installed" - } - ] - }, - { - "uuid": "04e47d7b-cb5c-41ab-a1b5-71c363e0d851", - "control-id": "cis_rhel10_5-3.2.1", - "description": "This requirement is hard to be automated without any specific requirement. The policy even\nstates that provided commands are examples, other custom settings might be in place and the\nsettings might be different depending on site policies. The other rules will already make\nsure there is a correct autheselect profile regardless of the existing settings. It is\nnecessary to better discuss with CIS Community.", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "sshd_set_login_grace_time" } ] }, { - "uuid": "602e476a-3115-4d83-9039-dfafc20563b9", - "control-id": "cis_rhel10_5-3.2.2", - "description": "This requirement is also indirectly satisfied by the requirement 5.3.3.1.", + "uuid": "4f111bc7-4f86-4ac7-94b3-af722cfdf9c3", + "control-id": "cis_rhel10_5-1.14", + "description": "The CIS benchmark is not opinionated about which loglevel is selected here. Here, this\nprofile uses VERBOSE by default, as it allows for the capture of login and logout activity\nas well as key fingerprints.", "props": [ { "name": "implementation-status", @@ -19722,54 +18615,48 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_password_auth" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_system_auth" + "value": "sshd_set_loglevel_verbose" } ] }, { - "uuid": "05e584c3-ea2e-4a3b-8127-f13e286b3750", - "control-id": "cis_rhel10_5-3.2.3", - "description": "This requirement is also indirectly satisfied by the requirement 5.3.3.2.", + "uuid": "76711b0a-712b-4622-91f1-28d1fd443ad3", + "control-id": "cis_rhel10_5-1.15", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "alternative", + "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_use_strong_macs" } ] }, { - "uuid": "f38fc4f5-162f-4e9a-8640-0cab82f4f311", - "control-id": "cis_rhel10_5-3.2.4", - "description": "The module is properly enabled by the rules mentioned in related_rules.\nRequirements in 5.3.3.3 use these rules.", + "uuid": "d11c0c0d-82c7-4f8f-825c-8b92fb9d1d06", + "control-id": "cis_rhel10_5-1.16", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - } - ] - }, - { - "uuid": "ae84df92-6540-4d2e-8c06-5a383fd4ede1", - "control-id": "cis_rhel10_5-3.2.5", - "description": "This module is always present by default. It is necessary to investigate if a new rule to\ncheck its existence needs to be created. But so far the rule no_empty_passwords, used in\n5.3.3.4 can ensure this requirement is attended.", - "props": [ + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "sshd_set_max_auth_tries" } ] }, { - "uuid": "8d799ec3-8fbc-4250-8f99-070edc9d6507", - "control-id": "cis_rhel10_5-3.3.1.1", + "uuid": "40396de0-1625-4b3e-adc8-82c95b8d919f", + "control-id": "cis_rhel10_5-1.17", "description": "REPLACE_ME", "props": [ { @@ -19780,14 +18667,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_deny" + "value": "sshd_set_maxstartups" } ] }, { - "uuid": "10d6017e-3af7-4e62-8d47-b6367476213a", - "control-id": "cis_rhel10_5-3.3.1.2", - "description": "The policy also accepts value 0, which means the locked accounts should be manually unlocked\nby an administrator. However, it also mentions that using value 0 can facilitate a DoS\nattack to legitimate users.", + "uuid": "50b2063e-7b28-4593-8644-f53cf1d8589e", + "control-id": "cis_rhel10_5-1.18", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -19797,13 +18684,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_unlock_time" + "value": "sshd_set_max_sessions" } ] }, { - "uuid": "d9b82c2a-2fdb-46a8-bc2d-bfe8fc0758a6", - "control-id": "cis_rhel10_5-3.3.2.1", + "uuid": "ae9cd74d-531b-41cf-b24a-ddd81875b38f", + "control-id": "cis_rhel10_5-1.19", "description": "REPLACE_ME", "props": [ { @@ -19814,13 +18701,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_difok" + "value": "sshd_disable_empty_passwords" } ] }, { - "uuid": "d58d776a-de49-4a1c-94c4-357f445780d8", - "control-id": "cis_rhel10_5-3.3.2.2", + "uuid": "2a08a803-192c-47ad-a3b0-2baf6ee677b1", + "control-id": "cis_rhel10_5-1.20", "description": "REPLACE_ME", "props": [ { @@ -19831,14 +18718,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_minlen" + "value": "sshd_disable_root_login" } ] }, { - "uuid": "32adb807-c807-47b9-848a-dffdb3b41193", - "control-id": "cis_rhel10_5-3.3.2.3", - "description": "This requirement is expected to be manual. However, in previous versions of the policy\nit was already automated the configuration of \"minclass\" option. This posture was kept for\nRHEL 9 in this new version. Rules related to other options are informed in related_rules.\nIn short, minclass=4 alone can achieve the same result achieved by the combination of the\nother 4 options mentioned in the policy.", + "uuid": "a66eea7b-8600-40f7-9df7-79d73a1357b8", + "control-id": "cis_rhel10_5-1.21", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -19848,13 +18735,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_minclass" + "value": "sshd_do_not_permit_user_env" } ] }, { - "uuid": "c3fe609c-b21e-4ea3-9e65-a4126cc24252", - "control-id": "cis_rhel10_5-3.3.2.4", + "uuid": "2d622009-37a3-44f4-aa4c-fa5590b48112", + "control-id": "cis_rhel10_5-1.22", "description": "REPLACE_ME", "props": [ { @@ -19865,26 +18752,30 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_maxrepeat" + "value": "sshd_enable_pam" } ] }, { - "uuid": "938fbf1d-8469-4665-b242-851b19e5c700", - "control-id": "cis_rhel10_5-3.3.2.5", + "uuid": "a7ba41dd-68bf-49b5-9b40-c66b96bbeb3a", + "control-id": "cis_rhel10_5-2.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "planned", - "remarks": "A new templated rule and variable are necessary for the maxsequence option." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "package_sudo_installed" } ] }, { - "uuid": "58802af4-881c-4462-9a20-f83eb15d56c7", - "control-id": "cis_rhel10_5-3.3.2.6", + "uuid": "b3d5b0f1-4876-4f01-bdfc-cac2b4f85800", + "control-id": "cis_rhel10_5-2.2", "description": "REPLACE_ME", "props": [ { @@ -19895,13 +18786,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_dictcheck" + "value": "sudo_add_use_pty" } ] }, { - "uuid": "db1dd539-4731-4931-89de-901ad5fa819e", - "control-id": "cis_rhel10_5-3.3.2.7", + "uuid": "96ddc6e2-0fbc-49ed-bbfe-b8c4eccf5f06", + "control-id": "cis_rhel10_5-2.3", "description": "REPLACE_ME", "props": [ { @@ -19912,14 +18803,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_enforce_root" + "value": "sudo_custom_logfile" } ] }, { - "uuid": "a6a02ae7-bc8f-4c06-bb1d-2034ba85197d", - "control-id": "cis_rhel10_5-3.3.3.1", - "description": "Although mentioned in the section 5.3.3.3, there is no explicit requirement to configure\nretry option of pam_pwhistory. If come in the future, the rule accounts_password_pam_retry\ncan be used.", + "uuid": "38861e10-094d-4080-8f5c-867b1f5b162b", + "control-id": "cis_rhel10_5-2.5", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -19929,44 +18820,31 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_pwhistory_remember_password_auth" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_pwhistory_remember_system_auth" + "value": "sudo_require_authentication" } ] }, { - "uuid": "4b71084b-5d3f-4f44-8a81-28e8866d668c", - "control-id": "cis_rhel10_5-3.3.3.2", + "uuid": "2b5e7f74-62ef-410e-bbd8-2449ce40ef1d", + "control-id": "cis_rhel10_5-2.6", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "planned", - "remarks": "A new rule needs to be created to check and remediate the enforce_for_root option in\n/etc/security/pwhistory.conf. accounts_password_pam_enforce_root can be used as reference." - } - ] - }, - { - "uuid": "d46e95fe-c041-466a-ac89-d020ca86c560", - "control-id": "cis_rhel10_5-3.3.3.3", - "description": "In RHEL 9 pam_pwhistory is enabled via authselect feature, as required in 5.3.2.4. The\nfeature automatically set \"use_authok\" option. In any case, we don't have a rule to check\nthis option specifically.", - "props": [ + "value": "implemented" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "sudo_require_reauthentication" } ] }, { - "uuid": "4be29d24-6bc8-4ea9-a149-0dce123de1e5", - "control-id": "cis_rhel10_5-3.3.4.1", - "description": "The rule more specifically used in this requirement also satify the requirement 5.3.2.5.", + "uuid": "2df545c8-bc2c-4c12-900c-01a7e69087c7", + "control-id": "cis_rhel10_5-2.7", + "description": "Members of \"wheel\" or GID 0 groups are checked by default if the group option is not set for\npam_wheel.so module. The recommendation states the group should be empty to reinforce the\nuse of \"sudo\" for privileged access. Therefore, members of these groups should be manually\nchecked or a different group should be informed.", "props": [ { "name": "implementation-status", @@ -19976,27 +18854,31 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_empty_passwords" + "value": "use_pam_wheel_group_for_su" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "ensure_pam_wheel_group_empty" } ] }, { - "uuid": "6addc49e-4dbe-49c4-9712-214a1d2a2f1a", - "control-id": "cis_rhel10_5-3.3.4.2", - "description": "REPLACE_ME", + "uuid": "39bf256f-6dd2-43c9-9d16-613d75a35cbd", + "control-id": "cis_rhel10_5-3.1.1", + "description": "This requirement is hard to be automated without any specific requirement. The policy even\nstates that provided commands are examples, other custom settings might be in place and the\nsettings might be different depending on site policies. The other rules will already make\nsure there is a correct autheselect profile regardless of the existing settings. It is\nnecessary to better discuss with CIS Community.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "Usage of pam_unix.so module together with \"remember\" option is deprecated and is not\nrecommened by this policy. Instead, it should be used remember option of pam_pwhistory\nmodule, as required in 5.3.3.3.1. See here for more details about pam_unix.so:\nhttps://bugzilla.redhat.com/show_bug.cgi?id=1778929\nA new rule needs to be created to remove the remember option from pam_unix module." + "value": "partial" } ] }, { - "uuid": "70e7abf6-4222-41cf-a8c5-b64e752f1868", - "control-id": "cis_rhel10_5-3.3.4.3", - "description": "Changes in logindefs mentioned in this requirement are more specifically covered by 5.4.1.4", + "uuid": "15688733-5f98-469b-b11d-1c4a73c18c23", + "control-id": "cis_rhel10_5-3.1.2", + "description": "This requirement is also indirectly satisfied by the requirement 5.3.2.1.", "props": [ { "name": "implementation-status", @@ -20006,29 +18888,34 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_systemauth" + "value": "account_password_pam_faillock_password_auth" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_passwordauth" + "value": "account_password_pam_faillock_system_auth" } ] }, { - "uuid": "95af65a6-af5d-4fc1-84ff-d045d5e9c5de", - "control-id": "cis_rhel10_5-3.3.4.4", - "description": "In RHEL 9 pam_unix is enabled by default in all authselect profiles already with the\nuse_authtok option set. In any case, we don't have a rule to check this option specifically,\nlike in 5.3.3.3.3.", + "uuid": "5cab9729-83cf-49f5-bc5b-8507682e1525", + "control-id": "cis_rhel10_5-3.1.3", + "description": "This requirement is also indirectly satisfied by the requirement 5.3.2.2.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "package_pam_pwquality_installed" } ] }, { - "uuid": "187898ed-10af-460f-8d81-821135d9caaf", + "uuid": "a4969d9f-03fb-4e16-8a3a-508ae382f878", "control-id": "cis_rhel10_5-4.1.1", "description": "REPLACE_ME", "props": [ @@ -20050,7 +18937,7 @@ ] }, { - "uuid": "3cac09be-4927-43d6-addb-03e7a6315f5e", + "uuid": "5cba9e65-9387-4c62-9f8c-255a124ef228", "control-id": "cis_rhel10_5-4.1.3", "description": "REPLACE_ME", "props": [ @@ -20072,7 +18959,7 @@ ] }, { - "uuid": "4ef8a481-f304-44e8-a7e4-8c1e795d0ab4", + "uuid": "a683a252-53e2-4bfe-83d7-6e679f743d50", "control-id": "cis_rhel10_5-4.1.4", "description": "There's a \"new\" set of options in /etc/login.defs file to define the number of iterations\nperformed during the hashing process.", "props": [ @@ -20094,7 +18981,7 @@ ] }, { - "uuid": "07e52ef8-fb2e-46b5-bbb3-d8bc9ff7dc76", + "uuid": "c0cc0a87-d274-4ad4-8eae-faf82c55a4b3", "control-id": "cis_rhel10_5-4.1.5", "description": "REPLACE_ME", "props": [ @@ -20116,7 +19003,7 @@ ] }, { - "uuid": "f568cad9-0bfd-4d0c-8229-515e1b08e0c5", + "uuid": "2d3ee8d0-5af8-41f9-a1ee-22d52f72c694", "control-id": "cis_rhel10_5-4.1.6", "description": "REPLACE_ME", "props": [ @@ -20133,7 +19020,7 @@ ] }, { - "uuid": "b7f87d46-e547-4b17-b69b-29a70ceb5440", + "uuid": "b7b76632-e53b-4044-b08a-63413e5908ba", "control-id": "cis_rhel10_5-4.2.1", "description": "REPLACE_ME", "props": [ @@ -20150,7 +19037,7 @@ ] }, { - "uuid": "822e07ec-9f0a-4c67-8def-b409387e7b70", + "uuid": "93b4003b-00bb-4447-9dfd-9f2222e6eb6c", "control-id": "cis_rhel10_5-4.2.2", "description": "The rule confirms the primary group for root, but doesn't check if any other user are also\nusing GID 0. New rule is necessary.\nThere is assessment but no automated remediation for this rule and this sounds reasonable.", "props": [ @@ -20167,20 +19054,24 @@ ] }, { - "uuid": "6579800d-48ae-42d0-95ba-2df467773a6f", + "uuid": "d394ae04-16a2-4662-9e45-dfce3c9b2642", "control-id": "cis_rhel10_5-4.2.3", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "New rule is necessary." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "groups_no_zero_gid_except_root" } ] }, { - "uuid": "f6ef78e4-d5ba-4647-add0-7697252987ab", + "uuid": "7e4a1c17-7188-4331-b166-edfe476a7c9c", "control-id": "cis_rhel10_5-4.2.4", "description": "REPLACE_ME", "props": [ @@ -20197,7 +19088,7 @@ ] }, { - "uuid": "93fd4d88-e3fc-42c8-8ecd-48372a39a4af", + "uuid": "344dfe91-a2d3-456e-a3c2-724327b61b93", "control-id": "cis_rhel10_5-4.2.5", "description": "REPLACE_ME", "props": [ @@ -20219,20 +19110,24 @@ ] }, { - "uuid": "9b020e58-db1a-4f72-9e0f-7415fddee8e7", + "uuid": "d72ba501-f661-4ff2-8894-9259a8046a88", "control-id": "cis_rhel10_5-4.2.6", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "There is no rule to ensure umask in /root/.bash_profile and /root/.bashrc. A new rule have\nto be created. It can be based on accounts_umask_interactive_users." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_umask_root" } ] }, { - "uuid": "e4bb1aa3-def2-49be-a6d3-a7f8f4ca5d88", + "uuid": "c7a4091c-4fa8-4795-a9a0-0d7d535cdce2", "control-id": "cis_rhel10_5-4.2.7", "description": "REPLACE_ME", "props": [ @@ -20254,20 +19149,19 @@ ] }, { - "uuid": "1d3a657a-5379-41f7-a04d-51d8ed359abb", + "uuid": "41b21d6a-2da2-445b-89dd-f8bf34e2fd18", "control-id": "cis_rhel10_5-4.2.8", - "description": "REPLACE_ME", + "description": "New rule is necessary.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "New rule is necessary." + "value": "implemented" } ] }, { - "uuid": "f7057d67-c02e-4b3d-b04a-e132c1c377f5", + "uuid": "82976154-c1e3-42f8-9ba6-e66f056506d0", "control-id": "cis_rhel10_5-4.3.2", "description": "REPLACE_ME", "props": [ @@ -20284,7 +19178,7 @@ ] }, { - "uuid": "e9cb8722-37b9-490b-9beb-7984d5752fc8", + "uuid": "f0f17daf-9161-4a9d-86b4-5d9b18da44d9", "control-id": "cis_rhel10_5-4.3.3", "description": "REPLACE_ME", "props": [ @@ -20311,7 +19205,7 @@ ] }, { - "uuid": "4a0998b5-665c-417f-ae7e-6b2943f94792", + "uuid": "90c7c09d-7876-4d71-9294-bfdcaaae2fd7", "control-id": "cis_rhel10_6-1.1", "description": "REPLACE_ME", "props": [ @@ -20333,7 +19227,7 @@ ] }, { - "uuid": "d0ae6cd2-68f6-42e3-9d02-893ce2a4f719", + "uuid": "b9a37639-6229-41ef-9c71-5ad727debaee", "control-id": "cis_rhel10_6-1.2", "description": "REPLACE_ME", "props": [ @@ -20350,7 +19244,7 @@ ] }, { - "uuid": "c1ba82b2-fbc5-4f92-8a99-4584124dc049", + "uuid": "6634fa36-4615-49bd-8ad5-e8272de7c019", "control-id": "cis_rhel10_6-1.3", "description": "REPLACE_ME", "props": [ @@ -20367,7 +19261,7 @@ ] }, { - "uuid": "b0270948-3976-4530-9e1b-13f4abb97036", + "uuid": "98cb7de1-5404-4b4e-a9e3-15fa59a6c90b", "control-id": "cis_rhel10_6-2.1.1", "description": "REPLACE_ME", "props": [ @@ -20384,7 +19278,7 @@ ] }, { - "uuid": "3d071add-4c4d-4dfd-834a-1f2bce438642", + "uuid": "9b397932-0053-4407-b147-ceb3da5f177c", "control-id": "cis_rhel10_6-2.1.2", "description": "REPLACE_ME", "props": [ @@ -20397,7 +19291,7 @@ ] }, { - "uuid": "fef3f21f-a424-47b7-9c7a-3b9190a37629", + "uuid": "b202744a-2842-4cc5-9f84-201cb26cf570", "control-id": "cis_rhel10_6-2.1.3", "description": "REPLACE_ME", "props": [ @@ -20410,7 +19304,7 @@ ] }, { - "uuid": "8bb7cf06-44da-48a1-ad17-fa523df7b3c1", + "uuid": "3fc6d6a7-df7a-4537-9c42-3f141839de84", "control-id": "cis_rhel10_6-2.1.4", "description": "REPLACE_ME", "props": [ @@ -20423,51 +19317,55 @@ ] }, { - "uuid": "44e4be51-1e27-47f9-b3da-6b5d8de6de75", - "control-id": "cis_rhel10_6-2.2.1.1", + "uuid": "87950bff-bcce-4fdf-8edf-00ff1bfc43ee", + "control-id": "cis_rhel10_6-2.2.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_systemd-journal-remote_installed" + "value": "alternative", + "remarks": "This rule conflicts with 6.2.3.3. More investigation is needed to properly solve this." } ] }, { - "uuid": "56bab0a5-e428-4663-9e23-e56779b78431", - "control-id": "cis_rhel10_6-2.2.1.2", + "uuid": "1d11d99c-ab86-440d-b48f-6bdaded73bc7", + "control-id": "cis_rhel10_6-2.2.3", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "journald_compress" } ] }, { - "uuid": "6937750e-96fe-4d5f-aede-eafa0bcdd76e", - "control-id": "cis_rhel10_6-2.2.1.3", + "uuid": "26d54c98-b5e5-4b87-adc7-059ad48ce3dd", + "control-id": "cis_rhel10_6-2.2.4", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "New templated rule is necessary." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "journald_storage" } ] }, { - "uuid": "25c56a8c-1a98-490a-b375-947797f2bf03", - "control-id": "cis_rhel10_6-2.2.1.4", + "uuid": "d1bbbc9a-020a-4f43-8bf0-d40864f6d7cc", + "control-id": "cis_rhel10_6-2.2.1.1", "description": "REPLACE_ME", "props": [ { @@ -20478,43 +19376,39 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "socket_systemd-journal-remote_disabled" + "value": "package_systemd-journal-remote_installed" } ] }, { - "uuid": "705f436b-3b49-48ce-ae30-9f9508c7386c", - "control-id": "cis_rhel10_6-2.2.2", + "uuid": "8b244230-91a0-484d-a182-b214e6faa08a", + "control-id": "cis_rhel10_6-2.2.1.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "alternative", - "remarks": "This rule conflicts with 6.2.3.3. More investigation is needed to properly solve this." + "remarks": "REPLACE_ME" } ] }, { - "uuid": "e9c90926-885c-427a-9612-6cc0627bb82e", - "control-id": "cis_rhel10_6-2.2.3", + "uuid": "a4813730-697b-45a8-be1b-05b38b61a43c", + "control-id": "cis_rhel10_6-2.2.1.3", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_compress" + "value": "alternative", + "remarks": "New templated rule is necessary." } ] }, { - "uuid": "a74fcf0b-ad0d-4d72-a6dd-5c17c8cc9af8", - "control-id": "cis_rhel10_6-2.2.4", + "uuid": "c50ce80f-347b-4eae-be5e-397b6f62ee5b", + "control-id": "cis_rhel10_6-2.2.1.4", "description": "REPLACE_ME", "props": [ { @@ -20525,12 +19419,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_storage" + "value": "socket_systemd-journal-remote_disabled" } ] }, { - "uuid": "e0fc716c-7272-4578-a589-93a123d37f37", + "uuid": "590711d5-73ed-43c0-b238-7918eb4bdd87", "control-id": "cis_rhel10_6-2.3.1", "description": "REPLACE_ME", "props": [ @@ -20542,7 +19436,7 @@ ] }, { - "uuid": "fcddb819-8021-4e50-b436-4052bbe01856", + "uuid": "a02004f0-7de2-4870-94e4-24b3713d792d", "control-id": "cis_rhel10_6-2.3.2", "description": "REPLACE_ME", "props": [ @@ -20554,7 +19448,7 @@ ] }, { - "uuid": "ca46e7d4-7129-4b6a-be40-6e3ac6217dfd", + "uuid": "dc642689-e4f4-4bc0-adb9-fe00b1d42d0b", "control-id": "cis_rhel10_6-2.3.3", "description": "REPLACE_ME", "props": [ @@ -20566,7 +19460,7 @@ ] }, { - "uuid": "00b8ead7-1794-4833-9cdd-8a367ef0770a", + "uuid": "74d6d181-f298-4d4e-8112-5256e7878a1d", "control-id": "cis_rhel10_6-2.3.4", "description": "REPLACE_ME", "props": [ @@ -20578,7 +19472,7 @@ ] }, { - "uuid": "7202a497-94b1-44bc-b7d0-fb8de894f6f2", + "uuid": "122fdcde-7781-4cd6-b795-a0f11db1c730", "control-id": "cis_rhel10_6-2.3.5", "description": "REPLACE_ME", "props": [ @@ -20591,7 +19485,7 @@ ] }, { - "uuid": "722ac5e2-c2bd-4464-acab-7717e7540cc3", + "uuid": "89bf13c9-ab74-483d-a853-6c9ff0ad5566", "control-id": "cis_rhel10_6-2.3.6", "description": "REPLACE_ME", "props": [ @@ -20604,7 +19498,7 @@ ] }, { - "uuid": "15185150-4033-43a6-98fb-4ab5eea7e6af", + "uuid": "d501c2c2-b276-44ef-8280-f2006f38dd32", "control-id": "cis_rhel10_6-2.3.7", "description": "REPLACE_ME", "props": [ @@ -20616,7 +19510,7 @@ ] }, { - "uuid": "4854cec7-c4bb-4541-8ec5-e7413c810a5a", + "uuid": "72b03b8a-0f31-4661-977d-729c818d231e", "control-id": "cis_rhel10_6-2.3.8", "description": "REPLACE_ME", "props": [ @@ -20629,7 +19523,7 @@ ] }, { - "uuid": "2937003f-8545-48c3-81f6-183ece19620a", + "uuid": "f893e7d0-5331-4e18-ad7e-591026f5bc36", "control-id": "cis_rhel10_6-2.4.1", "description": "It is not harmful to run these rules even if rsyslog is not installed or active.", "props": [ @@ -20656,7 +19550,7 @@ ] }, { - "uuid": "f222d1ef-0baf-480f-a19b-b2901ec3d199", + "uuid": "3aac3e17-232d-479c-a630-893e3f858168", "control-id": "cis_rhel10_7-1.1", "description": "REPLACE_ME", "props": [ @@ -20683,7 +19577,7 @@ ] }, { - "uuid": "5c96a8f2-7c7b-4ab2-810b-1ab62a6a2124", + "uuid": "8a0d319c-0964-4a66-bfc1-3a2a9b32d9ac", "control-id": "cis_rhel10_7-1.2", "description": "REPLACE_ME", "props": [ @@ -20710,7 +19604,7 @@ ] }, { - "uuid": "466ca432-82e5-4fee-934a-2043730ba8e7", + "uuid": "b1854783-cad5-469a-a8fc-16d644725cf8", "control-id": "cis_rhel10_7-1.3", "description": "REPLACE_ME", "props": [ @@ -20737,7 +19631,7 @@ ] }, { - "uuid": "d1dbaa17-2933-4713-9852-ce105371c23f", + "uuid": "c7daefb4-d55e-4990-ad23-c3f7021d1d33", "control-id": "cis_rhel10_7-1.4", "description": "REPLACE_ME", "props": [ @@ -20764,7 +19658,7 @@ ] }, { - "uuid": "c1e071e9-9e9f-40b7-93e4-0659d84c9074", + "uuid": "86e5bd3a-2c0f-4edc-8976-e9269e38a8c7", "control-id": "cis_rhel10_7-1.5", "description": "REPLACE_ME", "props": [ @@ -20791,7 +19685,7 @@ ] }, { - "uuid": "22510f26-803f-48c0-8c17-a12cd1685a23", + "uuid": "3c250c7b-d52d-42ec-b733-c62bf52364d7", "control-id": "cis_rhel10_7-1.6", "description": "REPLACE_ME", "props": [ @@ -20818,7 +19712,7 @@ ] }, { - "uuid": "ab8e3610-bb3c-4651-a234-e5a18b6b8a0d", + "uuid": "fc95da67-d954-487b-aac7-447b78da1f37", "control-id": "cis_rhel10_7-1.7", "description": "REPLACE_ME", "props": [ @@ -20845,7 +19739,7 @@ ] }, { - "uuid": "6c9edba4-cf54-4aa5-907d-13ae1e404cb7", + "uuid": "b8635bc1-301e-46ea-83eb-a7688fdd39db", "control-id": "cis_rhel10_7-1.8", "description": "REPLACE_ME", "props": [ @@ -20872,7 +19766,7 @@ ] }, { - "uuid": "b139482c-0f23-42be-8099-958533a90e0b", + "uuid": "0172ed42-9284-4b0e-a47b-3d30a5c24f90", "control-id": "cis_rhel10_7-1.9", "description": "REPLACE_ME", "props": [ @@ -20899,14 +19793,14 @@ ] }, { - "uuid": "648ef94f-6a1f-447d-ab12-e8f75e895286", + "uuid": "b693c390-b7b8-45de-a90d-fa1df130335c", "control-id": "cis_rhel10_7-1.10", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "implemented" }, { "name": "Rule_Id", @@ -20916,7 +19810,7 @@ ] }, { - "uuid": "4e3c05a8-6953-488c-8884-43fc36401073", + "uuid": "ee50aca7-9404-42ae-85f9-86811aa16d76", "control-id": "cis_rhel10_7-1.11", "description": "REPLACE_ME", "props": [ @@ -20938,7 +19832,7 @@ ] }, { - "uuid": "7086dc61-100d-41a3-827f-7a4762d5e737", + "uuid": "a751c08e-5155-4d70-8b29-e526fd022414", "control-id": "cis_rhel10_7-1.12", "description": "REPLACE_ME", "props": [ @@ -20960,7 +19854,7 @@ ] }, { - "uuid": "6c4140b2-236d-4335-b2a7-8e78c16788db", + "uuid": "526dc869-d213-4e99-b844-150edc4de70c", "control-id": "cis_rhel10_7-1.13", "description": "REPLACE_ME", "props": [ @@ -20973,7 +19867,7 @@ ] }, { - "uuid": "f6c61725-0f16-41a3-8d15-fbfa61ca0ea7", + "uuid": "55022c9a-36e8-4bfa-a600-f3e6a18d146f", "control-id": "cis_rhel10_7-2.1", "description": "REPLACE_ME", "props": [ @@ -20990,7 +19884,7 @@ ] }, { - "uuid": "a8e12361-7bc9-4a11-8b30-f5ca03a9da17", + "uuid": "b1d95c2f-cf23-42e2-ac39-b2169681736c", "control-id": "cis_rhel10_7-2.2", "description": "REPLACE_ME", "props": [ @@ -21007,7 +19901,7 @@ ] }, { - "uuid": "ef7decf9-f1f8-452d-82ae-41fc2e10e293", + "uuid": "b38bf6c8-600a-4cf4-90b4-1ad6a3d5079e", "control-id": "cis_rhel10_7-2.3", "description": "REPLACE_ME", "props": [ @@ -21024,7 +19918,7 @@ ] }, { - "uuid": "2e5fbfc5-d52c-4fb0-9d27-a4827a7e36ab", + "uuid": "4a3c86d0-9e81-469e-a920-816eecda175f", "control-id": "cis_rhel10_7-2.4", "description": "REPLACE_ME", "props": [ @@ -21041,7 +19935,7 @@ ] }, { - "uuid": "4b018247-17b8-4079-b178-42bdcc712ccc", + "uuid": "649bab75-c973-498b-a9cd-fba03d1ae192", "control-id": "cis_rhel10_7-2.5", "description": "REPLACE_ME", "props": [ @@ -21058,7 +19952,7 @@ ] }, { - "uuid": "4f82c357-ab33-4e08-b054-4b53636ba85a", + "uuid": "125f3cac-b401-4b5a-a4d1-45422fb7492d", "control-id": "cis_rhel10_7-2.6", "description": "REPLACE_ME", "props": [ @@ -21075,7 +19969,7 @@ ] }, { - "uuid": "2226492e-9d09-436a-a5d8-8a11c241b654", + "uuid": "00989bed-8e6f-4014-9b06-bd888b98082c", "control-id": "cis_rhel10_7-2.7", "description": "REPLACE_ME", "props": [ @@ -21092,7 +19986,7 @@ ] }, { - "uuid": "1dd151ee-adff-456d-8282-e66d44eb3053", + "uuid": "ea5b0ae0-7584-48bc-a948-5642b0be045a", "control-id": "cis_rhel10_7-2.8", "description": "REPLACE_ME", "props": [ @@ -21119,7 +20013,7 @@ ] }, { - "uuid": "48834260-9cdf-4803-8591-2f7e557168cd", + "uuid": "87e0174e-1412-45ec-b54b-04a62eef65a1", "control-id": "cis_rhel10_7-2.9", "description": "Missing a rule to check that .bash_history is mode 0600 or more restrictive.", "props": [ diff --git a/component-definitions/rhel10/rhel10-cis_rhel10-l1_workstation/component-definition.json b/component-definitions/rhel10/rhel10-cis_rhel10-l1_workstation/component-definition.json index d7295af27..8daff13d3 100644 --- a/component-definitions/rhel10/rhel10-cis_rhel10-l1_workstation/component-definition.json +++ b/component-definitions/rhel10/rhel10-cis_rhel10-l1_workstation/component-definition.json @@ -3,8 +3,8 @@ "uuid": "f215e0d6-22bf-45fa-955c-4bc760e0ee55", "metadata": { "title": "Component definition for rhel10", - "last-modified": "2025-09-12T14:57:18.129619+08:00", - "version": "1.0", + "last-modified": "2025-09-16T19:16:04.718145+00:00", + "version": "1.1", "oscal-version": "1.1.3" }, "components": [ @@ -131,7 +131,7 @@ { "name": "Parameter_Value_Alternatives_5", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", + "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel10': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", "remarks": "rule_set_000" }, { @@ -149,7 +149,7 @@ { "name": "Parameter_Value_Alternatives_6", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", + "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel10': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", "remarks": "rule_set_000" }, { @@ -515,3913 +515,4159 @@ { "name": "Parameter_Id_27", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_account_disable_post_pw_expiration", + "value": "sysctl_net_ipv6_conf_default_forwarding_value", "remarks": "rule_set_000" }, { "name": "Parameter_Description_27", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The number of days to wait after a password expires, until the account will be permanently disabled.", + "value": "Toggle IPv6 default Forwarding", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_27", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'0': '0', 180: 180, 30: 30, 35: 35, 40: 40, 45: 45, 60: 60, 90: 90, 'default': 35}", + "value": "{'default': '0', 'disabled': '0', 'enabled': 1}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_28", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_maximum_age_login_defs", + "value": "var_account_disable_post_pw_expiration", "remarks": "rule_set_000" }, { "name": "Parameter_Description_28", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Maximum age of password in days", + "value": "The number of days to wait after a password expires, until the account will be permanently disabled.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_28", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{365: 365, 120: 120, 180: 180, 90: 90, 60: 60, 45: 45, 'default': 60}", + "value": "{'0': '0', 180: 180, 30: 30, 35: 35, 40: 40, 45: 45, 60: 60, 90: 90, 'default': 35}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_29", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_password_warn_age_login_defs", + "value": "var_accounts_maximum_age_login_defs", "remarks": "rule_set_000" }, { "name": "Parameter_Description_29", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The number of days' warning given before a password expires.", + "value": "Maximum age of password in days", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_29", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'0': '0', 14: 14, 10: 10, 7: 7, 'default': 7}", + "value": "{365: 365, 120: 120, 180: 180, 90: 90, 60: 60, 45: 45, 'default': 60}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_30", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_passwords_pam_faillock_deny", + "value": "var_accounts_password_warn_age_login_defs", "remarks": "rule_set_000" }, { "name": "Parameter_Description_30", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Number of failed login attempts before account lockout", + "value": "The number of days' warning given before a password expires.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_30", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{10: 10, 3: 3, 4: 4, 5: 5, 6: 6, 8: 8, 'default': 3}", + "value": "{'0': '0', 14: 14, 10: 10, 7: 7, 'default': 7}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_31", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_passwords_pam_faillock_unlock_time", + "value": "var_accounts_passwords_pam_faillock_deny", "remarks": "rule_set_000" }, { "name": "Parameter_Description_31", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Seconds before automatic unlocking or permanently locking after excessive failed logins", + "value": "Number of failed login attempts before account lockout", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_31", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{1800: 1800, 3600: 3600, 600: 600, 604800: 604800, 86400: 86400, 900: 900, 300: 300, 'default': 0, 'never': 0}", + "value": "{10: 10, 3: 3, 4: 4, 5: 5, 6: 6, 8: 8, 'default': 3}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_32", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_tmout", + "value": "var_accounts_passwords_pam_faillock_unlock_time", "remarks": "rule_set_000" }, { "name": "Parameter_Description_32", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "In an interactive shell, the value is interpreted as the number of seconds to wait for input after issuing the primary prompt. Bash terminates after waiting for that number of seconds if input does not arrive.", + "value": "Seconds before automatic unlocking or permanently locking after excessive failed logins", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_32", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'30_min': 1800, '10_min': 600, '15_min': 900, '5_min': 300, 'default': 600}", + "value": "{1800: 1800, 3600: 3600, 600: 600, 604800: 604800, 86400: 86400, 900: 900, 300: 300, 'default': 0, 'never': 0}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_33", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_user_umask", + "value": "var_accounts_tmout", "remarks": "rule_set_000" }, { "name": "Parameter_Description_33", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enter default user umask", + "value": "In an interactive shell, the value is interpreted as the number of seconds to wait for input after issuing the primary prompt. Bash terminates after waiting for that number of seconds if input does not arrive.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_33", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'007': '007', '022': '022', '027': '027', '077': '077', 'default': '027'}", + "value": "{'30_min': 1800, '10_min': 600, '15_min': 900, '5_min': 300, 'default': 600}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_34", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_authselect_profile", + "value": "var_accounts_user_umask", "remarks": "rule_set_000" }, { "name": "Parameter_Description_34", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the authselect profile to select", + "value": "Enter default user umask", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_34", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'local': 'local', 'default': 'minimal', 'minimal': 'minimal', 'sssd': 'sssd'}", + "value": "{'007': '007', '022': '022', '027': '027', '077': '077', 'default': '027'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_35", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_multiple_time_servers", + "value": "var_authselect_profile", "remarks": "rule_set_000" }, { "name": "Parameter_Description_35", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The list of vendor-approved time servers", + "value": "Specify the authselect profile to select", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_35", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'generic': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'stig': '0.us.pool.ntp.mil', 'fedora': '0.fedora.pool.ntp.org,1.fedora.pool.ntp.org,2.fedora.pool.ntp.org,3.fedora.pool.ntp.org', 'rhel': '0.rhel.pool.ntp.org,1.rhel.pool.ntp.org,2.rhel.pool.ntp.org,3.rhel.pool.ntp.org', 'ol': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'suse': '0.suse.pool.ntp.org,1.suse.pool.ntp.org,2.suse.pool.ntp.org,3.suse.pool.ntp.org', 'alinux': '0.ntp.cloud.aliyuncs.com,1.ntp.aliyun.com,2.ntp1.aliyun.com,3.ntp1.cloud.aliyuncs.com', 'amazon': '0.rhel.pool.ntp.org,1.rhel.pool.ntp.org,2.rhel.pool.ntp.org,3.rhel.pool.ntp.org', 'ubuntu': '0.ubuntu.pool.ntp.org,1.ubuntu.pool.ntp.org,2.ubuntu.pool.ntp.org,3.ubuntu.pool.ntp.org', 'almalinux': '0.almalinux.pool.ntp.org,1.almalinux.pool.ntp.org,2.almalinux.pool.ntp.org,3.almalinux.pool.ntp.org', 'debian': '0.debian.pool.ntp.org,1.debian.pool.ntp.org,2.debian.pool.ntp.org,3.debian.pool.ntp.org', 'nist': 'time.nist.gov,time-a-g.nist.gov,time-b-g.nist.gov,time-c-g.nist.gov'}", + "value": "{'local': 'local', 'default': 'minimal', 'minimal': 'minimal', 'sssd': 'sssd'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_36", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_pam_wheel_group_for_su", + "value": "var_multiple_time_servers", "remarks": "rule_set_000" }, { "name": "Parameter_Description_36", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "pam_wheel module has a parameter called group, which controls which groups can access the su command. This variable holds the valid value for the parameter.", + "value": "The list of vendor-approved time servers", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_36", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'sugroup', 'cis': 'sugroup'}", + "value": "{'default': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'generic': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'stig': '0.us.pool.ntp.mil', 'fedora': '0.fedora.pool.ntp.org,1.fedora.pool.ntp.org,2.fedora.pool.ntp.org,3.fedora.pool.ntp.org', 'rhel': '0.rhel.pool.ntp.org,1.rhel.pool.ntp.org,2.rhel.pool.ntp.org,3.rhel.pool.ntp.org', 'ol': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'suse': '0.suse.pool.ntp.org,1.suse.pool.ntp.org,2.suse.pool.ntp.org,3.suse.pool.ntp.org', 'alinux': '0.ntp.cloud.aliyuncs.com,1.ntp.aliyun.com,2.ntp1.aliyun.com,3.ntp1.cloud.aliyuncs.com', 'amazon': '0.rhel.pool.ntp.org,1.rhel.pool.ntp.org,2.rhel.pool.ntp.org,3.rhel.pool.ntp.org', 'ubuntu': '0.ubuntu.pool.ntp.org,1.ubuntu.pool.ntp.org,2.ubuntu.pool.ntp.org,3.ubuntu.pool.ntp.org', 'almalinux': '0.almalinux.pool.ntp.org,1.almalinux.pool.ntp.org,2.almalinux.pool.ntp.org,3.almalinux.pool.ntp.org', 'debian': '0.debian.pool.ntp.org,1.debian.pool.ntp.org,2.debian.pool.ntp.org,3.debian.pool.ntp.org', 'nist': 'time.nist.gov,time-a-g.nist.gov,time-b-g.nist.gov,time-c-g.nist.gov'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_hashing_algorithm", + "value": "var_pam_wheel_group_for_su", "remarks": "rule_set_000" }, { "name": "Parameter_Description_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the system default encryption algorithm for encrypting passwords. Defines the value set as ENCRYPT_METHOD in /etc/login.defs.", + "value": "pam_wheel module has a parameter called group, which controls which groups can access the su command. This variable holds the valid value for the parameter.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'SHA512', 'SHA512': 'SHA512', 'SHA256': 'SHA256', 'yescrypt': 'YESCRYPT', 'cis_ubuntu2404': 'SHA512|YESCRYPT'}", + "value": "{'default': 'sugroup', 'cis': 'sugroup'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_hashing_algorithm_pam", + "value": "var_password_hashing_algorithm", "remarks": "rule_set_000" }, { "name": "Parameter_Description_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the system default encryption algorithm for encrypting passwords. Defines the hashing algorithm to be used in pam_unix.so.", + "value": "Specify the system default encryption algorithm for encrypting passwords. Defines the value set as ENCRYPT_METHOD in /etc/login.defs.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'sha512', 'sha512': 'sha512', 'yescrypt': 'yescrypt'}", + "value": "{'default': 'SHA512', 'SHA512': 'SHA512', 'SHA256': 'SHA256', 'yescrypt': 'YESCRYPT', 'cis_ubuntu2404': 'SHA512|YESCRYPT'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_dictcheck", + "value": "var_password_hashing_algorithm_pam", "remarks": "rule_set_000" }, { "name": "Parameter_Description_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Prevent the use of dictionary words for passwords.", + "value": "Specify the system default encryption algorithm for encrypting passwords. Defines the hashing algorithm to be used in pam_unix.so.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{1: 1, 'default': 1}", + "value": "{'default': 'sha512', 'sha512': 'sha512', 'yescrypt': 'yescrypt'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_40", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_difok", + "value": "var_password_pam_dictcheck", "remarks": "rule_set_000" }, { "name": "Parameter_Description_40", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Minimum number of characters not present in old password", + "value": "Prevent the use of dictionary words for passwords.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_40", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{15: 15, 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 8: 8, 'default': 8}", + "value": "{1: 1, 'default': 1}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_41", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_maxrepeat", + "value": "var_password_pam_difok", "remarks": "rule_set_000" }, { "name": "Parameter_Description_41", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Maximum Number of Consecutive Repeating Characters in a Password", + "value": "Minimum number of characters not present in old password", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_41", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{1: 1, 2: 2, 3: 3, 'default': 3}", + "value": "{15: 15, 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 8: 8, 'default': 8}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_42", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_minclass", + "value": "var_password_pam_maxrepeat", "remarks": "rule_set_000" }, { "name": "Parameter_Description_42", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Minimum number of categories of characters that must exist in a password", + "value": "Maximum Number of Consecutive Repeating Characters in a Password", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_42", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{1: 1, 2: 2, 3: 3, 4: 4, 'default': 3}", + "value": "{1: 1, 2: 2, 3: 3, 'default': 3}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_43", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_minlen", + "value": "var_password_pam_minclass", "remarks": "rule_set_000" }, { "name": "Parameter_Description_43", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Minimum number of characters in password", + "value": "Minimum number of categories of characters that must exist in a password", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_43", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{10: 10, 12: 12, 14: 14, 15: 15, 17: 17, 18: 18, 20: 20, 6: 6, 7: 7, 8: 8, 'default': 15}", + "value": "{1: 1, 2: 2, 3: 3, 4: 4, 'default': 3}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_44", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_remember", + "value": "var_password_pam_minlen", "remarks": "rule_set_000" }, { "name": "Parameter_Description_44", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Prevent password re-use using password history lookup", + "value": "Minimum number of characters in password", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_44", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'0': '0', 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 8: 8, 9: 9, 24: 24, 'default': 5}", + "value": "{10: 10, 12: 12, 14: 14, 15: 15, 17: 17, 18: 18, 20: 20, 6: 6, 7: 7, 8: 8, 'default': 15}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_45", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_remember_control_flag", + "value": "var_password_pam_remember", "remarks": "rule_set_000" }, { "name": "Parameter_Description_45", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "'Specify the control flag required for password remember requirement. If multiple values are allowed write them separated by commas as in \"required,requisite\", for remediations the first value will be taken'", + "value": "Prevent password re-use using password history lookup", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_45", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'required': 'required', 'optional': 'optional', 'requisite': 'requisite', 'sufficient': 'sufficient', 'binding': 'binding', 'ol8': 'required,requisite', 'requisite_or_required': 'requisite,required', 'default': 'requisite'}", + "value": "{'0': '0', 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 8: 8, 9: 9, 24: 24, 'default': 5}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_46", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_postfix_inet_interfaces", + "value": "var_password_pam_remember_control_flag", "remarks": "rule_set_000" }, { "name": "Parameter_Description_46", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The setting for inet_interfaces in /etc/postfix/main.cf", + "value": "'Specify the control flag required for password remember requirement. If multiple values are allowed write them separated by commas as in \"required,requisite\", for remediations the first value will be taken'", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_46", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'loopback-only': 'loopback-only', 'default': 'loopback-only', 'localhost': 'localhost'}", + "value": "{'required': 'required', 'optional': 'optional', 'requisite': 'requisite', 'sufficient': 'sufficient', 'binding': 'binding', 'ol8': 'required,requisite', 'requisite_or_required': 'requisite,required', 'default': 'requisite'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_47", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_screensaver_lock_delay", + "value": "var_postfix_inet_interfaces", "remarks": "rule_set_000" }, { "name": "Parameter_Description_47", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Choose allowed duration (in seconds) after a screensaver becomes active before displaying an authentication prompt", + "value": "The setting for inet_interfaces in /etc/postfix/main.cf", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_47", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'10_seconds': 10, '5_seconds': 5, 'default': '0', 'immediate': '0'}", + "value": "{'loopback-only': 'loopback-only', 'default': 'loopback-only', 'localhost': 'localhost'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_48", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_selinux_policy_name", + "value": "var_screensaver_lock_delay", "remarks": "rule_set_000" }, { "name": "Parameter_Description_48", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Type of policy in use. Possible values are:
targeted - Only targeted network daemons are protected.
strict - Full SELinux protection.
mls - Multiple levels of security", + "value": "Choose allowed duration (in seconds) after a screensaver becomes active before displaying an authentication prompt", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_48", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'targeted', 'mls': 'mls', 'targeted': 'targeted'}", + "value": "{'10_seconds': 10, '5_seconds': 5, 'default': '0', 'immediate': '0'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_49", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_sshd_max_sessions", + "value": "var_selinux_policy_name", "remarks": "rule_set_000" }, { "name": "Parameter_Description_49", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the maximum number of open sessions permitted.", + "value": "Type of policy in use. Possible values are:
targeted - Only targeted network daemons are protected.
strict - Full SELinux protection.
mls - Multiple levels of security", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_49", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{10: 10, 4: 4, 3: 3, 2: 2, 1: 1, 0: 0, 'default': 10}", + "value": "{'default': 'targeted', 'mls': 'mls', 'targeted': 'targeted'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_50", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_sshd_set_keepalive", + "value": "var_sshd_max_sessions", "remarks": "rule_set_000" }, { "name": "Parameter_Description_50", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the maximum number of idle message counts before session is terminated.", + "value": "Specify the maximum number of open sessions permitted.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_50", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{10: 10, 3: 3, 5: 5, 0: 0, 1: 1, 'default': 0}", + "value": "{10: 10, 4: 4, 3: 3, 2: 2, 1: 1, 0: 0, 'default': 10}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_51", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_sshd_set_login_grace_time", + "value": "var_sshd_set_keepalive", "remarks": "rule_set_000" }, { "name": "Parameter_Description_51", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure parameters for how long the servers stays connected before the user has successfully logged in", + "value": "Specify the maximum number of idle message counts before session is terminated.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_51", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 60, 60: 60}", + "value": "{10: 10, 3: 3, 5: 5, 0: 0, 1: 1, 'default': 0}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_52", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_sshd_set_maxstartups", + "value": "var_sshd_set_login_grace_time", "remarks": "rule_set_000" }, { "name": "Parameter_Description_52", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure parameters for maximum concurrent unauthenticated connections to the SSH daemon.", + "value": "Configure parameters for how long the servers stays connected before the user has successfully logged in", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_52", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': '10:30:100', '10:30:60': '10:30:60'}", + "value": "{'default': 60, 60: 60}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_53", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_system_crypto_policy", + "value": "var_sshd_set_maxstartups", "remarks": "rule_set_000" }, { "name": "Parameter_Description_53", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the crypto policy for the system.", + "value": "Configure parameters for maximum concurrent unauthenticated connections to the SSH daemon.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_53", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': '10:30:100', '10:30:60': '10:30:60'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_54", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_user_initialization_files_regex", + "value": "var_system_crypto_policy", "remarks": "rule_set_000" }, { "name": "Parameter_Description_54", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "'A regular expression describing a list of file names for files that are sourced at login time for interactive users'", + "value": "Specify the crypto policy for the system.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_54", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Id_55", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "var_user_initialization_files_regex", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Description_55", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "'A regular expression describing a list of file names for files that are sourced at login time for interactive users'", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Value_Alternatives_55", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'default': '^(\\\\.bashrc|\\\\.zshrc|\\\\.cshrc|\\\\.profile|\\\\.bash_login|\\\\.bash_profile)$', 'all_dotfiles': '^\\\\.[\\\\w\\\\- ]+$'}", "remarks": "rule_set_000" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_tmp", + "value": "kernel_module_cramfs_disabled", "remarks": "rule_set_001" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /tmp Located On Separate Partition", + "value": "Disable Mounting of cramfs", "remarks": "rule_set_001" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_nodev", + "value": "kernel_module_freevxfs_disabled", "remarks": "rule_set_002" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /tmp", + "value": "Disable Mounting of freevxfs", "remarks": "rule_set_002" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_nosuid", + "value": "kernel_module_hfs_disabled", "remarks": "rule_set_003" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /tmp", + "value": "Disable Mounting of hfs", "remarks": "rule_set_003" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_noexec", + "value": "kernel_module_hfsplus_disabled", "remarks": "rule_set_004" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /tmp", + "value": "Disable Mounting of hfsplus", "remarks": "rule_set_004" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_dev_shm", + "value": "kernel_module_jffs2_disabled", "remarks": "rule_set_005" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /dev/shm is configured", + "value": "Disable Mounting of jffs2", "remarks": "rule_set_005" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_nodev", + "value": "partition_for_tmp", "remarks": "rule_set_006" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /dev/shm", + "value": "Ensure /tmp Located On Separate Partition", "remarks": "rule_set_006" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_nosuid", + "value": "mount_option_tmp_nodev", "remarks": "rule_set_007" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /dev/shm", + "value": "Add nodev Option to /tmp", "remarks": "rule_set_007" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_noexec", + "value": "mount_option_tmp_nosuid", "remarks": "rule_set_008" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /dev/shm", + "value": "Add nosuid Option to /tmp", "remarks": "rule_set_008" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_home_nodev", + "value": "mount_option_tmp_noexec", "remarks": "rule_set_009" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /home", + "value": "Add noexec Option to /tmp", "remarks": "rule_set_009" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_home_nosuid", + "value": "partition_for_dev_shm", "remarks": "rule_set_010" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /home", + "value": "Ensure /dev/shm is configured", "remarks": "rule_set_010" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_nodev", + "value": "mount_option_dev_shm_nodev", "remarks": "rule_set_011" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /var", + "value": "Add nodev Option to /dev/shm", "remarks": "rule_set_011" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_nosuid", + "value": "mount_option_dev_shm_nosuid", "remarks": "rule_set_012" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /var", + "value": "Add nosuid Option to /dev/shm", "remarks": "rule_set_012" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_tmp_nodev", + "value": "mount_option_dev_shm_noexec", "remarks": "rule_set_013" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /var/tmp", + "value": "Add noexec Option to /dev/shm", "remarks": "rule_set_013" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_tmp_nosuid", + "value": "mount_option_home_nodev", "remarks": "rule_set_014" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /var/tmp", + "value": "Add nodev Option to /home", "remarks": "rule_set_014" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_tmp_noexec", + "value": "mount_option_home_nosuid", "remarks": "rule_set_015" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /var/tmp", + "value": "Add nosuid Option to /home", "remarks": "rule_set_015" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_nodev", + "value": "mount_option_var_nodev", "remarks": "rule_set_016" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /var/log", + "value": "Add nodev Option to /var", "remarks": "rule_set_016" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_nosuid", + "value": "mount_option_var_nosuid", "remarks": "rule_set_017" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /var/log", + "value": "Add nosuid Option to /var", "remarks": "rule_set_017" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_noexec", + "value": "mount_option_var_tmp_nodev", "remarks": "rule_set_018" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /var/log", + "value": "Add nodev Option to /var/tmp", "remarks": "rule_set_018" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_audit_nodev", + "value": "mount_option_var_tmp_nosuid", "remarks": "rule_set_019" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /var/log/audit", + "value": "Add nosuid Option to /var/tmp", "remarks": "rule_set_019" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_audit_nosuid", + "value": "mount_option_var_tmp_noexec", "remarks": "rule_set_020" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /var/log/audit", + "value": "Add noexec Option to /var/tmp", "remarks": "rule_set_020" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_audit_noexec", + "value": "mount_option_var_log_nodev", "remarks": "rule_set_021" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /var/log/audit", + "value": "Add nodev Option to /var/log", "remarks": "rule_set_021" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_gpgcheck_globally_activated", + "value": "mount_option_var_log_nosuid", "remarks": "rule_set_022" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure gpgcheck Enabled In Main dnf Configuration", + "value": "Add nosuid Option to /var/log", "remarks": "rule_set_022" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_libselinux_installed", + "value": "mount_option_var_log_noexec", "remarks": "rule_set_023" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install libselinux Package", + "value": "Add noexec Option to /var/log", "remarks": "rule_set_023" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "grub2_enable_selinux", + "value": "mount_option_var_log_audit_nodev", "remarks": "rule_set_024" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure SELinux Not Disabled in /etc/default/grub", + "value": "Add nodev Option to /var/log/audit", "remarks": "rule_set_024" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "selinux_policytype", + "value": "mount_option_var_log_audit_nosuid", "remarks": "rule_set_025" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure SELinux Policy", + "value": "Add nosuid Option to /var/log/audit", "remarks": "rule_set_025" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "selinux_not_disabled", + "value": "mount_option_var_log_audit_noexec", "remarks": "rule_set_026" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure SELinux is Not Disabled", + "value": "Add noexec Option to /var/log/audit", "remarks": "rule_set_026" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_mcstrans_removed", + "value": "ensure_gpgcheck_globally_activated", "remarks": "rule_set_027" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall mcstrans Package", + "value": "Ensure gpgcheck Enabled In Main dnf Configuration", "remarks": "rule_set_027" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "grub2_password", + "value": "package_libselinux_installed", "remarks": "rule_set_028" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Boot Loader Password in grub2", + "value": "Install libselinux Package", "remarks": "rule_set_028" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_grub2_cfg", + "value": "grub2_enable_selinux", "remarks": "rule_set_029" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/grub.cfg Group Ownership", + "value": "Ensure SELinux Not Disabled in /etc/default/grub", "remarks": "rule_set_029" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_grub2_cfg", + "value": "selinux_policytype", "remarks": "rule_set_030" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/grub.cfg User Ownership", + "value": "Configure SELinux Policy", "remarks": "rule_set_030" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_grub2_cfg", + "value": "selinux_not_disabled", "remarks": "rule_set_031" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/grub.cfg Permissions", + "value": "Ensure SELinux is Not Disabled", "remarks": "rule_set_031" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_user_cfg", + "value": "package_mcstrans_removed", "remarks": "rule_set_032" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/user.cfg Group Ownership", + "value": "Uninstall mcstrans Package", "remarks": "rule_set_032" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_user_cfg", + "value": "grub2_password", "remarks": "rule_set_033" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/user.cfg User Ownership", + "value": "Set Boot Loader Password in grub2", "remarks": "rule_set_033" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_user_cfg", + "value": "file_groupowner_grub2_cfg", "remarks": "rule_set_034" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/user.cfg Permissions", + "value": "Verify /boot/grub2/grub.cfg Group Ownership", "remarks": "rule_set_034" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_kernel_randomize_va_space", + "value": "file_owner_grub2_cfg", "remarks": "rule_set_035" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Randomized Layout of Virtual Address Space", + "value": "Verify /boot/grub2/grub.cfg User Ownership", "remarks": "rule_set_035" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_kernel_yama_ptrace_scope", + "value": "file_permissions_grub2_cfg", "remarks": "rule_set_036" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Restrict usage of ptrace to descendant processes", + "value": "Verify /boot/grub2/grub.cfg Permissions", "remarks": "rule_set_036" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_backtraces", + "value": "file_groupowner_user_cfg", "remarks": "rule_set_037" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable core dump backtraces", + "value": "Verify /boot/grub2/user.cfg Group Ownership", "remarks": "rule_set_037" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_storage", + "value": "file_owner_user_cfg", "remarks": "rule_set_038" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable storing core dump", + "value": "Verify /boot/grub2/user.cfg User Ownership", "remarks": "rule_set_038" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_crypto_policy", + "value": "file_permissions_user_cfg", "remarks": "rule_set_039" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure System Cryptography Policy", + "value": "Verify /boot/grub2/user.cfg Permissions", "remarks": "rule_set_039" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_ssh_crypto_policy", + "value": "disable_users_coredumps", "remarks": "rule_set_040" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure SSH to use System Crypto Policy", + "value": "Disable Core Dumps for All Users", "remarks": "rule_set_040" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "banner_etc_motd_cis", + "value": "sysctl_fs_protected_hardlinks", "remarks": "rule_set_041" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Message Of The Day Is Configured Properly", + "value": "Enable Kernel Parameter to Enforce DAC on Hardlinks", "remarks": "rule_set_041" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "banner_etc_issue_cis", + "value": "sysctl_fs_suid_dumpable", "remarks": "rule_set_042" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Local Login Warning Banner Is Configured Properly", + "value": "Disable Core Dumps for SUID programs", "remarks": "rule_set_042" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "banner_etc_issue_net_cis", + "value": "sysctl_kernel_dmesg_restrict", "remarks": "rule_set_043" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Remote Login Warning Banner Is Configured Properly", + "value": "Restrict Access to Kernel Message Buffer", "remarks": "rule_set_043" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_motd", + "value": "sysctl_kernel_kptr_restrict", "remarks": "rule_set_044" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Ownership of Message of the Day Banner", + "value": "Restrict Exposed Kernel Pointer Addresses Access", "remarks": "rule_set_044" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_motd", + "value": "sysctl_kernel_yama_ptrace_scope", "remarks": "rule_set_045" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify ownership of Message of the Day Banner", + "value": "Restrict usage of ptrace to descendant processes", "remarks": "rule_set_045" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_motd", + "value": "sysctl_kernel_randomize_va_space", "remarks": "rule_set_046" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify permissions on Message of the Day Banner", + "value": "Enable Randomized Layout of Virtual Address Space", "remarks": "rule_set_046" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_issue", + "value": "coredump_disable_backtraces", "remarks": "rule_set_047" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Ownership of System Login Banner", + "value": "Disable core dump backtraces", "remarks": "rule_set_047" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_issue", + "value": "coredump_disable_storage", "remarks": "rule_set_048" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify ownership of System Login Banner", + "value": "Disable storing core dump", "remarks": "rule_set_048" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_issue", + "value": "configure_crypto_policy", "remarks": "rule_set_049" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify permissions on System Login Banner", + "value": "Configure System Cryptography Policy", "remarks": "rule_set_049" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_issue_net", + "value": "banner_etc_motd_cis", "remarks": "rule_set_050" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Ownership of System Login Banner for Remote Connections", + "value": "Ensure Message Of The Day Is Configured Properly", "remarks": "rule_set_050" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_issue_net", + "value": "banner_etc_issue_cis", "remarks": "rule_set_051" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify ownership of System Login Banner for Remote Connections", + "value": "Ensure Local Login Warning Banner Is Configured Properly", "remarks": "rule_set_051" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_issue_net", + "value": "banner_etc_issue_net_cis", "remarks": "rule_set_052" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify permissions on System Login Banner for Remote Connections", + "value": "Ensure Remote Login Warning Banner Is Configured Properly", "remarks": "rule_set_052" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_banner_enabled", + "value": "file_groupowner_etc_motd", "remarks": "rule_set_053" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable GNOME3 Login Warning Banner", + "value": "Verify Group Ownership of Message of the Day Banner", "remarks": "rule_set_053" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_login_banner_text", + "value": "file_owner_etc_motd", "remarks": "rule_set_054" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set the GNOME3 Login Warning Banner Text", + "value": "Verify ownership of Message of the Day Banner", "remarks": "rule_set_054" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_user_list", + "value": "file_permissions_etc_motd", "remarks": "rule_set_055" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable the GNOME3 Login User List", + "value": "Verify permissions on Message of the Day Banner", "remarks": "rule_set_055" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_screensaver_idle_delay", + "value": "file_groupowner_etc_issue", "remarks": "rule_set_056" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set GNOME3 Screensaver Inactivity Timeout", + "value": "Verify Group Ownership of System Login Banner", "remarks": "rule_set_056" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_screensaver_lock_delay", + "value": "file_owner_etc_issue", "remarks": "rule_set_057" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set GNOME3 Screensaver Lock Delay After Activation Period", + "value": "Verify ownership of System Login Banner", "remarks": "rule_set_057" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_session_idle_user_locks", + "value": "file_permissions_etc_issue", "remarks": "rule_set_058" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Users Cannot Change GNOME3 Session Idle Settings", + "value": "Verify permissions on System Login Banner", "remarks": "rule_set_058" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_screensaver_user_locks", + "value": "file_groupowner_etc_issue_net", "remarks": "rule_set_059" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Users Cannot Change GNOME3 Screensaver Settings", + "value": "Verify Group Ownership of System Login Banner for Remote Connections", "remarks": "rule_set_059" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_autorun", + "value": "file_owner_etc_issue_net", "remarks": "rule_set_060" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable GNOME3 Automount running", + "value": "Verify ownership of System Login Banner for Remote Connections", "remarks": "rule_set_060" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_kea_removed", + "value": "file_permissions_etc_issue_net", "remarks": "rule_set_061" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall kea Package", + "value": "Verify permissions on System Login Banner for Remote Connections", "remarks": "rule_set_061" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_bind_removed", + "value": "dconf_gnome_banner_enabled", "remarks": "rule_set_062" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall bind Package", + "value": "Enable GNOME3 Login Warning Banner", "remarks": "rule_set_062" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_dnsmasq_removed", + "value": "dconf_gnome_login_banner_text", "remarks": "rule_set_063" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall dnsmasq Package", + "value": "Set the GNOME3 Login Warning Banner Text", "remarks": "rule_set_063" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_samba_removed", + "value": "dconf_gnome_disable_user_list", "remarks": "rule_set_064" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall Samba Package", + "value": "Disable the GNOME3 Login User List", "remarks": "rule_set_064" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_vsftpd_removed", + "value": "dconf_gnome_screensaver_idle_delay", "remarks": "rule_set_065" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall vsftpd Package", + "value": "Set GNOME3 Screensaver Inactivity Timeout", "remarks": "rule_set_065" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_dovecot_removed", + "value": "dconf_gnome_screensaver_lock_delay", "remarks": "rule_set_066" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall dovecot Package", + "value": "Set GNOME3 Screensaver Lock Delay After Activation Period", "remarks": "rule_set_066" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_cyrus-imapd_removed", + "value": "dconf_gnome_session_idle_user_locks", "remarks": "rule_set_067" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall cyrus-imapd Package", + "value": "Ensure Users Cannot Change GNOME3 Session Idle Settings", "remarks": "rule_set_067" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_nfs_disabled", + "value": "dconf_gnome_screensaver_user_locks", "remarks": "rule_set_068" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Network File System (nfs)", + "value": "Ensure Users Cannot Change GNOME3 Screensaver Settings", "remarks": "rule_set_068" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_rpcbind_disabled", + "value": "dconf_gnome_disable_autorun", "remarks": "rule_set_069" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable rpcbind Service", + "value": "Disable GNOME3 Automount running", "remarks": "rule_set_069" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_rsync_removed", + "value": "package_kea_removed", "remarks": "rule_set_070" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall rsync Package", + "value": "Uninstall kea Package", "remarks": "rule_set_070" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_net-snmp_removed", + "value": "package_bind_removed", "remarks": "rule_set_071" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall net-snmp Package", + "value": "Uninstall bind Package", "remarks": "rule_set_071" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_telnet-server_removed", + "value": "package_dnsmasq_removed", "remarks": "rule_set_072" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall telnet-server Package", + "value": "Uninstall dnsmasq Package", "remarks": "rule_set_072" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_tftp-server_removed", + "value": "package_vsftpd_removed", "remarks": "rule_set_073" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall tftp-server Package", + "value": "Uninstall vsftpd Package", "remarks": "rule_set_073" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_squid_removed", + "value": "package_dovecot_removed", "remarks": "rule_set_074" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall squid Package", + "value": "Uninstall dovecot Package", "remarks": "rule_set_074" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_httpd_removed", + "value": "package_cyrus-imapd_removed", "remarks": "rule_set_075" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall httpd Package", + "value": "Uninstall cyrus-imapd Package", "remarks": "rule_set_075" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_nginx_removed", + "value": "service_nfs_disabled", "remarks": "rule_set_076" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall nginx Package", + "value": "Disable Network File System (nfs)", "remarks": "rule_set_076" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "postfix_network_listening_disabled", + "value": "service_rpcbind_disabled", "remarks": "rule_set_077" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Postfix Network Listening", + "value": "Disable rpcbind Service", "remarks": "rule_set_077" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "has_nonlocal_mta", + "value": "package_rsync_removed", "remarks": "rule_set_078" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Mail Transfer Agent is not Listening on any non-loopback Address", + "value": "Uninstall rsync Package", "remarks": "rule_set_078" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_ftp_removed", + "value": "package_samba_removed", "remarks": "rule_set_079" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Remove ftp Package", + "value": "Uninstall Samba Package", "remarks": "rule_set_079" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_telnet_removed", + "value": "package_net-snmp_removed", "remarks": "rule_set_080" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Remove telnet Clients", + "value": "Uninstall net-snmp Package", "remarks": "rule_set_080" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_tftp_removed", + "value": "package_telnet-server_removed", "remarks": "rule_set_081" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Remove tftp Daemon", + "value": "Uninstall telnet-server Package", "remarks": "rule_set_081" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "chronyd_specify_remote_server", + "value": "package_tftp-server_removed", "remarks": "rule_set_082" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "A remote time server for Chrony is configured", + "value": "Uninstall tftp-server Package", "remarks": "rule_set_082" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "chronyd_run_as_chrony_user", + "value": "package_squid_removed", "remarks": "rule_set_083" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that chronyd is running under chrony user account", + "value": "Uninstall squid Package", "remarks": "rule_set_083" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_cron_installed", + "value": "package_httpd_removed", "remarks": "rule_set_084" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install the cron service", + "value": "Uninstall httpd Package", "remarks": "rule_set_084" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_crond_enabled", + "value": "package_nginx_removed", "remarks": "rule_set_085" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable cron Service", + "value": "Uninstall nginx Package", "remarks": "rule_set_085" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_crontab", + "value": "postfix_network_listening_disabled", "remarks": "rule_set_086" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns Crontab", + "value": "Disable Postfix Network Listening", "remarks": "rule_set_086" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_crontab", + "value": "has_nonlocal_mta", "remarks": "rule_set_087" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on crontab", + "value": "Ensure Mail Transfer Agent is not Listening on any non-loopback Address", "remarks": "rule_set_087" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_crontab", + "value": "package_ftp_removed", "remarks": "rule_set_088" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on crontab", + "value": "Remove ftp Package", "remarks": "rule_set_088" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_hourly", + "value": "package_telnet_removed", "remarks": "rule_set_089" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns cron.hourly", + "value": "Remove telnet Clients", "remarks": "rule_set_089" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_hourly", + "value": "package_tftp_removed", "remarks": "rule_set_090" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on cron.hourly", + "value": "Remove tftp Daemon", "remarks": "rule_set_090" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_hourly", + "value": "chronyd_specify_remote_server", "remarks": "rule_set_091" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on cron.hourly", + "value": "A remote time server for Chrony is configured", "remarks": "rule_set_091" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_daily", + "value": "chronyd_run_as_chrony_user", "remarks": "rule_set_092" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns cron.daily", + "value": "Ensure that chronyd is running under chrony user account", "remarks": "rule_set_092" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_daily", + "value": "package_cron_installed", "remarks": "rule_set_093" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on cron.daily", + "value": "Install the cron service", "remarks": "rule_set_093" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_daily", + "value": "service_crond_enabled", "remarks": "rule_set_094" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on cron.daily", + "value": "Enable cron Service", "remarks": "rule_set_094" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_weekly", + "value": "file_groupowner_crontab", "remarks": "rule_set_095" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns cron.weekly", + "value": "Verify Group Who Owns Crontab", "remarks": "rule_set_095" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_weekly", + "value": "file_owner_crontab", "remarks": "rule_set_096" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on cron.weekly", + "value": "Verify Owner on crontab", "remarks": "rule_set_096" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_weekly", + "value": "file_permissions_crontab", "remarks": "rule_set_097" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on cron.weekly", + "value": "Verify Permissions on crontab", "remarks": "rule_set_097" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_monthly", + "value": "file_groupowner_cron_hourly", "remarks": "rule_set_098" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns cron.monthly", + "value": "Verify Group Who Owns cron.hourly", "remarks": "rule_set_098" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_monthly", + "value": "file_owner_cron_hourly", "remarks": "rule_set_099" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on cron.monthly", + "value": "Verify Owner on cron.hourly", "remarks": "rule_set_099" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_monthly", + "value": "file_permissions_cron_hourly", "remarks": "rule_set_100" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on cron.monthly", + "value": "Verify Permissions on cron.hourly", "remarks": "rule_set_100" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_d", + "value": "file_groupowner_cron_daily", "remarks": "rule_set_101" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns cron.d", + "value": "Verify Group Who Owns cron.daily", "remarks": "rule_set_101" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_d", + "value": "file_owner_cron_daily", "remarks": "rule_set_102" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on cron.d", + "value": "Verify Owner on cron.daily", "remarks": "rule_set_102" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_d", + "value": "file_permissions_cron_daily", "remarks": "rule_set_103" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on cron.d", + "value": "Verify Permissions on cron.daily", "remarks": "rule_set_103" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_cron_deny_not_exist", + "value": "file_groupowner_cron_weekly", "remarks": "rule_set_104" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that /etc/cron.deny does not exist", + "value": "Verify Group Who Owns cron.weekly", "remarks": "rule_set_104" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_cron_allow_exists", + "value": "file_owner_cron_weekly", "remarks": "rule_set_105" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that /etc/cron.allow exists", + "value": "Verify Owner on cron.weekly", "remarks": "rule_set_105" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_allow", + "value": "file_permissions_cron_weekly", "remarks": "rule_set_106" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns /etc/cron.allow file", + "value": "Verify Permissions on cron.weekly", "remarks": "rule_set_106" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_allow", + "value": "file_groupowner_cron_monthly", "remarks": "rule_set_107" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns /etc/cron.allow file", + "value": "Verify Group Who Owns cron.monthly", "remarks": "rule_set_107" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_allow", + "value": "file_owner_cron_monthly", "remarks": "rule_set_108" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on /etc/cron.allow file", + "value": "Verify Owner on cron.monthly", "remarks": "rule_set_108" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_at_deny_not_exist", + "value": "file_permissions_cron_monthly", "remarks": "rule_set_109" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that /etc/at.deny does not exist", + "value": "Verify Permissions on cron.monthly", "remarks": "rule_set_109" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_at_allow", + "value": "file_groupowner_cron_d", "remarks": "rule_set_110" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns /etc/at.allow file", + "value": "Verify Group Who Owns cron.d", "remarks": "rule_set_110" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_at_allow", + "value": "file_owner_cron_d", "remarks": "rule_set_111" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns /etc/at.allow file", + "value": "Verify Owner on cron.d", "remarks": "rule_set_111" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_at_allow", + "value": "file_permissions_cron_d", "remarks": "rule_set_112" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on /etc/at.allow file", + "value": "Verify Permissions on cron.d", "remarks": "rule_set_112" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_ip_forward", + "value": "file_cron_deny_not_exist", "remarks": "rule_set_113" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for IP Forwarding on IPv4 Interfaces", + "value": "Ensure that /etc/cron.deny does not exist", "remarks": "rule_set_113" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_forwarding", + "value": "file_cron_allow_exists", "remarks": "rule_set_114" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for IPv6 Forwarding", + "value": "Ensure that /etc/cron.allow exists", "remarks": "rule_set_114" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_send_redirects", + "value": "file_groupowner_cron_allow", "remarks": "rule_set_115" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces", + "value": "Verify Group Who Owns /etc/cron.allow file", "remarks": "rule_set_115" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_send_redirects", + "value": "file_owner_cron_allow", "remarks": "rule_set_116" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces by Default", + "value": "Verify User Who Owns /etc/cron.allow file", "remarks": "rule_set_116" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses", + "value": "file_permissions_cron_allow", "remarks": "rule_set_117" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Ignore Bogus ICMP Error Responses on IPv4 Interfaces", + "value": "Verify Permissions on /etc/cron.allow file", "remarks": "rule_set_117" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts", + "value": "file_at_deny_not_exist", "remarks": "rule_set_118" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Ignore ICMP Broadcast Echo Requests on IPv4 Interfaces", + "value": "Ensure that /etc/at.deny does not exist", "remarks": "rule_set_118" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_accept_redirects", + "value": "file_groupowner_at_allow", "remarks": "rule_set_119" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Accepting ICMP Redirects for All IPv4 Interfaces", + "value": "Verify Group Who Owns /etc/at.allow file", "remarks": "rule_set_119" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_accept_redirects", + "value": "file_owner_at_allow", "remarks": "rule_set_120" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 Interfaces", + "value": "Verify User Who Owns /etc/at.allow file", "remarks": "rule_set_120" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_redirects", + "value": "file_permissions_at_allow", "remarks": "rule_set_121" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Accepting ICMP Redirects for All IPv6 Interfaces", + "value": "Verify Permissions on /etc/at.allow file", "remarks": "rule_set_121" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_redirects", + "value": "kernel_module_atm_disabled", "remarks": "rule_set_122" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces", + "value": "Disable ATM Support", "remarks": "rule_set_122" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_secure_redirects", + "value": "kernel_module_can_disabled", "remarks": "rule_set_123" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces", + "value": "Disable CAN Support", "remarks": "rule_set_123" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_secure_redirects", + "value": "kernel_module_dccp_disabled", "remarks": "rule_set_124" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Kernel Parameter for Accepting Secure Redirects By Default", + "value": "Disable DCCP Support", "remarks": "rule_set_124" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_rp_filter", + "value": "kernel_module_tipc_disabled", "remarks": "rule_set_125" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces", + "value": "Disable TIPC Support", "remarks": "rule_set_125" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_rp_filter", + "value": "kernel_module_rds_disabled", "remarks": "rule_set_126" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces by Default", + "value": "Disable RDS Support", "remarks": "rule_set_126" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_accept_source_route", + "value": "kernel_module_sctp_disabled", "remarks": "rule_set_127" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces", + "value": "Disable SCTP Support", "remarks": "rule_set_127" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_accept_source_route", + "value": "sysctl_net_ipv4_ip_forward", "remarks": "rule_set_128" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces by Default", + "value": "Disable Kernel Parameter for IP Forwarding on IPv4 Interfaces", "remarks": "rule_set_128" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_source_route", + "value": "sysctl_net_ipv4_conf_all_forwarding", "remarks": "rule_set_129" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces", + "value": "Disable Kernel Parameter for IPv4 Forwarding on all IPv4 Interfaces", "remarks": "rule_set_129" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_source_route", + "value": "sysctl_net_ipv4_conf_all_send_redirects", "remarks": "rule_set_130" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces by Default", + "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces", "remarks": "rule_set_130" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_log_martians", + "value": "sysctl_net_ipv4_conf_default_send_redirects", "remarks": "rule_set_131" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces", + "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces by Default", "remarks": "rule_set_131" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_log_martians", + "value": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses", "remarks": "rule_set_132" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Paremeter to Log Martian Packets on all IPv4 Interfaces by Default", + "value": "Enable Kernel Parameter to Ignore Bogus ICMP Error Responses on IPv4 Interfaces", "remarks": "rule_set_132" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_tcp_syncookies", + "value": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts", "remarks": "rule_set_133" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces", + "value": "Enable Kernel Parameter to Ignore ICMP Broadcast Echo Requests on IPv4 Interfaces", "remarks": "rule_set_133" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_ra", + "value": "sysctl_net_ipv4_conf_all_accept_redirects", "remarks": "rule_set_134" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Accepting Router Advertisements on All IPv6 Interfaces", + "value": "Disable Accepting ICMP Redirects for All IPv4 Interfaces", "remarks": "rule_set_134" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_ra", + "value": "sysctl_net_ipv4_conf_default_accept_redirects", "remarks": "rule_set_135" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Accepting Router Advertisements on all IPv6 Interfaces by Default", + "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 Interfaces", "remarks": "rule_set_135" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_nftables_installed", + "value": "sysctl_net_ipv4_conf_all_secure_redirects", "remarks": "rule_set_136" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install nftables Package", + "value": "Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces", "remarks": "rule_set_136" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_firewalld_enabled", + "value": "sysctl_net_ipv4_conf_default_secure_redirects", "remarks": "rule_set_137" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify firewalld Enabled", + "value": "Configure Kernel Parameter for Accepting Secure Redirects By Default", "remarks": "rule_set_137" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_firewalld_installed", + "value": "sysctl_net_ipv4_conf_all_rp_filter", "remarks": "rule_set_138" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install firewalld Package", + "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces", "remarks": "rule_set_138" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_nftables_disabled", + "value": "sysctl_net_ipv4_conf_default_rp_filter", "remarks": "rule_set_139" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify nftables Service is Disabled", + "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces by Default", "remarks": "rule_set_139" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "firewalld_loopback_traffic_trusted", + "value": "sysctl_net_ipv4_conf_all_accept_source_route", "remarks": "rule_set_140" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Firewalld to Trust Loopback Traffic", + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces", "remarks": "rule_set_140" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "firewalld_loopback_traffic_restricted", + "value": "sysctl_net_ipv4_conf_default_accept_source_route", "remarks": "rule_set_141" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Firewalld to Restrict Loopback Traffic", + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces by Default", "remarks": "rule_set_141" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_sshd_config", + "value": "sysctl_net_ipv4_conf_all_log_martians", "remarks": "rule_set_142" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns SSH Server config file", + "value": "Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces", "remarks": "rule_set_142" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_sshd_config", + "value": "sysctl_net_ipv4_conf_default_log_martians", "remarks": "rule_set_143" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on SSH Server config file", + "value": "Enable Kernel Paremeter to Log Martian Packets on all IPv4 Interfaces by Default", "remarks": "rule_set_143" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_config", + "value": "sysctl_net_ipv4_tcp_syncookies", "remarks": "rule_set_144" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on SSH Server config file", + "value": "Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces", "remarks": "rule_set_144" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_private_key", + "value": "sysctl_net_ipv6_conf_all_forwarding", "remarks": "rule_set_145" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on SSH Server Private *_key Key Files", + "value": "Disable Kernel Parameter for IPv6 Forwarding", "remarks": "rule_set_145" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_private_key", + "value": "sysctl_net_ipv6_conf_default_forwarding", "remarks": "rule_set_146" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Ownership on SSH Server Private *_key Key Files", + "value": "Disable Kernel Parameter for IPv6 Forwarding by default", "remarks": "rule_set_146" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_sshd_private_key", + "value": "sysctl_net_ipv6_conf_all_accept_redirects", "remarks": "rule_set_147" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Ownership on SSH Server Private *_key Key Files", + "value": "Disable Accepting ICMP Redirects for All IPv6 Interfaces", "remarks": "rule_set_147" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_pub_key", + "value": "sysctl_net_ipv6_conf_default_accept_redirects", "remarks": "rule_set_148" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on SSH Server Public *.pub Key Files", + "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces", "remarks": "rule_set_148" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_pub_key", + "value": "sysctl_net_ipv6_conf_all_accept_source_route", "remarks": "rule_set_149" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Ownership on SSH Server Public *.pub Key Files", + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces", "remarks": "rule_set_149" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_sshd_pub_key", + "value": "sysctl_net_ipv6_conf_default_accept_source_route", "remarks": "rule_set_150" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Ownership on SSH Server Public *.pub Key Files", + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces by Default", "remarks": "rule_set_150" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_kex", + "value": "sysctl_net_ipv6_conf_all_accept_ra", "remarks": "rule_set_151" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Use Only Strong Key Exchange algorithms", + "value": "Configure Accepting Router Advertisements on All IPv6 Interfaces", "remarks": "rule_set_151" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_macs", + "value": "sysctl_net_ipv6_conf_default_accept_ra", "remarks": "rule_set_152" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Use Only Strong MACs", + "value": "Disable Accepting Router Advertisements on all IPv6 Interfaces by Default", "remarks": "rule_set_152" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_limit_user_access", + "value": "package_firewalld_installed", "remarks": "rule_set_153" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Limit Users' SSH Access", + "value": "Install firewalld Package", "remarks": "rule_set_153" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_enable_warning_banner_net", + "value": "service_firewalld_enabled", "remarks": "rule_set_154" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable SSH Warning Banner", + "value": "Verify firewalld Enabled", "remarks": "rule_set_154" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_idle_timeout", + "value": "firewalld_loopback_traffic_trusted", "remarks": "rule_set_155" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set SSH Client Alive Interval", + "value": "Configure Firewalld to Trust Loopback Traffic", "remarks": "rule_set_155" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_keepalive", + "value": "firewalld_loopback_traffic_restricted", "remarks": "rule_set_156" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set SSH Client Alive Count Max", + "value": "Configure Firewalld to Restrict Loopback Traffic", "remarks": "rule_set_156" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_gssapi_auth", + "value": "file_groupowner_sshd_config", "remarks": "rule_set_157" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable GSSAPI Authentication", + "value": "Verify Group Who Owns SSH Server config file", "remarks": "rule_set_157" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "disable_host_auth", + "value": "file_owner_sshd_config", "remarks": "rule_set_158" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Host-Based Authentication", + "value": "Verify Owner on SSH Server config file", "remarks": "rule_set_158" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_rhosts", + "value": "file_permissions_sshd_config", "remarks": "rule_set_159" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable SSH Support for .rhosts Files", + "value": "Verify Permissions on SSH Server config file", "remarks": "rule_set_159" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_login_grace_time", + "value": "file_groupownership_sshd_private_key", "remarks": "rule_set_160" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure SSH LoginGraceTime is configured", + "value": "Verify Group Ownership on SSH Server Private *_key Key Files", "remarks": "rule_set_160" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_loglevel_verbose", + "value": "file_ownership_sshd_private_key", "remarks": "rule_set_161" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set SSH Daemon LogLevel to VERBOSE", + "value": "Verify Ownership on SSH Server Private *_key Key Files", "remarks": "rule_set_161" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_max_auth_tries", + "value": "file_permissions_sshd_private_key", "remarks": "rule_set_162" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set SSH authentication attempt limit", + "value": "Verify Permissions on SSH Server Private *_key Key Files", "remarks": "rule_set_162" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_maxstartups", + "value": "file_groupownership_sshd_pub_key", "remarks": "rule_set_163" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure SSH MaxStartups is configured", + "value": "Verify Group Ownership on SSH Server Public *.pub Key Files", "remarks": "rule_set_163" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_max_sessions", + "value": "file_ownership_sshd_pub_key", "remarks": "rule_set_164" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set SSH MaxSessions limit", + "value": "Verify Ownership on SSH Server Public *.pub Key Files", "remarks": "rule_set_164" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_empty_passwords", + "value": "file_permissions_sshd_pub_key", "remarks": "rule_set_165" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable SSH Access via Empty Passwords", + "value": "Verify Permissions on SSH Server Public *.pub Key Files", "remarks": "rule_set_165" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_root_login", + "value": "sshd_limit_user_access", "remarks": "rule_set_166" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable SSH Root Login", + "value": "Limit Users' SSH Access", "remarks": "rule_set_166" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_do_not_permit_user_env", + "value": "sshd_enable_warning_banner_net", "remarks": "rule_set_167" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Do Not Allow SSH Environment Options", + "value": "Enable SSH Warning Banner", "remarks": "rule_set_167" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_enable_pam", + "value": "sshd_set_idle_timeout", "remarks": "rule_set_168" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable PAM", + "value": "Set SSH Client Alive Interval", "remarks": "rule_set_168" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_sudo_installed", + "value": "sshd_set_keepalive", "remarks": "rule_set_169" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install sudo Package", + "value": "Set SSH Client Alive Count Max", "remarks": "rule_set_169" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_add_use_pty", + "value": "sshd_disable_forwarding", "remarks": "rule_set_170" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Only Users Logged In To Real tty Can Execute Sudo - sudo use_pty", + "value": "Disable SSH Forwarding", "remarks": "rule_set_170" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_custom_logfile", + "value": "sshd_disable_gssapi_auth", "remarks": "rule_set_171" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Sudo Logfile Exists - sudo logfile", + "value": "Disable GSSAPI Authentication", "remarks": "rule_set_171" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_require_reauthentication", + "value": "disable_host_auth", "remarks": "rule_set_172" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Require Re-Authentication When Using the sudo Command", + "value": "Disable Host-Based Authentication", "remarks": "rule_set_172" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "use_pam_wheel_group_for_su", + "value": "sshd_disable_rhosts", "remarks": "rule_set_173" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enforce Usage of pam_wheel with Group Parameter for su Authentication", + "value": "Disable SSH Support for .rhosts Files", "remarks": "rule_set_173" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_pam_wheel_group_empty", + "value": "sshd_use_strong_kex", "remarks": "rule_set_174" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure the Group Used by pam_wheel.so Module Exists on System and is Empty", + "value": "Use Only Strong Key Exchange algorithms", "remarks": "rule_set_174" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_pam_pwquality_installed", + "value": "sshd_set_login_grace_time", "remarks": "rule_set_175" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install pam_pwquality Package", + "value": "Ensure SSH LoginGraceTime is configured", "remarks": "rule_set_175" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_password_auth", + "value": "sshd_set_loglevel_verbose", "remarks": "rule_set_176" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth File.", + "value": "Set SSH Daemon LogLevel to VERBOSE", "remarks": "rule_set_176" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_system_auth", + "value": "sshd_use_strong_macs", "remarks": "rule_set_177" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth File.", + "value": "Use Only Strong MACs", "remarks": "rule_set_177" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_deny", + "value": "sshd_set_max_auth_tries", "remarks": "rule_set_178" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Lock Accounts After Failed Password Attempts", + "value": "Set SSH authentication attempt limit", "remarks": "rule_set_178" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_unlock_time", + "value": "sshd_set_maxstartups", "remarks": "rule_set_179" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Lockout Time for Failed Password Attempts", + "value": "Ensure SSH MaxStartups is configured", "remarks": "rule_set_179" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_difok", + "value": "sshd_set_max_sessions", "remarks": "rule_set_180" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure PAM Enforces Password Requirements - Minimum Different Characters", + "value": "Set SSH MaxSessions limit", "remarks": "rule_set_180" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_minlen", + "value": "sshd_disable_empty_passwords", "remarks": "rule_set_181" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure PAM Enforces Password Requirements - Minimum Length", + "value": "Disable SSH Access via Empty Passwords", "remarks": "rule_set_181" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_minclass", + "value": "sshd_disable_root_login", "remarks": "rule_set_182" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure PAM Enforces Password Requirements - Minimum Different Categories", + "value": "Disable SSH Root Login", "remarks": "rule_set_182" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_maxrepeat", + "value": "sshd_do_not_permit_user_env", "remarks": "rule_set_183" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Password Maximum Consecutive Repeating Characters", + "value": "Do Not Allow SSH Environment Options", "remarks": "rule_set_183" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_dictcheck", + "value": "sshd_enable_pam", "remarks": "rule_set_184" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure PAM Enforces Password Requirements - Prevent the Use of Dictionary Words", + "value": "Enable PAM", "remarks": "rule_set_184" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_enforce_root", + "value": "package_sudo_installed", "remarks": "rule_set_185" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure PAM Enforces Password Requirements - Enforce for root User", + "value": "Install sudo Package", "remarks": "rule_set_185" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_pwhistory_remember_password_auth", + "value": "sudo_add_use_pty", "remarks": "rule_set_186" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Limit Password Reuse: password-auth", + "value": "Ensure Only Users Logged In To Real tty Can Execute Sudo - sudo use_pty", "remarks": "rule_set_186" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_pwhistory_remember_system_auth", + "value": "sudo_custom_logfile", "remarks": "rule_set_187" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Limit Password Reuse: system-auth", + "value": "Ensure Sudo Logfile Exists - sudo logfile", "remarks": "rule_set_187" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_empty_passwords", + "value": "sudo_require_authentication", "remarks": "rule_set_188" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Prevent Login to Accounts With Empty Password", + "value": "Ensure Users Re-Authenticate for Privilege Escalation - sudo", "remarks": "rule_set_188" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_systemauth", + "value": "sudo_require_reauthentication", "remarks": "rule_set_189" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set PAM''s Password Hashing Algorithm", + "value": "Require Re-Authentication When Using the sudo Command", "remarks": "rule_set_189" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_passwordauth", + "value": "use_pam_wheel_group_for_su", "remarks": "rule_set_190" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set PAM''s Password Hashing Algorithm - password-auth", + "value": "Enforce Usage of pam_wheel with Group Parameter for su Authentication", "remarks": "rule_set_190" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_maximum_age_login_defs", + "value": "ensure_pam_wheel_group_empty", "remarks": "rule_set_191" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Password Maximum Age", + "value": "Ensure the Group Used by pam_wheel.so Module Exists on System and is Empty", "remarks": "rule_set_191" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_set_max_life_existing", + "value": "account_password_pam_faillock_password_auth", "remarks": "rule_set_192" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Existing Passwords Maximum Age", + "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth File.", "remarks": "rule_set_192" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_warn_age_login_defs", + "value": "account_password_pam_faillock_system_auth", "remarks": "rule_set_193" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Password Warning Age", + "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth File.", "remarks": "rule_set_193" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_set_warn_age_existing", + "value": "package_pam_pwquality_installed", "remarks": "rule_set_194" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Existing Passwords Warning Age", + "value": "Install pam_pwquality Package", "remarks": "rule_set_194" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_libuserconf", + "value": "accounts_passwords_pam_faillock_deny", "remarks": "rule_set_195" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Password Hashing Algorithm in /etc/libuser.conf", + "value": "Lock Accounts After Failed Password Attempts", "remarks": "rule_set_195" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_logindefs", + "value": "accounts_passwords_pam_faillock_unlock_time", "remarks": "rule_set_196" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Password Hashing Algorithm in /etc/login.defs", + "value": "Set Lockout Time for Failed Password Attempts", "remarks": "rule_set_196" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_disable_post_pw_expiration", + "value": "accounts_password_pam_difok", "remarks": "rule_set_197" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Account Expiration Following Inactivity", + "value": "Ensure PAM Enforces Password Requirements - Minimum Different Characters", "remarks": "rule_set_197" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_set_post_pw_existing", + "value": "accounts_password_pam_minlen", "remarks": "rule_set_198" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set existing passwords a period of inactivity before they been locked", + "value": "Ensure PAM Enforces Password Requirements - Minimum Length", "remarks": "rule_set_198" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_last_change_is_in_past", + "value": "accounts_password_pam_minclass", "remarks": "rule_set_199" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure all users last password change date is in the past", + "value": "Ensure PAM Enforces Password Requirements - Minimum Different Categories", "remarks": "rule_set_199" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_no_uid_except_zero", + "value": "accounts_password_pam_maxrepeat", "remarks": "rule_set_200" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Only Root Has UID 0", + "value": "Set Password Maximum Consecutive Repeating Characters", "remarks": "rule_set_200" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_root_gid_zero", + "value": "accounts_password_pam_dictcheck", "remarks": "rule_set_201" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Root Has A Primary GID 0", + "value": "Ensure PAM Enforces Password Requirements - Prevent the Use of Dictionary Words", "remarks": "rule_set_201" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_root_password_configured", + "value": "accounts_password_pam_enforce_root", "remarks": "rule_set_202" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Authentication Required for Single User Mode", + "value": "Ensure PAM Enforces Password Requirements - Enforce for root User", "remarks": "rule_set_202" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_root_path_dirs_no_write", + "value": "accounts_password_pam_pwhistory_remember_password_auth", "remarks": "rule_set_203" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that Root's Path Does Not Include World or Group-Writable Directories", + "value": "Limit Password Reuse: password-auth", "remarks": "rule_set_203" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "root_path_no_dot", + "value": "accounts_password_pam_pwhistory_remember_system_auth", "remarks": "rule_set_204" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that Root's Path Does Not Include Relative Paths or Null Directories", + "value": "Limit Password Reuse: system-auth", "remarks": "rule_set_204" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_password_auth_for_systemaccounts", + "value": "no_empty_passwords", "remarks": "rule_set_205" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that System Accounts Are Locked", + "value": "Prevent Login to Accounts With Empty Password", "remarks": "rule_set_205" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_shelllogin_for_systemaccounts", + "value": "set_password_hashing_algorithm_systemauth", "remarks": "rule_set_206" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that System Accounts Do Not Run a Shell Upon Login", + "value": "Set PAM''s Password Hashing Algorithm", "remarks": "rule_set_206" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_tmout", + "value": "set_password_hashing_algorithm_passwordauth", "remarks": "rule_set_207" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Interactive Session Timeout", + "value": "Set PAM''s Password Hashing Algorithm - password-auth", "remarks": "rule_set_207" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_umask_etc_bashrc", + "value": "accounts_maximum_age_login_defs", "remarks": "rule_set_208" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure the Default Bash Umask is Set Correctly", + "value": "Set Password Maximum Age", "remarks": "rule_set_208" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_umask_etc_login_defs", + "value": "accounts_password_set_max_life_existing", "remarks": "rule_set_209" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure the Default Umask is Set Correctly in login.defs", + "value": "Set Existing Passwords Maximum Age", "remarks": "rule_set_209" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_umask_etc_profile", + "value": "accounts_password_warn_age_login_defs", "remarks": "rule_set_210" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure the Default Umask is Set Correctly in /etc/profile", + "value": "Set Password Warning Age", "remarks": "rule_set_210" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_aide_installed", + "value": "accounts_password_set_warn_age_existing", "remarks": "rule_set_211" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install AIDE", + "value": "Set Existing Passwords Warning Age", "remarks": "rule_set_211" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "aide_build_database", + "value": "set_password_hashing_algorithm_libuserconf", "remarks": "rule_set_212" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Build and Test AIDE Database", + "value": "Set Password Hashing Algorithm in /etc/libuser.conf", "remarks": "rule_set_212" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "aide_periodic_cron_checking", + "value": "set_password_hashing_algorithm_logindefs", "remarks": "rule_set_213" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Periodic Execution of AIDE", + "value": "Set Password Hashing Algorithm in /etc/login.defs", "remarks": "rule_set_213" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "aide_check_audit_tools", + "value": "account_disable_post_pw_expiration", "remarks": "rule_set_214" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure AIDE to Verify the Audit Tools", + "value": "Set Account Expiration Following Inactivity", "remarks": "rule_set_214" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_systemd-journald_enabled", + "value": "accounts_set_post_pw_existing", "remarks": "rule_set_215" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable systemd-journald Service", + "value": "Set existing passwords a period of inactivity before they been locked", "remarks": "rule_set_215" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_systemd-journal-remote_installed", + "value": "accounts_password_last_change_is_in_past", "remarks": "rule_set_216" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install systemd-journal-remote Package", + "value": "Ensure all users last password change date is in the past", "remarks": "rule_set_216" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "socket_systemd-journal-remote_disabled", + "value": "accounts_no_uid_except_zero", "remarks": "rule_set_217" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable systemd-journal-remote Socket", + "value": "Verify Only Root Has UID 0", "remarks": "rule_set_217" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_compress", + "value": "accounts_root_gid_zero", "remarks": "rule_set_218" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure journald is configured to compress large log files", + "value": "Verify Root Has A Primary GID 0", "remarks": "rule_set_218" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_storage", + "value": "groups_no_zero_gid_except_root", "remarks": "rule_set_219" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure journald is configured to write log files to persistent disk", + "value": "Verify Only Group Root Has GID 0", "remarks": "rule_set_219" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "rsyslog_files_groupownership", + "value": "ensure_root_password_configured", "remarks": "rule_set_220" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Log Files Are Owned By Appropriate Group", + "value": "Ensure Authentication Required for Single User Mode", "remarks": "rule_set_220" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "rsyslog_files_ownership", + "value": "accounts_root_path_dirs_no_write", "remarks": "rule_set_221" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Log Files Are Owned By Appropriate User", + "value": "Ensure that Root's Path Does Not Include World or Group-Writable Directories", "remarks": "rule_set_221" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "rsyslog_files_permissions", + "value": "root_path_no_dot", "remarks": "rule_set_222" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure System Log Files Have Correct Permissions", + "value": "Ensure that Root's Path Does Not Include Relative Paths or Null Directories", "remarks": "rule_set_222" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_passwd", + "value": "accounts_umask_root", "remarks": "rule_set_223" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns passwd File", + "value": "Ensure the Root Bash Umask is Set Correctly", "remarks": "rule_set_223" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_passwd", + "value": "no_password_auth_for_systemaccounts", "remarks": "rule_set_224" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns passwd File", + "value": "Ensure that System Accounts Are Locked", "remarks": "rule_set_224" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_passwd", + "value": "no_shelllogin_for_systemaccounts", "remarks": "rule_set_225" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on passwd File", + "value": "Ensure that System Accounts Do Not Run a Shell Upon Login", "remarks": "rule_set_225" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_passwd", + "value": "accounts_tmout", "remarks": "rule_set_226" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns Backup passwd File", + "value": "Set Interactive Session Timeout", "remarks": "rule_set_226" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_passwd", + "value": "accounts_umask_etc_bashrc", "remarks": "rule_set_227" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns Backup passwd File", + "value": "Ensure the Default Bash Umask is Set Correctly", "remarks": "rule_set_227" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_passwd", + "value": "accounts_umask_etc_login_defs", "remarks": "rule_set_228" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on Backup passwd File", + "value": "Ensure the Default Umask is Set Correctly in login.defs", "remarks": "rule_set_228" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_group", + "value": "accounts_umask_etc_profile", "remarks": "rule_set_229" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns group File", + "value": "Ensure the Default Umask is Set Correctly in /etc/profile", "remarks": "rule_set_229" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_group", + "value": "package_aide_installed", "remarks": "rule_set_230" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns group File", + "value": "Install AIDE", "remarks": "rule_set_230" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_group", + "value": "aide_build_database", "remarks": "rule_set_231" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on group File", + "value": "Build and Test AIDE Database", "remarks": "rule_set_231" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_group", + "value": "aide_periodic_cron_checking", "remarks": "rule_set_232" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns Backup group File", + "value": "Configure Periodic Execution of AIDE", "remarks": "rule_set_232" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_group", + "value": "aide_check_audit_tools", "remarks": "rule_set_233" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns Backup group File", + "value": "Configure AIDE to Verify the Audit Tools", "remarks": "rule_set_233" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_group", + "value": "service_systemd-journald_enabled", "remarks": "rule_set_234" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on Backup group File", + "value": "Enable systemd-journald Service", "remarks": "rule_set_234" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_shadow", + "value": "journald_compress", "remarks": "rule_set_235" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns shadow File", + "value": "Ensure journald is configured to compress large log files", "remarks": "rule_set_235" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_shadow", + "value": "journald_storage", "remarks": "rule_set_236" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns shadow File", + "value": "Ensure journald is configured to write log files to persistent disk", "remarks": "rule_set_236" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_shadow", + "value": "package_systemd-journal-remote_installed", "remarks": "rule_set_237" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on shadow File", + "value": "Install systemd-journal-remote Package", "remarks": "rule_set_237" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_shadow", + "value": "socket_systemd-journal-remote_disabled", "remarks": "rule_set_238" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns Backup shadow File", + "value": "Disable systemd-journal-remote Socket", "remarks": "rule_set_238" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_shadow", + "value": "rsyslog_files_groupownership", "remarks": "rule_set_239" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns Backup shadow File", + "value": "Ensure Log Files Are Owned By Appropriate Group", "remarks": "rule_set_239" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_shadow", + "value": "rsyslog_files_ownership", "remarks": "rule_set_240" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on Backup shadow File", + "value": "Ensure Log Files Are Owned By Appropriate User", "remarks": "rule_set_240" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_gshadow", + "value": "rsyslog_files_permissions", "remarks": "rule_set_241" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns gshadow File", + "value": "Ensure System Log Files Have Correct Permissions", "remarks": "rule_set_241" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_gshadow", + "value": "file_groupowner_etc_passwd", "remarks": "rule_set_242" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns gshadow File", + "value": "Verify Group Who Owns passwd File", "remarks": "rule_set_242" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_gshadow", + "value": "file_owner_etc_passwd", "remarks": "rule_set_243" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on gshadow File", + "value": "Verify User Who Owns passwd File", "remarks": "rule_set_243" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_gshadow", + "value": "file_permissions_etc_passwd", "remarks": "rule_set_244" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns Backup gshadow File", + "value": "Verify Permissions on passwd File", "remarks": "rule_set_244" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_gshadow", + "value": "file_groupowner_backup_etc_passwd", "remarks": "rule_set_245" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns Backup gshadow File", + "value": "Verify Group Who Owns Backup passwd File", "remarks": "rule_set_245" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_gshadow", + "value": "file_owner_backup_etc_passwd", "remarks": "rule_set_246" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on Backup gshadow File", + "value": "Verify User Who Owns Backup passwd File", "remarks": "rule_set_246" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_shells", + "value": "file_permissions_backup_etc_passwd", "remarks": "rule_set_247" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns /etc/shells File", + "value": "Verify Permissions on Backup passwd File", "remarks": "rule_set_247" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_shells", + "value": "file_groupowner_etc_group", "remarks": "rule_set_248" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Who Owns /etc/shells File", + "value": "Verify Group Who Owns group File", "remarks": "rule_set_248" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_shells", + "value": "file_owner_etc_group", "remarks": "rule_set_249" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on /etc/shells File", + "value": "Verify User Who Owns group File", "remarks": "rule_set_249" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_etc_security_opasswd", + "value": "file_permissions_etc_group", "remarks": "rule_set_250" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions and Ownership of Old Passwords File", + "value": "Verify Permissions on group File", "remarks": "rule_set_250" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_unauthorized_world_writable", + "value": "file_groupowner_backup_etc_group", "remarks": "rule_set_251" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure No World-Writable Files Exist", + "value": "Verify Group Who Owns Backup group File", "remarks": "rule_set_251" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dir_perms_world_writable_sticky_bits", + "value": "file_owner_backup_etc_group", "remarks": "rule_set_252" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify that All World-Writable Directories Have Sticky Bits Set", + "value": "Verify User Who Owns Backup group File", "remarks": "rule_set_252" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_files_unowned_by_user", + "value": "file_permissions_backup_etc_group", "remarks": "rule_set_253" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Files Are Owned by a User", + "value": "Verify Permissions on Backup group File", "remarks": "rule_set_253" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_ungroupowned", + "value": "file_owner_etc_shadow", "remarks": "rule_set_254" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Files Are Owned by a Group", + "value": "Verify User Who Owns shadow File", "remarks": "rule_set_254" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_all_shadowed", + "value": "file_groupowner_etc_shadow", "remarks": "rule_set_255" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify All Account Password Hashes are Shadowed", + "value": "Verify Group Who Owns shadow File", "remarks": "rule_set_255" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_empty_passwords_etc_shadow", + "value": "file_permissions_etc_shadow", "remarks": "rule_set_256" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure There Are No Accounts With Blank or Null Passwords", + "value": "Verify Permissions on shadow File", "remarks": "rule_set_256" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "gid_passwd_group_same", + "value": "file_groupowner_backup_etc_shadow", "remarks": "rule_set_257" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "All GIDs referenced in /etc/passwd must be defined in /etc/group", + "value": "Verify User Who Owns Backup shadow File", "remarks": "rule_set_257" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_unique_id", + "value": "file_owner_backup_etc_shadow", "remarks": "rule_set_258" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Accounts on the System Have Unique User IDs", + "value": "Verify Group Who Owns Backup shadow File", "remarks": "rule_set_258" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "group_unique_id", + "value": "file_permissions_backup_etc_shadow", "remarks": "rule_set_259" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Groups on the System Have Unique Group ID", + "value": "Verify Permissions on Backup shadow File", "remarks": "rule_set_259" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_unique_name", + "value": "file_groupowner_etc_gshadow", "remarks": "rule_set_260" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Accounts on the System Have Unique Names", + "value": "Verify Group Who Owns gshadow File", "remarks": "rule_set_260" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "group_unique_name", + "value": "file_owner_etc_gshadow", "remarks": "rule_set_261" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Groups on the System Have Unique Group Names", + "value": "Verify User Who Owns gshadow File", "remarks": "rule_set_261" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_user_interactive_home_directory_exists", + "value": "file_permissions_etc_gshadow", "remarks": "rule_set_262" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "All Interactive Users Home Directories Must Exist", + "value": "Verify Permissions on gshadow File", "remarks": "rule_set_262" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_home_directories", + "value": "file_groupowner_backup_etc_gshadow", "remarks": "rule_set_263" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "All Interactive User Home Directories Must Be Owned By The Primary User", + "value": "Verify Group Who Owns Backup gshadow File", "remarks": "rule_set_263" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_home_directories", + "value": "file_owner_backup_etc_gshadow", "remarks": "rule_set_264" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "All Interactive User Home Directories Must Have mode 0750 Or Less Permissive", + "value": "Verify User Who Owns Backup gshadow File", "remarks": "rule_set_264" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_user_dot_group_ownership", + "value": "file_permissions_backup_etc_gshadow", "remarks": "rule_set_265" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "User Initialization Files Must Be Group-Owned By The Primary Group", + "value": "Verify Permissions on Backup gshadow File", "remarks": "rule_set_265" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_user_dot_user_ownership", + "value": "file_groupowner_etc_shells", "remarks": "rule_set_266" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "User Initialization Files Must Be Owned By the Primary User", + "value": "Verify Group Who Owns /etc/shells File", "remarks": "rule_set_266" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_user_dot_no_world_writable_programs", + "value": "file_owner_etc_shells", "remarks": "rule_set_267" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "User Initialization Files Must Not Run World-Writable Programs", + "value": "Verify Who Owns /etc/shells File", "remarks": "rule_set_267" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permission_user_init_files", + "value": "file_permissions_etc_shells", "remarks": "rule_set_268" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All User Initialization Files Have Mode 0740 Or Less Permissive", + "value": "Verify Permissions on /etc/shells File", "remarks": "rule_set_268" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_forward_files", + "value": "file_etc_security_opasswd", "remarks": "rule_set_269" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify No .forward Files Exist", + "value": "Verify Permissions and Ownership of Old Passwords File", "remarks": "rule_set_269" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_netrc_files", + "value": "file_permissions_unauthorized_world_writable", "remarks": "rule_set_270" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify No netrc Files Exist", + "value": "Ensure No World-Writable Files Exist", "remarks": "rule_set_270" - } - ], - "control-implementations": [ + }, { - "uuid": "672636f4-2bbf-4003-9471-ab7206274806", - "source": "trestle://profiles/rhel10-cis_rhel10-l1_workstation/profile.json", - "description": "REPLACE_ME", - "props": [ - { - "name": "Framework_Short_Name", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal", - "value": "cis_workstation_l1" - } - ], - "set-parameters": [ - { - "param-id": "cis_banner_text", - "values": [ - "cis" - ] - }, - { - "param-id": "inactivity_timeout_value", - "values": [ - "15_minutes" - ] - }, - { - "param-id": "login_banner_text", - "values": [ - "cis_banners" - ] - }, - { - "param-id": "sshd_idle_timeout_value", - "values": [ - "5_minutes" - ] - }, - { - "param-id": "sshd_max_auth_tries_value", - "values": [ - "4" - ] - }, - { - "param-id": "sshd_strong_kex", - "values": [ - "cis_rhel8" - ] - }, - { - "param-id": "sshd_strong_macs", - "values": [ - "cis_rhel8" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_all_accept_redirects_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_all_accept_source_route_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_all_log_martians_value", - "values": [ - "enabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_all_rp_filter_value", + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "dir_perms_world_writable_sticky_bits", + "remarks": "rule_set_271" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify that All World-Writable Directories Have Sticky Bits Set", + "remarks": "rule_set_271" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "no_files_unowned_by_user", + "remarks": "rule_set_272" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure All Files Are Owned by a User", + "remarks": "rule_set_272" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_ungroupowned", + "remarks": "rule_set_273" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure All Files Are Owned by a Group", + "remarks": "rule_set_273" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_password_all_shadowed", + "remarks": "rule_set_274" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify All Account Password Hashes are Shadowed", + "remarks": "rule_set_274" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "no_empty_passwords_etc_shadow", + "remarks": "rule_set_275" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure There Are No Accounts With Blank or Null Passwords", + "remarks": "rule_set_275" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "gid_passwd_group_same", + "remarks": "rule_set_276" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "All GIDs referenced in /etc/passwd must be defined in /etc/group", + "remarks": "rule_set_276" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "account_unique_id", + "remarks": "rule_set_277" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure All Accounts on the System Have Unique User IDs", + "remarks": "rule_set_277" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "group_unique_id", + "remarks": "rule_set_278" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure All Groups on the System Have Unique Group ID", + "remarks": "rule_set_278" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "account_unique_name", + "remarks": "rule_set_279" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure All Accounts on the System Have Unique Names", + "remarks": "rule_set_279" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "group_unique_name", + "remarks": "rule_set_280" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure All Groups on the System Have Unique Group Names", + "remarks": "rule_set_280" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_user_interactive_home_directory_exists", + "remarks": "rule_set_281" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "All Interactive Users Home Directories Must Exist", + "remarks": "rule_set_281" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_ownership_home_directories", + "remarks": "rule_set_282" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "All Interactive User Home Directories Must Be Owned By The Primary User", + "remarks": "rule_set_282" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_home_directories", + "remarks": "rule_set_283" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "All Interactive User Home Directories Must Have mode 0750 Or Less Permissive", + "remarks": "rule_set_283" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_user_dot_group_ownership", + "remarks": "rule_set_284" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "User Initialization Files Must Be Group-Owned By The Primary Group", + "remarks": "rule_set_284" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_user_dot_user_ownership", + "remarks": "rule_set_285" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "User Initialization Files Must Be Owned By the Primary User", + "remarks": "rule_set_285" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_user_dot_no_world_writable_programs", + "remarks": "rule_set_286" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "User Initialization Files Must Not Run World-Writable Programs", + "remarks": "rule_set_286" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permission_user_init_files", + "remarks": "rule_set_287" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure All User Initialization Files Have Mode 0740 Or Less Permissive", + "remarks": "rule_set_287" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "no_forward_files", + "remarks": "rule_set_288" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify No .forward Files Exist", + "remarks": "rule_set_288" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "no_netrc_files", + "remarks": "rule_set_289" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify No netrc Files Exist", + "remarks": "rule_set_289" + } + ], + "control-implementations": [ + { + "uuid": "7d1deda1-45d0-4991-8c48-537a5f3abcf3", + "source": "trestle://profiles/rhel10-cis_rhel10-l1_workstation/profile.json", + "description": "REPLACE_ME", + "props": [ + { + "name": "Framework_Short_Name", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal", + "value": "cis_workstation_l1" + } + ], + "set-parameters": [ + { + "param-id": "cis_banner_text", "values": [ - "enabled" + "cis" ] }, { - "param-id": "sysctl_net_ipv4_conf_all_secure_redirects_value", + "param-id": "inactivity_timeout_value", "values": [ - "disabled" + "15_minutes" ] }, { - "param-id": "sysctl_net_ipv4_conf_default_accept_redirects_value", + "param-id": "login_banner_text", "values": [ - "disabled" + "cis_banners" ] }, { - "param-id": "sysctl_net_ipv4_conf_default_accept_source_route_value", + "param-id": "sshd_idle_timeout_value", "values": [ - "disabled" + "5_minutes" ] }, { - "param-id": "sysctl_net_ipv4_conf_default_log_martians_value", + "param-id": "sshd_max_auth_tries_value", "values": [ - "enabled" + "4" ] }, { - "param-id": "sysctl_net_ipv4_conf_default_rp_filter_value", + "param-id": "sshd_strong_kex", "values": [ - "enabled" + "cis_rhel10" ] }, { - "param-id": "sysctl_net_ipv4_conf_default_secure_redirects_value", + "param-id": "sshd_strong_macs", + "values": [ + "cis_rhel10" + ] + }, + { + "param-id": "sysctl_net_ipv4_conf_all_accept_redirects_value", "values": [ "disabled" ] }, { - "param-id": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts_value", + "param-id": "sysctl_net_ipv4_conf_all_accept_source_route_value", "values": [ - "enabled" + "disabled" ] }, { - "param-id": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses_value", + "param-id": "sysctl_net_ipv4_conf_all_log_martians_value", "values": [ "enabled" ] }, { - "param-id": "sysctl_net_ipv4_tcp_syncookies_value", + "param-id": "sysctl_net_ipv4_conf_all_rp_filter_value", "values": [ "enabled" ] }, { - "param-id": "sysctl_net_ipv6_conf_all_accept_ra_value", + "param-id": "sysctl_net_ipv4_conf_all_secure_redirects_value", "values": [ "disabled" ] }, { - "param-id": "sysctl_net_ipv6_conf_all_accept_redirects_value", + "param-id": "sysctl_net_ipv4_conf_default_accept_redirects_value", "values": [ "disabled" ] }, { - "param-id": "sysctl_net_ipv6_conf_all_accept_source_route_value", + "param-id": "sysctl_net_ipv4_conf_default_accept_source_route_value", "values": [ "disabled" ] }, { - "param-id": "sysctl_net_ipv6_conf_all_forwarding_value", + "param-id": "sysctl_net_ipv4_conf_default_log_martians_value", "values": [ - "disabled" + "enabled" ] }, { - "param-id": "sysctl_net_ipv6_conf_default_accept_ra_value", + "param-id": "sysctl_net_ipv4_conf_default_rp_filter_value", "values": [ - "disabled" + "enabled" ] }, { - "param-id": "sysctl_net_ipv6_conf_default_accept_redirects_value", + "param-id": "sysctl_net_ipv4_conf_default_secure_redirects_value", + "values": [ + "disabled" + ] + }, + { + "param-id": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts_value", + "values": [ + "enabled" + ] + }, + { + "param-id": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses_value", + "values": [ + "enabled" + ] + }, + { + "param-id": "sysctl_net_ipv4_tcp_syncookies_value", + "values": [ + "enabled" + ] + }, + { + "param-id": "sysctl_net_ipv6_conf_all_accept_ra_value", + "values": [ + "disabled" + ] + }, + { + "param-id": "sysctl_net_ipv6_conf_all_accept_redirects_value", + "values": [ + "disabled" + ] + }, + { + "param-id": "sysctl_net_ipv6_conf_all_accept_source_route_value", + "values": [ + "disabled" + ] + }, + { + "param-id": "sysctl_net_ipv6_conf_all_forwarding_value", + "values": [ + "disabled" + ] + }, + { + "param-id": "sysctl_net_ipv6_conf_default_accept_ra_value", + "values": [ + "disabled" + ] + }, + { + "param-id": "sysctl_net_ipv6_conf_default_accept_redirects_value", "values": [ "disabled" ] @@ -4432,6 +4678,12 @@ "disabled" ] }, + { + "param-id": "sysctl_net_ipv6_conf_default_forwarding_value", + "values": [ + "disabled" + ] + }, { "param-id": "var_account_disable_post_pw_expiration", "values": [ @@ -4603,7 +4855,7 @@ ], "implemented-requirements": [ { - "uuid": "4fa54cc5-9de0-44ba-b920-30f379d66625", + "uuid": "419179ef-6c42-4d1c-9b7c-2ee581fa384a", "control-id": "reload_dconf_db", "description": "This is a helper rule to reload Dconf database correctly.", "props": [ @@ -4620,7 +4872,7 @@ ] }, { - "uuid": "1c49356f-3972-48b1-a37b-bb9d25245694", + "uuid": "a6993293-9829-4901-ae46-57471a21b715", "control-id": "cis_rhel10_1-1.2.1.1", "description": "REPLACE_ME", "props": [ @@ -4637,7 +4889,7 @@ ] }, { - "uuid": "3bace352-ccd4-4b61-8005-e936873aded0", + "uuid": "17c2b6aa-e4dc-4162-9cb1-d45954898af3", "control-id": "cis_rhel10_1-1.2.1.2", "description": "REPLACE_ME", "props": [ @@ -4654,7 +4906,7 @@ ] }, { - "uuid": "c09931b7-0abf-416c-bd03-f4c034d25b5a", + "uuid": "db471c72-7f06-466b-9bd4-ea52d7e3246d", "control-id": "cis_rhel10_1-1.2.1.3", "description": "REPLACE_ME", "props": [ @@ -4671,7 +4923,7 @@ ] }, { - "uuid": "300a964f-9156-4647-877b-02c754c4bfc0", + "uuid": "56ec3a06-7966-41ab-afa5-0135a984ad7b", "control-id": "cis_rhel10_1-1.2.1.4", "description": "REPLACE_ME", "props": [ @@ -4688,7 +4940,7 @@ ] }, { - "uuid": "f623970a-f779-43ff-9e3c-eae61ef44177", + "uuid": "dd633707-5d2d-4015-9205-e5887b8a938a", "control-id": "cis_rhel10_1-1.2.2.1", "description": "REPLACE_ME", "props": [ @@ -4705,7 +4957,7 @@ ] }, { - "uuid": "3a5aede3-e3de-48c1-acdf-2de066e83bbd", + "uuid": "ea9f42db-e3d8-4684-887a-3f4a967436e1", "control-id": "cis_rhel10_1-1.2.2.2", "description": "REPLACE_ME", "props": [ @@ -4722,7 +4974,7 @@ ] }, { - "uuid": "745f43dc-d0d2-465d-aa29-668fd008831a", + "uuid": "cf87bb4f-e0cf-466e-95f7-f1897089e010", "control-id": "cis_rhel10_1-1.2.2.3", "description": "REPLACE_ME", "props": [ @@ -4739,7 +4991,7 @@ ] }, { - "uuid": "1e4834dc-592a-475e-9137-f4bac68ba9d0", + "uuid": "3989f38f-6720-4c66-8481-f35569fa967f", "control-id": "cis_rhel10_1-1.2.2.4", "description": "REPLACE_ME", "props": [ @@ -4756,7 +5008,7 @@ ] }, { - "uuid": "5648d98d-0bcd-45d9-b4f2-a955e49d8056", + "uuid": "12267afe-104a-4010-9512-19f2e8cbace1", "control-id": "cis_rhel10_1-1.2.3.2", "description": "REPLACE_ME", "props": [ @@ -4773,7 +5025,7 @@ ] }, { - "uuid": "8417b22f-1d2d-4baa-be62-c0daf67de32e", + "uuid": "34bbc419-c9c7-4156-8f7c-53b983541740", "control-id": "cis_rhel10_1-1.2.3.3", "description": "REPLACE_ME", "props": [ @@ -4790,7 +5042,7 @@ ] }, { - "uuid": "0defba54-b847-4b65-835b-65d46d77f6cb", + "uuid": "7485cb6a-3746-4f59-8e9a-d1e244c795e8", "control-id": "cis_rhel10_1-1.2.4.2", "description": "REPLACE_ME", "props": [ @@ -4807,7 +5059,7 @@ ] }, { - "uuid": "df3a65fc-2abe-4143-94d6-3d06e406106f", + "uuid": "dd640df5-207a-4262-93d3-ecfc383bc439", "control-id": "cis_rhel10_1-1.2.4.3", "description": "REPLACE_ME", "props": [ @@ -4824,7 +5076,7 @@ ] }, { - "uuid": "95d4eaed-2d41-43ab-bca3-95e7859748b1", + "uuid": "a564f3e5-129e-4733-9cd4-d9d486235488", "control-id": "cis_rhel10_1-1.2.5.2", "description": "REPLACE_ME", "props": [ @@ -4841,7 +5093,7 @@ ] }, { - "uuid": "4d9455a3-f23a-4303-9e20-fc8dfcf49159", + "uuid": "4903f68b-da5c-4dcf-988f-2d0d77a9d0b1", "control-id": "cis_rhel10_1-1.2.5.3", "description": "REPLACE_ME", "props": [ @@ -4858,7 +5110,7 @@ ] }, { - "uuid": "1f8cd6fc-ac4c-4312-97ae-b78361bbd3de", + "uuid": "fcebbdf7-25be-4382-a46b-8f2db2f4dd0b", "control-id": "cis_rhel10_1-1.2.5.4", "description": "REPLACE_ME", "props": [ @@ -4875,7 +5127,7 @@ ] }, { - "uuid": "875d4f30-b473-465f-afc2-60d168d0213a", + "uuid": "502042e2-a1bb-45bf-8afc-bd402677cf50", "control-id": "cis_rhel10_1-1.2.6.2", "description": "REPLACE_ME", "props": [ @@ -4892,7 +5144,7 @@ ] }, { - "uuid": "927cd56c-9171-4ec2-89df-698d75677fc9", + "uuid": "0f3cedf3-1450-45b3-b914-4a1c6eb86b58", "control-id": "cis_rhel10_1-1.2.6.3", "description": "REPLACE_ME", "props": [ @@ -4909,7 +5161,7 @@ ] }, { - "uuid": "9e48bc01-a770-4cc0-8fc0-e57fa7126215", + "uuid": "4390cbf8-33b8-4e69-8382-5f3aa7655f35", "control-id": "cis_rhel10_1-1.2.6.4", "description": "REPLACE_ME", "props": [ @@ -4926,7 +5178,7 @@ ] }, { - "uuid": "463b8c3b-ec76-45c4-8903-3af3a740c123", + "uuid": "008bda58-dfa3-49cb-9167-08a8bcd7a270", "control-id": "cis_rhel10_1-1.2.7.2", "description": "REPLACE_ME", "props": [ @@ -4943,7 +5195,7 @@ ] }, { - "uuid": "a1022aec-62e2-4829-89e5-60a9f5463a57", + "uuid": "5018c106-daa0-49e7-a4fd-83b39f4455e7", "control-id": "cis_rhel10_1-1.2.7.3", "description": "REPLACE_ME", "props": [ @@ -4960,7 +5212,7 @@ ] }, { - "uuid": "d0308a2b-105c-4706-a896-c1ed048d9675", + "uuid": "f6cfdc87-e250-4c1e-a46c-e540970afb8a", "control-id": "cis_rhel10_1-1.2.7.4", "description": "REPLACE_ME", "props": [ @@ -4977,7 +5229,7 @@ ] }, { - "uuid": "f3cf8e77-d217-4ddb-a99d-b1859dc8662c", + "uuid": "9c388758-595c-4c6b-85ed-e144097b968c", "control-id": "cis_rhel10_1-2.1.1", "description": "REPLACE_ME", "props": [ @@ -4990,7 +5242,7 @@ ] }, { - "uuid": "cf88287b-0c1c-4693-a293-5dbec9377508", + "uuid": "6c78b8b9-f90d-4691-af9c-31a1cf942097", "control-id": "cis_rhel10_1-2.1.2", "description": "REPLACE_ME", "props": [ @@ -5007,7 +5259,7 @@ ] }, { - "uuid": "85917b71-b0e7-4561-b7a2-395b866b3e13", + "uuid": "555106f6-31ef-43bd-a3c6-0b95448a36b3", "control-id": "cis_rhel10_1-2.1.4", "description": "REPLACE_ME", "props": [ @@ -5020,7 +5272,7 @@ ] }, { - "uuid": "ff57688a-b8af-470b-a45b-5532ad7b48c5", + "uuid": "1c854d5d-01e6-4449-93eb-ce1e84d05537", "control-id": "cis_rhel10_1-2.2.1", "description": "REPLACE_ME", "props": [ @@ -5033,7 +5285,7 @@ ] }, { - "uuid": "3a3c95ea-e87d-43c2-ae5d-e9bd31f15bbd", + "uuid": "f788e279-f1c7-4374-bf22-d0ea4ecc31c2", "control-id": "cis_rhel10_1-3.1.1", "description": "REPLACE_ME", "props": [ @@ -5050,7 +5302,7 @@ ] }, { - "uuid": "cd24c5f4-a696-4bcd-b10d-b0bef96fc12e", + "uuid": "b148a195-257d-41b3-b8e5-9ab5f0ca77a1", "control-id": "cis_rhel10_1-3.1.2", "description": "REPLACE_ME", "props": [ @@ -5067,7 +5319,7 @@ ] }, { - "uuid": "20282ded-ad77-45ce-ac63-8d49c8c7394a", + "uuid": "72c5d064-ac07-4c05-a7ea-7765995cc0ad", "control-id": "cis_rhel10_1-3.1.3", "description": "REPLACE_ME", "props": [ @@ -5084,7 +5336,7 @@ ] }, { - "uuid": "ae35fe6d-1546-4b77-882c-c6f87b852548", + "uuid": "0cd8f580-1832-493e-b024-b5dc83653174", "control-id": "cis_rhel10_1-3.1.4", "description": "REPLACE_ME", "props": [ @@ -5101,7 +5353,7 @@ ] }, { - "uuid": "740709fd-89ea-4913-92b2-faf61d83398b", + "uuid": "d21f46df-c385-4a8d-a83e-46edf70f5305", "control-id": "cis_rhel10_1-3.1.7", "description": "REPLACE_ME", "props": [ @@ -5118,7 +5370,7 @@ ] }, { - "uuid": "2c2a735b-51fd-462a-a527-d14662f65615", + "uuid": "c58e0c19-78d1-47d3-bc97-6efb28677c6e", "control-id": "cis_rhel10_1-4.1", "description": "There is no automated remediation for this rule and this is intentional.\nMore details in the rule description.", "props": [ @@ -5135,7 +5387,7 @@ ] }, { - "uuid": "1e3ec75c-3336-448f-b10b-351ae2aa1e5a", + "uuid": "c49b2f67-15a9-49fa-8711-42a610974753", "control-id": "cis_rhel10_1-4.2", "description": "REPLACE_ME", "props": [ @@ -5178,25 +5430,8 @@ ] }, { - "uuid": "4f3d8cdf-0c37-46ac-9e63-c4246e1949f1", + "uuid": "d68f7933-9a67-4484-a101-7ddfc1d5387d", "control-id": "cis_rhel10_1-5.1", - "description": "Address Space Layout Randomization (ASLR)", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_kernel_randomize_va_space" - } - ] - }, - { - "uuid": "d5a4fc94-d5d9-4362-b342-68fd3a0ab927", - "control-id": "cis_rhel10_1-5.2", "description": "REPLACE_ME", "props": [ { @@ -5207,13 +5442,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_kernel_yama_ptrace_scope" + "value": "disable_users_coredumps" } ] }, { - "uuid": "d400ebec-2c40-4863-a063-733809757c56", - "control-id": "cis_rhel10_1-5.3", + "uuid": "fd875de2-125a-4045-bd1f-f2baa89ea430", + "control-id": "cis_rhel10_1-5.2", "description": "REPLACE_ME", "props": [ { @@ -5224,12 +5459,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_backtraces" + "value": "sysctl_fs_protected_hardlinks" } ] }, { - "uuid": "aacffb0b-8eb6-4166-baad-6cb095c0626a", + "uuid": "0c61af4c-cc84-4e49-a5ae-ede1488be502", "control-id": "cis_rhel10_1-5.4", "description": "REPLACE_ME", "props": [ @@ -5241,12 +5476,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_storage" + "value": "sysctl_fs_suid_dumpable" } ] }, { - "uuid": "1e369f46-5c17-476d-a678-8a5bde9da304", + "uuid": "15e70b6f-5ed6-45bb-8739-edff213ca8d5", "control-id": "cis_rhel10_1-6.1", "description": "REPLACE_ME", "props": [ @@ -5263,37 +5498,21 @@ ] }, { - "uuid": "a29de4b5-983e-4766-8d31-398ddda7d4c9", + "uuid": "83e1151c-52b6-4dc3-9191-d2987b4e3225", "control-id": "cis_rhel10_1-6.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_ssh_crypto_policy" + "value": "alternative", + "remarks": "It is necessary a new rule to ensure a module disabling sha1 in\n/etc/crypto-policies/policies/modules/ so it can be used by update-crypto-policies command." } ] }, { - "uuid": "4b015a5f-54b5-4847-85a8-3732b6d23431", + "uuid": "df66c99b-23f0-415c-b3e9-cfd5800b90c0", "control-id": "cis_rhel10_1-6.3", - "description": "This requirement is already satisfied by 1.6.1.", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - } - ] - }, - { - "uuid": "a923c547-49e1-42a8-80db-2bb138b4b713", - "control-id": "cis_rhel10_1-6.4", "description": "REPLACE_ME", "props": [ { @@ -5305,8 +5524,8 @@ ] }, { - "uuid": "b17d8eb8-a441-4b2d-ab86-d84cc42fb404", - "control-id": "cis_rhel10_1-6.5", + "uuid": "e860b4bf-49bd-4d71-be60-dc1a0f4f215d", + "control-id": "cis_rhel10_1-6.4", "description": "REPLACE_ME", "props": [ { @@ -5318,33 +5537,7 @@ ] }, { - "uuid": "032570cb-05cc-410e-ac8c-facac1136521", - "control-id": "cis_rhel10_1-6.6", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } - ] - }, - { - "uuid": "8e69c91f-39c7-4d65-863d-4da060a660d6", - "control-id": "cis_rhel10_1-6.7", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } - ] - }, - { - "uuid": "909e663e-ac0a-4054-b388-71386f2c5265", + "uuid": "7096989a-a335-4bdd-9620-369da0357877", "control-id": "cis_rhel10_1-7.1", "description": "REPLACE_ME", "props": [ @@ -5361,7 +5554,7 @@ ] }, { - "uuid": "1d3cd44b-08bf-4a71-8e69-a74c49d9983d", + "uuid": "c91829fb-ee87-4f60-95b6-495d8fd52228", "control-id": "cis_rhel10_1-7.2", "description": "REPLACE_ME", "props": [ @@ -5378,7 +5571,7 @@ ] }, { - "uuid": "a3d1a2be-a17f-4a43-8b19-50a2b83d5d56", + "uuid": "cc27118a-ae4a-469e-949a-b3f6c6318e5f", "control-id": "cis_rhel10_1-7.3", "description": "REPLACE_ME", "props": [ @@ -5395,7 +5588,7 @@ ] }, { - "uuid": "75abd42e-6587-407d-9930-06059096b2e3", + "uuid": "4a574f2e-e10e-4f6b-a80d-7476a966ab57", "control-id": "cis_rhel10_1-7.4", "description": "REPLACE_ME", "props": [ @@ -5422,7 +5615,7 @@ ] }, { - "uuid": "51b3c8c7-334c-4fc1-aade-75b08ebdf857", + "uuid": "f2759af1-e550-4258-8a37-997b31b0a2cc", "control-id": "cis_rhel10_1-7.5", "description": "REPLACE_ME", "props": [ @@ -5449,7 +5642,7 @@ ] }, { - "uuid": "fcad9d7a-5edc-4d5a-8141-a0a642baf49a", + "uuid": "f4989300-28a6-4d84-8d02-7a4c484d5124", "control-id": "cis_rhel10_1-7.6", "description": "REPLACE_ME", "props": [ @@ -5476,31 +5669,9 @@ ] }, { - "uuid": "d47fbf2c-87b2-45b2-9ebc-b13782a8d4cd", + "uuid": "5d6b91a1-44c6-48b4-9c92-15fdced807a6", "control-id": "cis_rhel10_1-8.2", "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_banner_enabled" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_login_banner_text" - } - ] - }, - { - "uuid": "38ff63ad-003f-489e-b2c2-9f0eaf5384a4", - "control-id": "cis_rhel10_1-8.3", - "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -5515,8 +5686,8 @@ ] }, { - "uuid": "3966c83e-f788-4e43-9c66-6f5baf226066", - "control-id": "cis_rhel10_1-8.4", + "uuid": "1545f95f-704e-4827-9fe7-286052d3080a", + "control-id": "cis_rhel10_1-8.3", "description": "REPLACE_ME", "props": [ { @@ -5533,18 +5704,6 @@ "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_screensaver_lock_delay" - } - ] - }, - { - "uuid": "f29c57e9-ecf4-4ae7-a7fc-d04f36f73746", - "control-id": "cis_rhel10_1-8.5", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" }, { "name": "Rule_Id", @@ -5559,25 +5718,8 @@ ] }, { - "uuid": "61b835c7-7add-456e-b732-1385acd16ad4", - "control-id": "cis_rhel10_1-8.8", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_autorun" - } - ] - }, - { - "uuid": "c1f3c1de-d461-4ff6-bcea-38f38eb12531", - "control-id": "cis_rhel10_1-8.9", + "uuid": "f03c745b-fb10-4f6e-87d6-29527b681944", + "control-id": "cis_rhel10_1-8.5", "description": "REPLACE_ME", "props": [ { @@ -5593,36 +5735,7 @@ ] }, { - "uuid": "bf61c5ba-4075-42ca-b233-2e0d58de5104", - "control-id": "cis_rhel10_1-8.10", - "description": "This was inherited from the RHEL 9 profile.\nHowever, it was reported that XDMCP is no\nlonger in RHEL 10.", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - } - ] - }, - { - "uuid": "e6d72a14-1397-4061-9e6e-7a6f45b921a4", - "control-id": "cis_rhel10_2-1.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_kea_removed" - } - ] - }, - { - "uuid": "f91c34d2-96c4-49cd-8962-330234ad5e27", + "uuid": "79cdb4c3-b367-4aac-add0-7c068ef52306", "control-id": "cis_rhel10_2-1.4", "description": "REPLACE_ME", "props": [ @@ -5634,12 +5747,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_bind_removed" + "value": "package_kea_removed" } ] }, { - "uuid": "cfa779c5-bae4-4da4-90f5-e98630ef3197", + "uuid": "545a835b-61bc-422a-9a14-b119b5e8b27e", "control-id": "cis_rhel10_2-1.5", "description": "REPLACE_ME", "props": [ @@ -5651,12 +5764,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_dnsmasq_removed" + "value": "package_bind_removed" } ] }, { - "uuid": "6d8b2707-271f-452a-b066-22a9e478a934", + "uuid": "a5753139-39da-47e7-917e-18aa2c64f201", "control-id": "cis_rhel10_2-1.6", "description": "REPLACE_ME", "props": [ @@ -5668,12 +5781,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_samba_removed" + "value": "package_dnsmasq_removed" } ] }, { - "uuid": "1ca7aab0-9cc8-4928-bf61-8fed80018cb5", + "uuid": "8d8ef211-968d-4bd3-a9ad-dfe737bc1b2b", "control-id": "cis_rhel10_2-1.7", "description": "REPLACE_ME", "props": [ @@ -5690,7 +5803,7 @@ ] }, { - "uuid": "1d4dbe35-54f9-4bd1-9779-d1722ac5cdc7", + "uuid": "8bf65c10-bea3-4c8c-a0e4-be1696b8916d", "control-id": "cis_rhel10_2-1.8", "description": "REPLACE_ME", "props": [ @@ -5712,7 +5825,7 @@ ] }, { - "uuid": "a5522cb1-ce7d-4365-a5ab-4d41ace1acb4", + "uuid": "c95dfe56-2d60-4524-8a1e-3cccbabbf776", "control-id": "cis_rhel10_2-1.9", "description": "Many of the libvirt packages used by Enterprise Linux virtualization are dependent on the\nnfs-utils package.", "props": [ @@ -5729,21 +5842,9 @@ ] }, { - "uuid": "e3724807-b77b-460c-8ed1-de4c7f259f92", - "control-id": "cis_rhel10_2-1.10", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - } - ] - }, - { - "uuid": "8258d58c-d04b-4b6b-98cd-5bf5e477636d", + "uuid": "f3e5e929-3775-4baa-8080-8a14297a4783", "control-id": "cis_rhel10_2-1.12", - "description": "Many of the libvirt packages used by Enterprise Linux virtualization, and the nfs-utils\npackage used for The Network File System (NFS), are dependent on the rpcbind package.", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -5753,12 +5854,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_rpcbind_disabled" + "value": "package_rsync_removed" } ] }, { - "uuid": "c4c9fbb5-f9ef-4b01-98bd-e4a842bd3faa", + "uuid": "d3acddc7-e870-4a1c-a8e6-b7a90008ca79", "control-id": "cis_rhel10_2-1.13", "description": "REPLACE_ME", "props": [ @@ -5770,12 +5871,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_rsync_removed" + "value": "package_samba_removed" } ] }, { - "uuid": "aaa144fb-b6ea-4670-894f-32ae01252b9b", + "uuid": "c1fe2594-367e-42d3-9a01-5fee1dd4134f", "control-id": "cis_rhel10_2-1.14", "description": "REPLACE_ME", "props": [ @@ -5792,7 +5893,7 @@ ] }, { - "uuid": "e509d5e9-2e24-46ad-8c22-95b5ef21379d", + "uuid": "74854bcf-014f-4ddb-87a3-ff7cc0f07c29", "control-id": "cis_rhel10_2-1.15", "description": "REPLACE_ME", "props": [ @@ -5809,7 +5910,7 @@ ] }, { - "uuid": "b1dbeb5c-e0f5-48f8-a08b-2b3eea216384", + "uuid": "d1479e6e-4177-4043-9e10-f0a53905fc39", "control-id": "cis_rhel10_2-1.16", "description": "REPLACE_ME", "props": [ @@ -5826,7 +5927,7 @@ ] }, { - "uuid": "6c459d22-f697-4612-9ee9-18fb1fe2c0f4", + "uuid": "75a275b5-50af-4f38-9f42-c59d927b09c2", "control-id": "cis_rhel10_2-1.17", "description": "REPLACE_ME", "props": [ @@ -5843,7 +5944,7 @@ ] }, { - "uuid": "2ae0bf42-d33f-47b9-af83-e02c75ddf853", + "uuid": "a02e0de4-a2bf-418a-a041-49a9416ea829", "control-id": "cis_rhel10_2-1.18", "description": "REPLACE_ME", "props": [ @@ -5865,7 +5966,7 @@ ] }, { - "uuid": "d0be9aca-2e64-49b1-8582-fce6ae83b577", + "uuid": "48a08a9e-6f83-47f7-91d3-a26b7791037f", "control-id": "cis_rhel10_2-1.21", "description": "The rule has_nonlocal_mta currently checks for services listening only on port 25,\nbut the policy checks also for ports 465 and 587", "props": [ @@ -5887,7 +5988,7 @@ ] }, { - "uuid": "b58587ad-af8d-4770-9439-363a3221d5f9", + "uuid": "d95fe6a3-2791-4c1d-b377-5240c09940f8", "control-id": "cis_rhel10_2-1.22", "description": "REPLACE_ME", "props": [ @@ -5900,7 +6001,7 @@ ] }, { - "uuid": "5d01c14f-3754-47d0-bb5f-447081780a1b", + "uuid": "21be8db6-3632-4a09-82fc-d643d78fc5e3", "control-id": "cis_rhel10_2-2.1", "description": "REPLACE_ME", "props": [ @@ -5917,21 +6018,9 @@ ] }, { - "uuid": "878d2b33-5828-4b6c-9a20-2c0237d267c1", + "uuid": "b78b2318-3448-4073-b9f4-f0c513758715", "control-id": "cis_rhel10_2-2.3", "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - } - ] - }, - { - "uuid": "839fb623-1b96-4e12-aaee-47c902e6f480", - "control-id": "cis_rhel10_2-2.4", - "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -5946,8 +6035,8 @@ ] }, { - "uuid": "7f6f6f25-a9ee-401d-a219-6b1c2077a05a", - "control-id": "cis_rhel10_2-2.5", + "uuid": "a4e9cea1-1acd-4bd5-8e2d-1f0bd5c32354", + "control-id": "cis_rhel10_2-2.4", "description": "REPLACE_ME", "props": [ { @@ -5963,7 +6052,7 @@ ] }, { - "uuid": "ed840695-9d07-4ea7-ba42-5185ae1bb9f3", + "uuid": "96873542-b1b4-43de-a19b-b16a983fba4c", "control-id": "cis_rhel10_2-3.1", "description": "REPLACE_ME", "props": [ @@ -5975,7 +6064,7 @@ ] }, { - "uuid": "b0d1e533-b951-4cff-8b54-63d600435e49", + "uuid": "3e5377bb-07dd-47a8-9a44-98282238fa74", "control-id": "cis_rhel10_2-3.2", "description": "REPLACE_ME", "props": [ @@ -5992,7 +6081,7 @@ ] }, { - "uuid": "2e060fca-4e6e-49d1-8730-a4371d1305d4", + "uuid": "a5ecf49d-5d30-4ddf-952e-c948f85ac219", "control-id": "cis_rhel10_2-3.3", "description": "REPLACE_ME", "props": [ @@ -6009,7 +6098,7 @@ ] }, { - "uuid": "7fcbeae2-9878-4251-9140-e1cba14c3a38", + "uuid": "5d1facdc-b75b-4862-b9ba-604d5f869453", "control-id": "cis_rhel10_2-4.1.1", "description": "REPLACE_ME", "props": [ @@ -6031,7 +6120,7 @@ ] }, { - "uuid": "f4be5344-8499-4932-a9fa-a7ff53cf3301", + "uuid": "a8551ff3-965c-4f18-97a2-85f8c08ce6b6", "control-id": "cis_rhel10_2-4.1.2", "description": "REPLACE_ME", "props": [ @@ -6058,7 +6147,7 @@ ] }, { - "uuid": "4da999ca-3cf8-41a5-8b07-bc947817a5c0", + "uuid": "525ce4f1-cd6a-49d9-b3d9-125689e06879", "control-id": "cis_rhel10_2-4.1.3", "description": "REPLACE_ME", "props": [ @@ -6085,7 +6174,7 @@ ] }, { - "uuid": "6c265eed-ac29-4403-93fc-55b768e50b02", + "uuid": "6bac759e-456d-4356-8aae-c8f4773d84fd", "control-id": "cis_rhel10_2-4.1.4", "description": "REPLACE_ME", "props": [ @@ -6112,7 +6201,7 @@ ] }, { - "uuid": "6e2c41d0-d12e-4c3f-ba05-7e05c8b4a4fc", + "uuid": "0e4c8d56-49b1-4b08-ba9f-b161b201f451", "control-id": "cis_rhel10_2-4.1.5", "description": "REPLACE_ME", "props": [ @@ -6139,7 +6228,7 @@ ] }, { - "uuid": "99a5dd9a-191c-40fc-8063-98e5bc7052d8", + "uuid": "aba83adf-1d37-4072-9823-482298933108", "control-id": "cis_rhel10_2-4.1.6", "description": "REPLACE_ME", "props": [ @@ -6166,34 +6255,20 @@ ] }, { - "uuid": "75992dad-2cb5-496d-996d-640de4621cf2", + "uuid": "93f334f3-2f04-43b3-be30-4992857a74af", "control-id": "cis_rhel10_2-4.1.7", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_d" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_d" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_d" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "989b6568-66a3-46fa-b734-088bb2b2e1ba", + "uuid": "70b02165-0bd6-4d67-a6d3-0b8d11c06d1b", "control-id": "cis_rhel10_2-4.1.8", "description": "REPLACE_ME", "props": [ @@ -6205,32 +6280,22 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_cron_deny_not_exist" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_cron_allow_exists" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_allow" + "value": "file_groupowner_cron_d" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_allow" + "value": "file_owner_cron_d" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_allow" + "value": "file_permissions_cron_d" } ] }, { - "uuid": "5375b2c7-cf24-46c6-9cea-1405642a2707", + "uuid": "aeeea3e2-00d9-4da8-8041-bb441f45895e", "control-id": "cis_rhel10_2-4.2.1", "description": "It is necessary to create a rule to ensure the existence of at.allow.\nfile_cron_allow_exists can be used as reference for a new templated rule.", "props": [ @@ -6262,7 +6327,7 @@ ] }, { - "uuid": "5e4c0a2b-fcfe-49d5-bf97-3bdea9eb90c7", + "uuid": "85dec517-efda-4a15-a0f0-e01a458aee4a", "control-id": "cis_rhel10_3-1.1", "description": "REPLACE_ME", "props": [ @@ -6275,8 +6340,8 @@ ] }, { - "uuid": "b15295a0-a5a3-42fa-b32d-0bc7d20c204b", - "control-id": "cis_rhel10_3-3.1", + "uuid": "77b187e5-38ed-464d-a157-93fc9f6e1bfd", + "control-id": "cis_rhel10_4-1.1", "description": "REPLACE_ME", "props": [ { @@ -6287,40 +6352,26 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_ip_forward" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_forwarding" + "value": "package_firewalld_installed" } ] }, { - "uuid": "058b7d71-0ddf-426a-9271-54ae2e3ad88e", - "control-id": "cis_rhel10_3-3.2", + "uuid": "e253be78-81c2-4854-83e9-4ac311b71db5", + "control-id": "cis_rhel10_4-1.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_send_redirects" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_send_redirects" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "58c9a112-730e-4247-84aa-55550d2eb057", - "control-id": "cis_rhel10_3-3.3", + "uuid": "b64048e1-c05c-4427-b3ec-562fc3eb1ab4", + "control-id": "cis_rhel10_5-1.1", "description": "REPLACE_ME", "props": [ { @@ -6331,30 +6382,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses" - } - ] - }, - { - "uuid": "788d0ea3-d64d-4108-a6b0-ab45dfc9563b", - "control-id": "cis_rhel10_3-3.4", - "description": "REPLACE_ME", - "props": [ + "value": "file_groupowner_sshd_config" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "file_owner_sshd_config" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts" + "value": "file_permissions_sshd_config" } ] }, { - "uuid": "9265edd2-e892-4484-a226-a2bc89702c2f", - "control-id": "cis_rhel10_3-3.5", + "uuid": "592220d7-3787-40fa-975d-492b72ce174f", + "control-id": "cis_rhel10_5-1.2", "description": "REPLACE_ME", "props": [ { @@ -6365,28 +6409,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_accept_redirects" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_accept_redirects" + "value": "file_groupownership_sshd_private_key" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_redirects" + "value": "file_ownership_sshd_private_key" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_redirects" + "value": "file_permissions_sshd_private_key" } ] }, { - "uuid": "0c1155b8-8e61-4bfe-bcc2-3881e8e9a8c7", - "control-id": "cis_rhel10_3-3.6", + "uuid": "bd7ce5df-bc72-4105-8b00-aadecf0ec010", + "control-id": "cis_rhel10_5-1.3", "description": "REPLACE_ME", "props": [ { @@ -6397,18 +6436,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_secure_redirects" + "value": "file_groupownership_sshd_pub_key" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_ownership_sshd_pub_key" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_secure_redirects" + "value": "file_permissions_sshd_pub_key" } ] }, { - "uuid": "0f5a5c23-ff3a-4025-8e60-4e71f2592444", - "control-id": "cis_rhel10_3-3.7", + "uuid": "6723e79a-d16f-402a-add0-b8e3b0c58421", + "control-id": "cis_rhel10_5-1.4", "description": "REPLACE_ME", "props": [ { @@ -6419,18 +6463,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_rp_filter" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_rp_filter" + "value": "sshd_limit_user_access" } ] }, { - "uuid": "a890f290-1cc1-45e0-abda-f0f522adac7a", - "control-id": "cis_rhel10_3-3.8", + "uuid": "a7fc2803-5b97-491c-a14a-f79067ebd749", + "control-id": "cis_rhel10_5-1.5", "description": "REPLACE_ME", "props": [ { @@ -6441,29 +6480,26 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_accept_source_route" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_accept_source_route" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_source_route" - }, + "value": "sshd_enable_warning_banner_net" + } + ] + }, + { + "uuid": "bf07c787-974d-4354-9138-245e87268587", + "control-id": "cis_rhel10_5-1.6", + "description": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation.", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_source_route" + "value": "implemented" } ] }, { - "uuid": "bd5448ff-028e-4274-b170-440e7b82a286", - "control-id": "cis_rhel10_3-3.9", - "description": "REPLACE_ME", + "uuid": "32677c18-05d6-4836-b034-11e499ee091a", + "control-id": "cis_rhel10_5-1.7", + "description": "The requirement gives an example of 45 seconds, but is flexible about the values. It is only\nnecessary to ensure there is a timeout configured in alignment to the site policy.", "props": [ { "name": "implementation-status", @@ -6473,18 +6509,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_log_martians" + "value": "sshd_set_idle_timeout" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_log_martians" + "value": "sshd_set_keepalive" } ] }, { - "uuid": "a77eee4e-a840-4d0e-ad85-e120009abf4a", - "control-id": "cis_rhel10_3-3.10", + "uuid": "5deb258b-7b40-4968-931f-2f23fb72743c", + "control-id": "cis_rhel10_5-1.8", "description": "REPLACE_ME", "props": [ { @@ -6495,13 +6531,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_tcp_syncookies" + "value": "sshd_disable_forwarding" } ] }, { - "uuid": "8f85fda0-dee9-49b2-ab2c-e622a42d46be", - "control-id": "cis_rhel10_3-3.11", + "uuid": "dcd60fcd-37c6-4c38-8eee-6175a96faf8d", + "control-id": "cis_rhel10_5-1.9", "description": "REPLACE_ME", "props": [ { @@ -6512,18 +6548,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_ra" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_ra" + "value": "sshd_disable_gssapi_auth" } ] }, { - "uuid": "6aa6ce7a-804c-47b8-af5e-fa4e09bb8791", - "control-id": "cis_rhel10_4-1.1", + "uuid": "d086eb4c-31d5-4912-a3cf-d91b5e399c2b", + "control-id": "cis_rhel10_5-1.10", "description": "REPLACE_ME", "props": [ { @@ -6534,13 +6565,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_nftables_installed" + "value": "disable_host_auth" } ] }, { - "uuid": "9c926df2-d42b-460e-b727-7ce265f105cf", - "control-id": "cis_rhel10_4-1.2", + "uuid": "8693d39c-e665-4dbe-8e78-72c3cdbb7bf9", + "control-id": "cis_rhel10_5-1.11", "description": "REPLACE_ME", "props": [ { @@ -6551,36 +6582,31 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_firewalld_enabled" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_firewalld_installed" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_nftables_disabled" + "value": "sshd_disable_rhosts" } ] }, { - "uuid": "da8eab83-b5d0-4095-9cb3-da92585c88ba", - "control-id": "cis_rhel10_4-2.1", + "uuid": "f1276bb2-5ffe-4bfe-b24a-b921894de964", + "control-id": "cis_rhel10_5-1.12", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "alternative", - "remarks": "REPLACE_ME" + "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_use_strong_kex" } ] }, { - "uuid": "5b6f7b8a-35ff-47e5-8bf6-0cff82a50c13", - "control-id": "cis_rhel10_4-2.2", + "uuid": "085bada6-7ce0-45b4-8f3f-fd1460cab2d3", + "control-id": "cis_rhel10_5-1.13", "description": "REPLACE_ME", "props": [ { @@ -6591,67 +6617,82 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "firewalld_loopback_traffic_trusted" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "firewalld_loopback_traffic_restricted" + "value": "sshd_set_login_grace_time" } ] }, { - "uuid": "11503ebf-92b3-45c2-91b4-735ddad7c031", - "control-id": "cis_rhel10_4-3.1", - "description": "RHEL systems use firewalld for firewall management. Although nftables is the default\nback-end for firewalld, it is not recommended to use nftables directly when firewalld\nis in use. When using firewalld the base chains are installed by default.", + "uuid": "1f791cc4-60a0-4d6e-ba51-0b053c42ae8f", + "control-id": "cis_rhel10_5-1.14", + "description": "The CIS benchmark is not opinionated about which loglevel is selected here. Here, this\nprofile uses VERBOSE by default, as it allows for the capture of login and logout activity\nas well as key fingerprints.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_set_loglevel_verbose" } ] }, { - "uuid": "648f7d57-6b18-48ef-914a-cfce28be4cf8", - "control-id": "cis_rhel10_4-3.2", + "uuid": "5aa800b6-0275-4c58-95e0-71dc5b428daf", + "control-id": "cis_rhel10_5-1.15", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "alternative", - "remarks": "REPLACE_ME" + "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_use_strong_macs" } ] }, { - "uuid": "c02e6ef0-2d2a-4ef2-8636-00bf5293aff2", - "control-id": "cis_rhel10_4-3.3", - "description": "RHEL systems use firewalld for firewall management. Although nftables is the default\nback-end for firewalld, it is not recommended to use nftables directly when firewalld\nis in use.", + "uuid": "9288b03a-659a-4201-ac96-88353c7d90bb", + "control-id": "cis_rhel10_5-1.16", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_set_max_auth_tries" } ] }, { - "uuid": "08b93946-0ed6-4dff-b4f4-34b8b0dc5420", - "control-id": "cis_rhel10_4-3.4", - "description": "RHEL systems use firewalld for firewall management. Although nftables is the default\nback-end for firewalld, it is not recommended to use nftables directly when firewalld\nis in use.", + "uuid": "66031c87-5e6d-4f04-a13d-4c87e1b363bc", + "control-id": "cis_rhel10_5-1.17", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_set_maxstartups" } ] }, { - "uuid": "1ff19fb2-bf46-4eeb-9ab2-a0c6ffeb0990", - "control-id": "cis_rhel10_5-1.1", + "uuid": "c3544568-1513-49b3-9f49-20acc4758ad4", + "control-id": "cis_rhel10_5-1.18", "description": "REPLACE_ME", "props": [ { @@ -6662,23 +6703,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_sshd_config" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_sshd_config" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_config" + "value": "sshd_set_max_sessions" } ] }, { - "uuid": "1f79f32d-6549-4774-96e7-55eaf807e5d9", - "control-id": "cis_rhel10_5-1.2", + "uuid": "2c81a833-928b-45cb-8a60-66ce4de611f3", + "control-id": "cis_rhel10_5-1.19", "description": "REPLACE_ME", "props": [ { @@ -6689,23 +6720,30 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_private_key" - }, + "value": "sshd_disable_empty_passwords" + } + ] + }, + { + "uuid": "9b1109af-1999-4d54-a8cd-9f9f3f3b7847", + "control-id": "cis_rhel10_5-1.20", + "description": "REPLACE_ME", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_private_key" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_sshd_private_key" + "value": "sshd_disable_root_login" } ] }, { - "uuid": "1960451a-45eb-4ed3-857e-b6ed67c220d6", - "control-id": "cis_rhel10_5-1.3", + "uuid": "b614ca0a-49f8-4abd-b1c2-ca091be65c68", + "control-id": "cis_rhel10_5-1.21", "description": "REPLACE_ME", "props": [ { @@ -6716,72 +6754,81 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_pub_key" - }, + "value": "sshd_do_not_permit_user_env" + } + ] + }, + { + "uuid": "89a351fb-87bf-4f8b-97cd-4046f19ba49e", + "control-id": "cis_rhel10_5-1.22", + "description": "REPLACE_ME", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_pub_key" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_sshd_pub_key" + "value": "sshd_enable_pam" } ] }, { - "uuid": "540c354d-43db-4f75-9ab3-0b5319ea85bf", - "control-id": "cis_rhel10_5-1.4", + "uuid": "ba4ee0e6-835d-49ec-b42c-fab563787fcb", + "control-id": "cis_rhel10_5-2.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "package_sudo_installed" } ] }, { - "uuid": "369a803d-b0c9-4940-af98-f0b4d4434f51", - "control-id": "cis_rhel10_5-1.5", + "uuid": "abe76d55-56a2-4552-a96b-9ef107d164b2", + "control-id": "cis_rhel10_5-2.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_kex" + "value": "sudo_add_use_pty" } ] }, { - "uuid": "cb4ec9dc-6226-4996-883a-a6ad9febf9ae", - "control-id": "cis_rhel10_5-1.6", + "uuid": "28c1be99-7364-4110-85ab-935657f8157e", + "control-id": "cis_rhel10_5-2.3", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_macs" + "value": "sudo_custom_logfile" } ] }, { - "uuid": "a5a1b547-1150-4ac6-97db-a611b5f45bd4", - "control-id": "cis_rhel10_5-1.7", + "uuid": "ed60998d-bd65-4ce2-8ddf-7db91c9de850", + "control-id": "cis_rhel10_5-2.5", "description": "REPLACE_ME", "props": [ { @@ -6792,13 +6839,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_limit_user_access" + "value": "sudo_require_authentication" } ] }, { - "uuid": "1556c0db-76b6-4670-81b3-3ee4e287c9f5", - "control-id": "cis_rhel10_5-1.8", + "uuid": "95058fc6-2209-4bd3-bb1c-43698d786727", + "control-id": "cis_rhel10_5-2.6", "description": "REPLACE_ME", "props": [ { @@ -6809,14 +6856,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_enable_warning_banner_net" + "value": "sudo_require_reauthentication" } ] }, { - "uuid": "f9b040a2-111d-4ca1-988d-14020d2978dd", - "control-id": "cis_rhel10_5-1.9", - "description": "The requirement gives an example of 45 seconds, but is flexible about the values. It is only\nnecessary to ensure there is a timeout configured in alignment to the site policy.", + "uuid": "0bea657c-b0ec-40ab-9a9a-abbdfdcf080c", + "control-id": "cis_rhel10_5-2.7", + "description": "Members of \"wheel\" or GID 0 groups are checked by default if the group option is not set for\npam_wheel.so module. The recommendation states the group should be empty to reinforce the\nuse of \"sudo\" for privileged access. Therefore, members of these groups should be manually\nchecked or a different group should be informed.", "props": [ { "name": "implementation-status", @@ -6826,32 +6873,31 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_idle_timeout" + "value": "use_pam_wheel_group_for_su" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_keepalive" + "value": "ensure_pam_wheel_group_empty" } ] }, { - "uuid": "bc0dc169-b4ce-4429-8464-e72b35569e9b", - "control-id": "cis_rhel10_5-1.10", - "description": "REPLACE_ME", + "uuid": "474e8d45-ad01-484a-8e72-6185323d6d26", + "control-id": "cis_rhel10_5-3.1.1", + "description": "This requirement is hard to be automated without any specific requirement. The policy even\nstates that provided commands are examples, other custom settings might be in place and the\nsettings might be different depending on site policies. The other rules will already make\nsure there is a correct autheselect profile regardless of the existing settings. It is\nnecessary to better discuss with CIS Community.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "New templated rule is necessary for \"disableforwarding\" option." + "value": "partial" } ] }, { - "uuid": "74ce0750-fee9-41e2-97d1-27f0dd810e06", - "control-id": "cis_rhel10_5-1.11", - "description": "REPLACE_ME", + "uuid": "0ae11b1e-9caa-4dd5-b215-e8cc2a900681", + "control-id": "cis_rhel10_5-3.1.2", + "description": "This requirement is also indirectly satisfied by the requirement 5.3.2.1.", "props": [ { "name": "implementation-status", @@ -6861,14 +6907,19 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_gssapi_auth" + "value": "account_password_pam_faillock_password_auth" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "account_password_pam_faillock_system_auth" } ] }, { - "uuid": "77fd6810-7eca-4af2-8456-2460463d670f", - "control-id": "cis_rhel10_5-1.12", - "description": "REPLACE_ME", + "uuid": "227a1ee7-40a6-49cd-8de9-085799d73197", + "control-id": "cis_rhel10_5-3.1.3", + "description": "This requirement is also indirectly satisfied by the requirement 5.3.2.2.", "props": [ { "name": "implementation-status", @@ -6878,13 +6929,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "disable_host_auth" + "value": "package_pam_pwquality_installed" } ] }, { - "uuid": "9e5b87e5-3d41-49bb-a7e0-52f4436b17c7", - "control-id": "cis_rhel10_5-1.13", + "uuid": "45865bd4-05d9-4eff-9f75-7b716acec2ec", + "control-id": "cis_rhel10_5-4.1.1", "description": "REPLACE_ME", "props": [ { @@ -6895,13 +6946,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_rhosts" + "value": "accounts_maximum_age_login_defs" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_password_set_max_life_existing" } ] }, { - "uuid": "edea1ffc-96a2-4666-9248-bee72775e19c", - "control-id": "cis_rhel10_5-1.14", + "uuid": "4a231274-1f34-4573-bc5c-c97133da72f1", + "control-id": "cis_rhel10_5-4.1.3", "description": "REPLACE_ME", "props": [ { @@ -6912,14 +6968,19 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_login_grace_time" + "value": "accounts_password_warn_age_login_defs" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_password_set_warn_age_existing" } ] }, { - "uuid": "dc94e96b-05d8-4569-8f04-6e3973ce2547", - "control-id": "cis_rhel10_5-1.15", - "description": "The CIS benchmark is not opinionated about which loglevel is selected here. Here, this\nprofile uses VERBOSE by default, as it allows for the capture of login and logout activity\nas well as key fingerprints.", + "uuid": "05f9e6ad-69b8-4545-97f5-202a49003b53", + "control-id": "cis_rhel10_5-4.1.4", + "description": "There's a \"new\" set of options in /etc/login.defs file to define the number of iterations\nperformed during the hashing process.", "props": [ { "name": "implementation-status", @@ -6929,13 +6990,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_loglevel_verbose" + "value": "set_password_hashing_algorithm_libuserconf" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "set_password_hashing_algorithm_logindefs" } ] }, { - "uuid": "8376cc9d-8a5b-41ee-a978-cec4bfd65ed3", - "control-id": "cis_rhel10_5-1.16", + "uuid": "9a3f3ca9-2783-49b2-bce6-3645d4b83d82", + "control-id": "cis_rhel10_5-4.1.5", "description": "REPLACE_ME", "props": [ { @@ -6946,13 +7012,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_max_auth_tries" + "value": "account_disable_post_pw_expiration" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_set_post_pw_existing" } ] }, { - "uuid": "b3a0da1d-c559-4b08-88d4-24260a06f011", - "control-id": "cis_rhel10_5-1.17", + "uuid": "f771c2c2-cd35-48bf-bf26-e1106e100a2f", + "control-id": "cis_rhel10_5-4.1.6", "description": "REPLACE_ME", "props": [ { @@ -6963,13 +7034,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_maxstartups" + "value": "accounts_password_last_change_is_in_past" } ] }, { - "uuid": "6fd02773-47b9-4d0c-bc34-1767b0616809", - "control-id": "cis_rhel10_5-1.18", + "uuid": "65ac9378-7826-4001-b8dc-2f9265c50950", + "control-id": "cis_rhel10_5-4.2.1", "description": "REPLACE_ME", "props": [ { @@ -6980,30 +7051,30 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_max_sessions" + "value": "accounts_no_uid_except_zero" } ] }, { - "uuid": "f61f099f-fa8d-4ca0-a8fc-6bb9a7fd5c09", - "control-id": "cis_rhel10_5-1.19", - "description": "REPLACE_ME", + "uuid": "f28d445d-a647-4d72-bc0a-04f733cc9cb2", + "control-id": "cis_rhel10_5-4.2.2", + "description": "The rule confirms the primary group for root, but doesn't check if any other user are also\nusing GID 0. New rule is necessary.\nThere is assessment but no automated remediation for this rule and this sounds reasonable.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "partial" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_empty_passwords" + "value": "accounts_root_gid_zero" } ] }, { - "uuid": "33cef94c-1b39-4132-996e-a39f01d77c53", - "control-id": "cis_rhel10_5-1.20", + "uuid": "a1903101-c45a-4088-8778-46d357d564a8", + "control-id": "cis_rhel10_5-4.2.3", "description": "REPLACE_ME", "props": [ { @@ -7014,13 +7085,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_root_login" + "value": "groups_no_zero_gid_except_root" } ] }, { - "uuid": "1f07f1c4-ccc5-4581-b42b-e368a234d711", - "control-id": "cis_rhel10_5-1.21", + "uuid": "42c5fd65-0061-432b-b5f7-1c1ddf3634ee", + "control-id": "cis_rhel10_5-4.2.4", "description": "REPLACE_ME", "props": [ { @@ -7031,13 +7102,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_do_not_permit_user_env" + "value": "ensure_root_password_configured" } ] }, { - "uuid": "0bde7748-8dc8-4a53-b65f-f06b684ef672", - "control-id": "cis_rhel10_5-1.22", + "uuid": "0c801fb8-4da6-4c77-bdca-b882c5b975fa", + "control-id": "cis_rhel10_5-4.2.5", "description": "REPLACE_ME", "props": [ { @@ -7048,13 +7119,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_enable_pam" + "value": "accounts_root_path_dirs_no_write" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "root_path_no_dot" } ] }, { - "uuid": "2c7dc711-e86b-4954-94d2-0894c6468a29", - "control-id": "cis_rhel10_5-2.1", + "uuid": "c402bfbc-58cb-4804-9334-82badf08fab2", + "control-id": "cis_rhel10_5-4.2.6", "description": "REPLACE_ME", "props": [ { @@ -7065,13 +7141,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_sudo_installed" + "value": "accounts_umask_root" } ] }, { - "uuid": "8aef813e-1677-4113-bc8e-ad971ce31a30", - "control-id": "cis_rhel10_5-2.2", + "uuid": "ab7ebb5a-d765-48d6-bad5-7c0a1e800e13", + "control-id": "cis_rhel10_5-4.2.7", "description": "REPLACE_ME", "props": [ { @@ -7082,30 +7158,30 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_add_use_pty" + "value": "no_password_auth_for_systemaccounts" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "no_shelllogin_for_systemaccounts" } ] }, { - "uuid": "a0bb88f9-39b8-4bad-8f0d-adf236a6652e", - "control-id": "cis_rhel10_5-2.3", - "description": "REPLACE_ME", + "uuid": "3a775a4a-dfba-4626-b9bb-7317b8165459", + "control-id": "cis_rhel10_5-4.2.8", + "description": "New rule is necessary.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_custom_logfile" } ] }, { - "uuid": "75f2ce3b-4f4e-4256-944e-9e8b0d48e8c4", - "control-id": "cis_rhel10_5-2.5", + "uuid": "447d7f33-89bc-44ca-b675-d1b617c9b1fe", + "control-id": "cis_rhel10_5-4.3.2", "description": "REPLACE_ME", "props": [ { @@ -7116,13 +7192,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_require_reauthentication" + "value": "accounts_tmout" } ] }, { - "uuid": "4320da55-0d9d-466d-bb70-028598e7acfe", - "control-id": "cis_rhel10_5-2.6", + "uuid": "7614dec1-2119-4413-a66d-5843081d317a", + "control-id": "cis_rhel10_5-4.3.3", "description": "REPLACE_ME", "props": [ { @@ -7133,14 +7209,24 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_require_reauthentication" + "value": "accounts_umask_etc_bashrc" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_umask_etc_login_defs" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_umask_etc_profile" } ] }, { - "uuid": "22f8f4eb-4736-4a78-842c-f92f489b4dee", - "control-id": "cis_rhel10_5-2.7", - "description": "Members of \"wheel\" or GID 0 groups are checked by default if the group option is not set for\npam_wheel.so module. The recommendation states the group should be empty to reinforce the\nuse of \"sudo\" for privileged access. Therefore, members of these groups should be manually\nchecked or a different group should be informed.", + "uuid": "a909005f-6c65-4919-b3a2-74819318fa61", + "control-id": "cis_rhel10_6-1.1", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -7150,132 +7236,121 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "use_pam_wheel_group_for_su" + "value": "package_aide_installed" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_pam_wheel_group_empty" + "value": "aide_build_database" } ] }, { - "uuid": "3dfd0e16-c6ed-4afa-8a6c-1d3fcf002fb9", - "control-id": "cis_rhel10_5-3.1.1", + "uuid": "bf9498ec-95b9-48f6-a8f2-8c9b9fd4e321", + "control-id": "cis_rhel10_6-1.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary a new rule to ensure PAM package is updated." - } - ] - }, - { - "uuid": "65b0f6cf-b3cc-4b5c-bd68-fb35365e8489", - "control-id": "cis_rhel10_5-3.1.2", - "description": "REPLACE_ME", - "props": [ + "value": "implemented" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary a new rule to ensure authselect package is updated." + "value": "aide_periodic_cron_checking" } ] }, { - "uuid": "ff7352ac-4e06-404b-9801-7d4e0137ade6", - "control-id": "cis_rhel10_5-3.1.3", + "uuid": "c9bf2682-55b9-47a5-8b25-6a886b2fae1b", + "control-id": "cis_rhel10_6-1.3", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary a new rule to ensure libpwquality package is updated." + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_pam_pwquality_installed" + "value": "aide_check_audit_tools" } ] }, { - "uuid": "ab4bc211-a4e6-4b11-b560-3899786d9506", - "control-id": "cis_rhel10_5-3.2.1", - "description": "This requirement is hard to be automated without any specific requirement. The policy even\nstates that provided commands are examples, other custom settings might be in place and the\nsettings might be different depending on site policies. The other rules will already make\nsure there is a correct autheselect profile regardless of the existing settings. It is\nnecessary to better discuss with CIS Community.", + "uuid": "d85d59eb-4f12-4931-8060-2111bef1d5ca", + "control-id": "cis_rhel10_6-2.1.1", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "service_systemd-journald_enabled" } ] }, { - "uuid": "44af564d-3c3d-496b-944d-1ed9d24fd2c9", - "control-id": "cis_rhel10_5-3.2.2", - "description": "This requirement is also indirectly satisfied by the requirement 5.3.3.1.", + "uuid": "ce38618b-d697-45cf-b9e6-3a64231e07d9", + "control-id": "cis_rhel10_6-2.1.2", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_password_auth" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_system_auth" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "1a337a73-5570-45d7-a6a9-82319e89049d", - "control-id": "cis_rhel10_5-3.2.3", - "description": "This requirement is also indirectly satisfied by the requirement 5.3.3.2.", + "uuid": "183aaa4e-8754-4f29-9908-5990e6f78b1f", + "control-id": "cis_rhel10_6-2.1.3", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "7eb3abba-7334-4a76-b4c8-3cffd7b7cdd6", - "control-id": "cis_rhel10_5-3.2.4", - "description": "The module is properly enabled by the rules mentioned in related_rules.\nRequirements in 5.3.3.3 use these rules.", + "uuid": "a660794f-d413-4239-8729-b0a8013abaa6", + "control-id": "cis_rhel10_6-2.1.4", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "alternative", + "remarks": "It is necessary to create a new rule to check the status of journald and rsyslog.\nIt would also be necessary a new rule to disable or remove rsyslog." } ] }, { - "uuid": "87d8ac77-0ac2-46a9-92d5-8e032e993648", - "control-id": "cis_rhel10_5-3.2.5", - "description": "This module is always present by default. It is necessary to investigate if a new rule to\ncheck its existence needs to be created. But so far the rule no_empty_passwords, used in\n5.3.3.4 can ensure this requirement is attended.", + "uuid": "62167d1b-9a87-4a82-8c76-37fe635700fc", + "control-id": "cis_rhel10_6-2.2.2", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "alternative", + "remarks": "This rule conflicts with 6.2.3.3. More investigation is needed to properly solve this." } ] }, { - "uuid": "f30ccfd6-88f1-4e01-8a3c-07065ab4de0f", - "control-id": "cis_rhel10_5-3.3.1.1", + "uuid": "ae502a12-cdb4-43aa-9d8e-8c0ea839828c", + "control-id": "cis_rhel10_6-2.2.3", "description": "REPLACE_ME", "props": [ { @@ -7286,14 +7361,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_deny" + "value": "journald_compress" } ] }, { - "uuid": "4dc102dc-5a62-4572-8dbb-b1c087e3417a", - "control-id": "cis_rhel10_5-3.3.1.2", - "description": "The policy also accepts value 0, which means the locked accounts should be manually unlocked\nby an administrator. However, it also mentions that using value 0 can facilitate a DoS\nattack to legitimate users.", + "uuid": "b5333a02-140e-4fb5-8f8e-f39ca8e69d9d", + "control-id": "cis_rhel10_6-2.2.4", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -7303,13 +7378,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_unlock_time" + "value": "journald_storage" } ] }, { - "uuid": "8d860a9f-5b8d-49ba-8b05-c44381fc2f4a", - "control-id": "cis_rhel10_5-3.3.2.1", + "uuid": "68bd50e2-60f0-4a66-bcbc-94884c2585d8", + "control-id": "cis_rhel10_6-2.2.1.1", "description": "REPLACE_ME", "props": [ { @@ -7320,47 +7395,39 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_difok" + "value": "package_systemd-journal-remote_installed" } ] }, { - "uuid": "bcb0543a-b880-4a17-b644-0b898c7eef85", - "control-id": "cis_rhel10_5-3.3.2.2", + "uuid": "a7c7aed8-56f7-49fa-93b6-d422b6fc7139", + "control-id": "cis_rhel10_6-2.2.1.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_minlen" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "7f067bf4-a362-4ce5-8c8c-5557c5020b0c", - "control-id": "cis_rhel10_5-3.3.2.3", - "description": "This requirement is expected to be manual. However, in previous versions of the policy\nit was already automated the configuration of \"minclass\" option. This posture was kept for\nRHEL 9 in this new version. Rules related to other options are informed in related_rules.\nIn short, minclass=4 alone can achieve the same result achieved by the combination of the\nother 4 options mentioned in the policy.", + "uuid": "bc13b61d-259a-4cd9-a055-a018a14602fc", + "control-id": "cis_rhel10_6-2.2.1.3", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_minclass" + "value": "alternative", + "remarks": "New templated rule is necessary." } ] }, { - "uuid": "126191ce-a94d-4595-9a51-ae21eda75003", - "control-id": "cis_rhel10_5-3.3.2.4", + "uuid": "4a07de36-5c2e-4868-87ae-36c469e8c3db", + "control-id": "cis_rhel10_6-2.2.1.4", "description": "REPLACE_ME", "props": [ { @@ -7371,138 +7438,113 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_maxrepeat" + "value": "socket_systemd-journal-remote_disabled" } ] }, { - "uuid": "615eb4bb-da59-49d7-b73e-52293f44268e", - "control-id": "cis_rhel10_5-3.3.2.5", + "uuid": "75659d86-b61c-422c-9f8b-f25196a0ab0e", + "control-id": "cis_rhel10_6-2.3.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "planned", - "remarks": "A new templated rule and variable are necessary for the maxsequence option." + "value": "implemented" } ] }, { - "uuid": "24b699cb-e467-45f8-8650-53749a7990f7", - "control-id": "cis_rhel10_5-3.3.2.6", + "uuid": "8d093057-e0a7-4217-9398-e94ce3a5bf3e", + "control-id": "cis_rhel10_6-2.3.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_dictcheck" } ] }, { - "uuid": "813d6bf3-eedb-4072-8951-ee066a43d62c", - "control-id": "cis_rhel10_5-3.3.2.7", + "uuid": "f8d40f05-e801-46c2-889c-69d489878579", + "control-id": "cis_rhel10_6-2.3.3", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_enforce_root" } ] }, { - "uuid": "632e1108-c7b1-49f1-9b62-4eae158f80f1", - "control-id": "cis_rhel10_5-3.3.3.1", - "description": "Although mentioned in the section 5.3.3.3, there is no explicit requirement to configure\nretry option of pam_pwhistory. If come in the future, the rule accounts_password_pam_retry\ncan be used.", + "uuid": "351c498e-f960-4e31-8241-4c4763e214b5", + "control-id": "cis_rhel10_6-2.3.4", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_pwhistory_remember_password_auth" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_pwhistory_remember_system_auth" } ] }, { - "uuid": "d51a8ce4-43b1-4859-bdbc-173287c21c9b", - "control-id": "cis_rhel10_5-3.3.3.2", + "uuid": "de12444c-be6c-41cd-8f71-933ad522e008", + "control-id": "cis_rhel10_6-2.3.5", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "planned", - "remarks": "A new rule needs to be created to check and remediate the enforce_for_root option in\n/etc/security/pwhistory.conf. accounts_password_pam_enforce_root can be used as reference." + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "a6307421-e537-47b9-a5ea-adbdde321f1b", - "control-id": "cis_rhel10_5-3.3.3.3", - "description": "In RHEL 9 pam_pwhistory is enabled via authselect feature, as required in 5.3.2.4. The\nfeature automatically set \"use_authok\" option. In any case, we don't have a rule to check\nthis option specifically.", + "uuid": "827f562d-11af-4749-a99b-a6bd9b73b13d", + "control-id": "cis_rhel10_6-2.3.6", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "0fb42209-3c24-4d63-8877-119722381b23", - "control-id": "cis_rhel10_5-3.3.4.1", - "description": "The rule more specifically used in this requirement also satify the requirement 5.3.2.5.", + "uuid": "24213ecc-9855-4124-b33e-aa382b8b9e54", + "control-id": "cis_rhel10_6-2.3.7", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_empty_passwords" } ] }, { - "uuid": "8d8c651c-d966-4ca1-9a8a-f81e2ccf9b98", - "control-id": "cis_rhel10_5-3.3.4.2", + "uuid": "aa7c8d1d-cb3c-42dc-ad77-7f78ac36f2ec", + "control-id": "cis_rhel10_6-2.3.8", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "alternative", - "remarks": "Usage of pam_unix.so module together with \"remember\" option is deprecated and is not\nrecommened by this policy. Instead, it should be used remember option of pam_pwhistory\nmodule, as required in 5.3.3.3.1. See here for more details about pam_unix.so:\nhttps://bugzilla.redhat.com/show_bug.cgi?id=1778929\nA new rule needs to be created to remove the remember option from pam_unix module." + "remarks": "REPLACE_ME" } ] }, { - "uuid": "1f4891b9-7d8b-4264-a509-062a5148b2e4", - "control-id": "cis_rhel10_5-3.3.4.3", - "description": "Changes in logindefs mentioned in this requirement are more specifically covered by 5.4.1.4", + "uuid": "3fbe8d0a-f3fe-423c-b12b-42edec2fcded", + "control-id": "cis_rhel10_6-2.4.1", + "description": "It is not harmful to run these rules even if rsyslog is not installed or active.", "props": [ { "name": "implementation-status", @@ -7512,30 +7554,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_systemauth" + "value": "rsyslog_files_groupownership" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_passwordauth" - } - ] - }, - { - "uuid": "c47790b7-6e49-4cb3-b5a2-ead3aafb8af1", - "control-id": "cis_rhel10_5-3.3.4.4", - "description": "In RHEL 9 pam_unix is enabled by default in all authselect profiles already with the\nuse_authtok option set. In any case, we don't have a rule to check this option specifically,\nlike in 5.3.3.3.3.", - "props": [ + "value": "rsyslog_files_ownership" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "rsyslog_files_permissions" } ] }, { - "uuid": "2a13d0a6-8c8b-4253-b303-d33e86bde42e", - "control-id": "cis_rhel10_5-4.1.1", + "uuid": "f449cd5c-1662-47b7-a466-09c69bfc8fc1", + "control-id": "cis_rhel10_7-1.1", "description": "REPLACE_ME", "props": [ { @@ -7546,18 +7581,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_maximum_age_login_defs" + "value": "file_groupowner_etc_passwd" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_set_max_life_existing" + "value": "file_owner_etc_passwd" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_etc_passwd" } ] }, { - "uuid": "0a418366-3be6-4bfe-9ca3-387a0b8c3162", - "control-id": "cis_rhel10_5-4.1.3", + "uuid": "9cffbf4f-fc88-4f74-9332-dc766e811a96", + "control-id": "cis_rhel10_7-1.2", "description": "REPLACE_ME", "props": [ { @@ -7568,40 +7608,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_warn_age_login_defs" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_set_warn_age_existing" - } - ] - }, - { - "uuid": "d3cb251c-4397-42e1-a2c8-d0f6530b2da4", - "control-id": "cis_rhel10_5-4.1.4", - "description": "There's a \"new\" set of options in /etc/login.defs file to define the number of iterations\nperformed during the hashing process.", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "file_groupowner_backup_etc_passwd" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_libuserconf" + "value": "file_owner_backup_etc_passwd" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_logindefs" + "value": "file_permissions_backup_etc_passwd" } ] }, { - "uuid": "6d2348bf-767c-44f1-be14-c7d4b258cd99", - "control-id": "cis_rhel10_5-4.1.5", + "uuid": "7d067497-637a-441b-b603-3ac61aff9c61", + "control-id": "cis_rhel10_7-1.3", "description": "REPLACE_ME", "props": [ { @@ -7612,35 +7635,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_disable_post_pw_expiration" + "value": "file_groupowner_etc_group" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_set_post_pw_existing" - } - ] - }, - { - "uuid": "7931d538-c621-4dcb-b24a-0ec9e770f618", - "control-id": "cis_rhel10_5-4.1.6", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "file_owner_etc_group" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_last_change_is_in_past" + "value": "file_permissions_etc_group" } ] }, { - "uuid": "4cc339d9-95e6-44a8-84eb-0485780402c6", - "control-id": "cis_rhel10_5-4.2.1", + "uuid": "d39609b2-fd5c-4adc-b2f4-721132bd5bf0", + "control-id": "cis_rhel10_7-1.4", "description": "REPLACE_ME", "props": [ { @@ -7651,60 +7662,50 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_no_uid_except_zero" - } - ] - }, - { - "uuid": "d75accee-a632-434c-8444-652bfbcf65a0", - "control-id": "cis_rhel10_5-4.2.2", - "description": "The rule confirms the primary group for root, but doesn't check if any other user are also\nusing GID 0. New rule is necessary.\nThere is assessment but no automated remediation for this rule and this sounds reasonable.", - "props": [ + "value": "file_groupowner_backup_etc_group" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "file_owner_backup_etc_group" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_root_gid_zero" + "value": "file_permissions_backup_etc_group" } ] }, { - "uuid": "80ef7af6-747c-4be3-9704-ce94c9eb26b9", - "control-id": "cis_rhel10_5-4.2.3", + "uuid": "3ea32403-7ec3-42f9-9efc-03c867577ebb", + "control-id": "cis_rhel10_7-1.5", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "New rule is necessary." - } - ] - }, - { - "uuid": "16b52013-9ef8-4bfe-8327-682b18d16827", - "control-id": "cis_rhel10_5-4.2.4", - "description": "REPLACE_ME", - "props": [ + "value": "implemented" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "file_owner_etc_shadow" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_root_password_configured" + "value": "file_groupowner_etc_shadow" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_etc_shadow" } ] }, { - "uuid": "7d5b63ef-0bdb-46f5-9ec5-bdafb38b3d98", - "control-id": "cis_rhel10_5-4.2.5", + "uuid": "ff311fae-31aa-4827-a1f8-3909f5d3120d", + "control-id": "cis_rhel10_7-1.6", "description": "REPLACE_ME", "props": [ { @@ -7715,31 +7716,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_root_path_dirs_no_write" + "value": "file_groupowner_backup_etc_shadow" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "root_path_no_dot" - } - ] - }, - { - "uuid": "a285deda-31b1-486b-9076-588fe273675a", - "control-id": "cis_rhel10_5-4.2.6", - "description": "REPLACE_ME", - "props": [ + "value": "file_owner_backup_etc_shadow" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "There is no rule to ensure umask in /root/.bash_profile and /root/.bashrc. A new rule have\nto be created. It can be based on accounts_umask_interactive_users." + "value": "file_permissions_backup_etc_shadow" } ] }, { - "uuid": "36ef5a7b-64a8-4651-babf-a88ac90fccd7", - "control-id": "cis_rhel10_5-4.2.7", + "uuid": "93d6cc01-be06-4d51-b74b-0584a0ad2966", + "control-id": "cis_rhel10_7-1.7", "description": "REPLACE_ME", "props": [ { @@ -7750,48 +7743,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_password_auth_for_systemaccounts" + "value": "file_groupowner_etc_gshadow" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_shelllogin_for_systemaccounts" - } - ] - }, - { - "uuid": "b633f357-d236-495e-81b0-480a99ca96e0", - "control-id": "cis_rhel10_5-4.2.8", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "New rule is necessary." - } - ] - }, - { - "uuid": "81a321bd-86f6-4bdb-8a76-aa87dbbbd3fb", - "control-id": "cis_rhel10_5-4.3.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "file_owner_etc_gshadow" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_tmout" + "value": "file_permissions_etc_gshadow" } ] }, { - "uuid": "346ec153-1cc8-40dc-b48e-5e3f545d55a6", - "control-id": "cis_rhel10_5-4.3.3", + "uuid": "890d32a8-b36d-4ecc-949a-b6f38173c654", + "control-id": "cis_rhel10_7-1.8", "description": "REPLACE_ME", "props": [ { @@ -7802,23 +7770,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_umask_etc_bashrc" + "value": "file_groupowner_backup_etc_gshadow" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_umask_etc_login_defs" + "value": "file_owner_backup_etc_gshadow" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_umask_etc_profile" + "value": "file_permissions_backup_etc_gshadow" } ] }, { - "uuid": "182d9dbb-577c-41f0-88b0-0fb57466afd0", - "control-id": "cis_rhel10_6-1.1", + "uuid": "394e44e2-5614-4470-8c57-34614bec4c28", + "control-id": "cis_rhel10_7-1.9", "description": "REPLACE_ME", "props": [ { @@ -7829,18 +7797,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_aide_installed" + "value": "file_groupowner_etc_shells" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "aide_build_database" + "value": "file_owner_etc_shells" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_etc_shells" } ] }, { - "uuid": "af628974-132f-4933-a62b-34e63f5e9c26", - "control-id": "cis_rhel10_6-1.2", + "uuid": "9f71da5c-2fcd-4548-8dfa-eea5ef87124a", + "control-id": "cis_rhel10_7-1.10", "description": "REPLACE_ME", "props": [ { @@ -7851,13 +7824,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "aide_periodic_cron_checking" + "value": "file_etc_security_opasswd" } ] }, { - "uuid": "cb1bf387-81ca-419c-8cfe-938fa21593c7", - "control-id": "cis_rhel10_6-1.3", + "uuid": "e2d4febd-7790-4e17-9878-cdc5ebd0f917", + "control-id": "cis_rhel10_7-1.11", "description": "REPLACE_ME", "props": [ { @@ -7868,43 +7841,40 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "aide_check_audit_tools" + "value": "file_permissions_unauthorized_world_writable" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "dir_perms_world_writable_sticky_bits" } ] }, { - "uuid": "83bfdbca-3333-426d-a6b2-7c47ac8ba294", - "control-id": "cis_rhel10_6-2.1.1", + "uuid": "3cf11705-3ee2-431b-a4d6-dbfbbfd3a7bd", + "control-id": "cis_rhel10_7-1.12", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "partial" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_systemd-journald_enabled" - } - ] - }, - { - "uuid": "0e79916d-3692-4e77-b55d-9a9e8baf10f4", - "control-id": "cis_rhel10_6-2.1.2", - "description": "REPLACE_ME", - "props": [ + "value": "no_files_unowned_by_user" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "file_permissions_ungroupowned" } ] }, { - "uuid": "805e15db-1c67-4bc3-a8fc-ab3ca8d836a8", - "control-id": "cis_rhel10_6-2.1.3", + "uuid": "33c25f47-4399-4c7c-b840-3430b4e9d69e", + "control-id": "cis_rhel10_7-1.13", "description": "REPLACE_ME", "props": [ { @@ -7916,21 +7886,25 @@ ] }, { - "uuid": "25906df7-e67b-4e7e-a39b-b3a0f2fe9216", - "control-id": "cis_rhel10_6-2.1.4", + "uuid": "1fb17453-8d09-4585-ad10-faa552929aa1", + "control-id": "cis_rhel10_7-2.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary to create a new rule to check the status of journald and rsyslog.\nIt would also be necessary a new rule to disable or remove rsyslog." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_password_all_shadowed" } ] }, { - "uuid": "404522c0-a590-4a31-bd5c-e06463e0161c", - "control-id": "cis_rhel10_6-2.2.1.1", + "uuid": "ae051cc3-7e93-4a0e-a691-ca91a4129ffc", + "control-id": "cis_rhel10_7-2.2", "description": "REPLACE_ME", "props": [ { @@ -7941,39 +7915,47 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_systemd-journal-remote_installed" + "value": "no_empty_passwords_etc_shadow" } ] }, { - "uuid": "eebbb4df-aab1-4452-b7de-3eb21eebd67f", - "control-id": "cis_rhel10_6-2.2.1.2", + "uuid": "f92b40f6-5d32-46ad-aadb-b25e7da87e8d", + "control-id": "cis_rhel10_7-2.3", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "gid_passwd_group_same" } ] }, { - "uuid": "2b7931bd-c508-42ef-84b1-a64e2b1b4658", - "control-id": "cis_rhel10_6-2.2.1.3", + "uuid": "21001b39-ed08-4d8a-be23-26c079122909", + "control-id": "cis_rhel10_7-2.4", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "New templated rule is necessary." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "account_unique_id" } ] }, { - "uuid": "125fbdbf-01b6-4e15-907d-4bcac21e9101", - "control-id": "cis_rhel10_6-2.2.1.4", + "uuid": "3bd524ab-86fa-461a-b9b0-17d71424f3b1", + "control-id": "cis_rhel10_7-2.5", "description": "REPLACE_ME", "props": [ { @@ -7984,26 +7966,30 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "socket_systemd-journal-remote_disabled" + "value": "group_unique_id" } ] }, { - "uuid": "e6d5aff6-5be6-426d-8bf6-d5787e10a123", - "control-id": "cis_rhel10_6-2.2.2", + "uuid": "fefa5a25-8a62-4861-a78e-d61e9ee3b9a2", + "control-id": "cis_rhel10_7-2.6", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "This rule conflicts with 6.2.3.3. More investigation is needed to properly solve this." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "account_unique_name" } ] }, { - "uuid": "e5069993-5f54-41a6-8bcd-dfb2891f4426", - "control-id": "cis_rhel10_6-2.2.3", + "uuid": "98e494b2-7c81-4819-911f-45290c040875", + "control-id": "cis_rhel10_7-2.7", "description": "REPLACE_ME", "props": [ { @@ -8014,13 +8000,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_compress" + "value": "group_unique_name" } ] }, { - "uuid": "5d8be20e-80bc-455f-b72d-05078593e928", - "control-id": "cis_rhel10_6-2.2.4", + "uuid": "6315160e-0921-4dab-a886-7c158780c599", + "control-id": "cis_rhel10_7-2.8", "description": "REPLACE_ME", "props": [ { @@ -8031,603 +8017,24 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_storage" + "value": "accounts_user_interactive_home_directory_exists" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_ownership_home_directories" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_home_directories" } ] }, { - "uuid": "45ed6a0f-baae-4a38-9d70-2834318d0dce", - "control-id": "cis_rhel10_6-2.3.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - } - ] - }, - { - "uuid": "631e416b-66b5-4a02-be0b-2140bebeeb14", - "control-id": "cis_rhel10_6-2.3.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - } - ] - }, - { - "uuid": "6676e490-7e94-42a3-bbd9-79ce5432bf8b", - "control-id": "cis_rhel10_6-2.3.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - } - ] - }, - { - "uuid": "d1f024a3-1002-4630-8d44-1c7bdf72f005", - "control-id": "cis_rhel10_6-2.3.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - } - ] - }, - { - "uuid": "0d5b25ec-6678-4eb5-8ca5-def464f22cd2", - "control-id": "cis_rhel10_6-2.3.5", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } - ] - }, - { - "uuid": "1ead852e-d239-43b3-9f31-0c494d1df81b", - "control-id": "cis_rhel10_6-2.3.6", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } - ] - }, - { - "uuid": "c58954f4-de00-4c28-954b-66c98a56c970", - "control-id": "cis_rhel10_6-2.3.7", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - } - ] - }, - { - "uuid": "a1a49605-ffcd-42ed-92cc-7ec5932662ca", - "control-id": "cis_rhel10_6-2.3.8", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } - ] - }, - { - "uuid": "a57482ba-a2a0-45fc-9e5c-ab935d533b10", - "control-id": "cis_rhel10_6-2.4.1", - "description": "It is not harmful to run these rules even if rsyslog is not installed or active.", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "rsyslog_files_groupownership" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "rsyslog_files_ownership" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "rsyslog_files_permissions" - } - ] - }, - { - "uuid": "2f38690e-2bef-4933-8c98-ecbd60506bab", - "control-id": "cis_rhel10_7-1.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_passwd" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_passwd" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_passwd" - } - ] - }, - { - "uuid": "f164a4ed-3faf-4e45-b0b6-521c1c116cc9", - "control-id": "cis_rhel10_7-1.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_passwd" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_passwd" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_passwd" - } - ] - }, - { - "uuid": "87504ea1-df3a-4f5f-99e3-ccb199ca0fc0", - "control-id": "cis_rhel10_7-1.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_group" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_group" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_group" - } - ] - }, - { - "uuid": "917bbf1d-3bb9-41dc-83a1-6502364cbaba", - "control-id": "cis_rhel10_7-1.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_group" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_group" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_group" - } - ] - }, - { - "uuid": "c450d231-5923-4fe9-ad50-d06785e0d325", - "control-id": "cis_rhel10_7-1.5", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_shadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_shadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_shadow" - } - ] - }, - { - "uuid": "584c7fd7-9ce7-4899-86bf-5777b7b00734", - "control-id": "cis_rhel10_7-1.6", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_shadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_shadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_shadow" - } - ] - }, - { - "uuid": "5f05f552-b444-4461-b627-e4b9d3d651f0", - "control-id": "cis_rhel10_7-1.7", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_gshadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_gshadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_gshadow" - } - ] - }, - { - "uuid": "3638f087-f5a4-49fc-bbb8-ce93ff37cf4a", - "control-id": "cis_rhel10_7-1.8", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_gshadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_gshadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_gshadow" - } - ] - }, - { - "uuid": "1af66949-5986-4f0f-a61a-3bf213b25502", - "control-id": "cis_rhel10_7-1.9", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_shells" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_shells" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_shells" - } - ] - }, - { - "uuid": "460640a9-8f9d-4afd-8b72-3f11ac2e6cf5", - "control-id": "cis_rhel10_7-1.10", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_etc_security_opasswd" - } - ] - }, - { - "uuid": "9ab35556-9a88-41db-84ae-24b66b70835d", - "control-id": "cis_rhel10_7-1.11", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_unauthorized_world_writable" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dir_perms_world_writable_sticky_bits" - } - ] - }, - { - "uuid": "d7531eb1-1288-41bb-8382-4ab4e04f62e3", - "control-id": "cis_rhel10_7-1.12", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_files_unowned_by_user" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_ungroupowned" - } - ] - }, - { - "uuid": "4ee26a73-c3dd-4060-8ef1-a4576d63b4f3", - "control-id": "cis_rhel10_7-1.13", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } - ] - }, - { - "uuid": "c03406ee-fef7-4219-b9fa-42676e3bfe96", - "control-id": "cis_rhel10_7-2.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_all_shadowed" - } - ] - }, - { - "uuid": "237092f3-0afa-48d3-aa0d-901a7e5fe457", - "control-id": "cis_rhel10_7-2.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_empty_passwords_etc_shadow" - } - ] - }, - { - "uuid": "e262eb4f-4170-4a5d-ab10-4d83d56dd2c0", - "control-id": "cis_rhel10_7-2.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "gid_passwd_group_same" - } - ] - }, - { - "uuid": "09b9b16d-46da-424a-bc6c-0ade206f6e37", - "control-id": "cis_rhel10_7-2.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_unique_id" - } - ] - }, - { - "uuid": "ee1bbdbc-3b33-4f8c-9d75-df9b133d01ac", - "control-id": "cis_rhel10_7-2.5", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "group_unique_id" - } - ] - }, - { - "uuid": "d5c55f54-658c-44cc-bc86-05f3aa53dafc", - "control-id": "cis_rhel10_7-2.6", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_unique_name" - } - ] - }, - { - "uuid": "898bac17-c5c2-4f04-9836-cc80433194e0", - "control-id": "cis_rhel10_7-2.7", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "group_unique_name" - } - ] - }, - { - "uuid": "71089be6-5331-4c3c-b091-642690b4bde7", - "control-id": "cis_rhel10_7-2.8", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_user_interactive_home_directory_exists" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_home_directories" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_home_directories" - } - ] - }, - { - "uuid": "f2a58abd-340a-43df-9a78-0c8ff5580423", - "control-id": "cis_rhel10_7-2.9", - "description": "Missing a rule to check that .bash_history is mode 0600 or more restrictive.", + "uuid": "15593a15-94be-4477-97d8-38bce5c57a7d", + "control-id": "cis_rhel10_7-2.9", + "description": "Missing a rule to check that .bash_history is mode 0600 or more restrictive.", "props": [ { "name": "implementation-status", @@ -8805,7 +8212,7 @@ { "name": "Parameter_Value_Alternatives_5", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", + "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel10': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", "remarks": "rule_set_000" }, { @@ -8823,7 +8230,7 @@ { "name": "Parameter_Value_Alternatives_6", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", + "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel10': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", "remarks": "rule_set_000" }, { @@ -9189,503 +8596,521 @@ { "name": "Parameter_Id_27", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_account_disable_post_pw_expiration", + "value": "sysctl_net_ipv6_conf_default_forwarding_value", "remarks": "rule_set_000" }, { "name": "Parameter_Description_27", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The number of days to wait after a password expires, until the account will be permanently disabled.", + "value": "Toggle IPv6 default Forwarding", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_27", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'0': '0', 180: 180, 30: 30, 35: 35, 40: 40, 45: 45, 60: 60, 90: 90, 'default': 35}", + "value": "{'default': '0', 'disabled': '0', 'enabled': 1}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_28", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_maximum_age_login_defs", + "value": "var_account_disable_post_pw_expiration", "remarks": "rule_set_000" }, { "name": "Parameter_Description_28", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Maximum age of password in days", + "value": "The number of days to wait after a password expires, until the account will be permanently disabled.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_28", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{365: 365, 120: 120, 180: 180, 90: 90, 60: 60, 45: 45, 'default': 60}", + "value": "{'0': '0', 180: 180, 30: 30, 35: 35, 40: 40, 45: 45, 60: 60, 90: 90, 'default': 35}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_29", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_password_warn_age_login_defs", + "value": "var_accounts_maximum_age_login_defs", "remarks": "rule_set_000" }, { "name": "Parameter_Description_29", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The number of days' warning given before a password expires.", + "value": "Maximum age of password in days", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_29", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'0': '0', 14: 14, 10: 10, 7: 7, 'default': 7}", + "value": "{365: 365, 120: 120, 180: 180, 90: 90, 60: 60, 45: 45, 'default': 60}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_30", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_passwords_pam_faillock_deny", + "value": "var_accounts_password_warn_age_login_defs", "remarks": "rule_set_000" }, { "name": "Parameter_Description_30", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Number of failed login attempts before account lockout", + "value": "The number of days' warning given before a password expires.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_30", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{10: 10, 3: 3, 4: 4, 5: 5, 6: 6, 8: 8, 'default': 3}", + "value": "{'0': '0', 14: 14, 10: 10, 7: 7, 'default': 7}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_31", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_passwords_pam_faillock_unlock_time", + "value": "var_accounts_passwords_pam_faillock_deny", "remarks": "rule_set_000" }, { "name": "Parameter_Description_31", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Seconds before automatic unlocking or permanently locking after excessive failed logins", + "value": "Number of failed login attempts before account lockout", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_31", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{1800: 1800, 3600: 3600, 600: 600, 604800: 604800, 86400: 86400, 900: 900, 300: 300, 'default': 0, 'never': 0}", + "value": "{10: 10, 3: 3, 4: 4, 5: 5, 6: 6, 8: 8, 'default': 3}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_32", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_tmout", + "value": "var_accounts_passwords_pam_faillock_unlock_time", "remarks": "rule_set_000" }, { "name": "Parameter_Description_32", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "In an interactive shell, the value is interpreted as the number of seconds to wait for input after issuing the primary prompt. Bash terminates after waiting for that number of seconds if input does not arrive.", + "value": "Seconds before automatic unlocking or permanently locking after excessive failed logins", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_32", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'30_min': 1800, '10_min': 600, '15_min': 900, '5_min': 300, 'default': 600}", + "value": "{1800: 1800, 3600: 3600, 600: 600, 604800: 604800, 86400: 86400, 900: 900, 300: 300, 'default': 0, 'never': 0}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_33", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_user_umask", + "value": "var_accounts_tmout", "remarks": "rule_set_000" }, { "name": "Parameter_Description_33", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enter default user umask", + "value": "In an interactive shell, the value is interpreted as the number of seconds to wait for input after issuing the primary prompt. Bash terminates after waiting for that number of seconds if input does not arrive.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_33", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'007': '007', '022': '022', '027': '027', '077': '077', 'default': '027'}", + "value": "{'30_min': 1800, '10_min': 600, '15_min': 900, '5_min': 300, 'default': 600}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_34", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_authselect_profile", + "value": "var_accounts_user_umask", "remarks": "rule_set_000" }, { "name": "Parameter_Description_34", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the authselect profile to select", + "value": "Enter default user umask", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_34", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'local': 'local', 'default': 'minimal', 'minimal': 'minimal', 'sssd': 'sssd'}", + "value": "{'007': '007', '022': '022', '027': '027', '077': '077', 'default': '027'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_35", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_multiple_time_servers", + "value": "var_authselect_profile", "remarks": "rule_set_000" }, { "name": "Parameter_Description_35", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The list of vendor-approved time servers", + "value": "Specify the authselect profile to select", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_35", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'generic': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'stig': '0.us.pool.ntp.mil', 'fedora': '0.fedora.pool.ntp.org,1.fedora.pool.ntp.org,2.fedora.pool.ntp.org,3.fedora.pool.ntp.org', 'rhel': '0.rhel.pool.ntp.org,1.rhel.pool.ntp.org,2.rhel.pool.ntp.org,3.rhel.pool.ntp.org', 'ol': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'suse': '0.suse.pool.ntp.org,1.suse.pool.ntp.org,2.suse.pool.ntp.org,3.suse.pool.ntp.org', 'alinux': '0.ntp.cloud.aliyuncs.com,1.ntp.aliyun.com,2.ntp1.aliyun.com,3.ntp1.cloud.aliyuncs.com', 'amazon': '0.rhel.pool.ntp.org,1.rhel.pool.ntp.org,2.rhel.pool.ntp.org,3.rhel.pool.ntp.org', 'ubuntu': '0.ubuntu.pool.ntp.org,1.ubuntu.pool.ntp.org,2.ubuntu.pool.ntp.org,3.ubuntu.pool.ntp.org', 'almalinux': '0.almalinux.pool.ntp.org,1.almalinux.pool.ntp.org,2.almalinux.pool.ntp.org,3.almalinux.pool.ntp.org', 'debian': '0.debian.pool.ntp.org,1.debian.pool.ntp.org,2.debian.pool.ntp.org,3.debian.pool.ntp.org', 'nist': 'time.nist.gov,time-a-g.nist.gov,time-b-g.nist.gov,time-c-g.nist.gov'}", + "value": "{'local': 'local', 'default': 'minimal', 'minimal': 'minimal', 'sssd': 'sssd'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_36", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_pam_wheel_group_for_su", + "value": "var_multiple_time_servers", "remarks": "rule_set_000" }, { "name": "Parameter_Description_36", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "pam_wheel module has a parameter called group, which controls which groups can access the su command. This variable holds the valid value for the parameter.", + "value": "The list of vendor-approved time servers", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_36", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'sugroup', 'cis': 'sugroup'}", + "value": "{'default': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'generic': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'stig': '0.us.pool.ntp.mil', 'fedora': '0.fedora.pool.ntp.org,1.fedora.pool.ntp.org,2.fedora.pool.ntp.org,3.fedora.pool.ntp.org', 'rhel': '0.rhel.pool.ntp.org,1.rhel.pool.ntp.org,2.rhel.pool.ntp.org,3.rhel.pool.ntp.org', 'ol': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'suse': '0.suse.pool.ntp.org,1.suse.pool.ntp.org,2.suse.pool.ntp.org,3.suse.pool.ntp.org', 'alinux': '0.ntp.cloud.aliyuncs.com,1.ntp.aliyun.com,2.ntp1.aliyun.com,3.ntp1.cloud.aliyuncs.com', 'amazon': '0.rhel.pool.ntp.org,1.rhel.pool.ntp.org,2.rhel.pool.ntp.org,3.rhel.pool.ntp.org', 'ubuntu': '0.ubuntu.pool.ntp.org,1.ubuntu.pool.ntp.org,2.ubuntu.pool.ntp.org,3.ubuntu.pool.ntp.org', 'almalinux': '0.almalinux.pool.ntp.org,1.almalinux.pool.ntp.org,2.almalinux.pool.ntp.org,3.almalinux.pool.ntp.org', 'debian': '0.debian.pool.ntp.org,1.debian.pool.ntp.org,2.debian.pool.ntp.org,3.debian.pool.ntp.org', 'nist': 'time.nist.gov,time-a-g.nist.gov,time-b-g.nist.gov,time-c-g.nist.gov'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_hashing_algorithm", + "value": "var_pam_wheel_group_for_su", "remarks": "rule_set_000" }, { "name": "Parameter_Description_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the system default encryption algorithm for encrypting passwords. Defines the value set as ENCRYPT_METHOD in /etc/login.defs.", + "value": "pam_wheel module has a parameter called group, which controls which groups can access the su command. This variable holds the valid value for the parameter.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'SHA512', 'SHA512': 'SHA512', 'SHA256': 'SHA256', 'yescrypt': 'YESCRYPT', 'cis_ubuntu2404': 'SHA512|YESCRYPT'}", + "value": "{'default': 'sugroup', 'cis': 'sugroup'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_hashing_algorithm_pam", + "value": "var_password_hashing_algorithm", "remarks": "rule_set_000" }, { "name": "Parameter_Description_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the system default encryption algorithm for encrypting passwords. Defines the hashing algorithm to be used in pam_unix.so.", + "value": "Specify the system default encryption algorithm for encrypting passwords. Defines the value set as ENCRYPT_METHOD in /etc/login.defs.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'sha512', 'sha512': 'sha512', 'yescrypt': 'yescrypt'}", + "value": "{'default': 'SHA512', 'SHA512': 'SHA512', 'SHA256': 'SHA256', 'yescrypt': 'YESCRYPT', 'cis_ubuntu2404': 'SHA512|YESCRYPT'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_dictcheck", + "value": "var_password_hashing_algorithm_pam", "remarks": "rule_set_000" }, { "name": "Parameter_Description_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Prevent the use of dictionary words for passwords.", + "value": "Specify the system default encryption algorithm for encrypting passwords. Defines the hashing algorithm to be used in pam_unix.so.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{1: 1, 'default': 1}", + "value": "{'default': 'sha512', 'sha512': 'sha512', 'yescrypt': 'yescrypt'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_40", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_difok", + "value": "var_password_pam_dictcheck", "remarks": "rule_set_000" }, { "name": "Parameter_Description_40", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Minimum number of characters not present in old password", + "value": "Prevent the use of dictionary words for passwords.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_40", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{15: 15, 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 8: 8, 'default': 8}", + "value": "{1: 1, 'default': 1}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_41", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_maxrepeat", + "value": "var_password_pam_difok", "remarks": "rule_set_000" }, { "name": "Parameter_Description_41", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Maximum Number of Consecutive Repeating Characters in a Password", + "value": "Minimum number of characters not present in old password", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_41", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "{15: 15, 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 8: 8, 'default': 8}", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Id_42", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "var_password_pam_maxrepeat", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Description_42", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Maximum Number of Consecutive Repeating Characters in a Password", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Value_Alternatives_42", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{1: 1, 2: 2, 3: 3, 'default': 3}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_42", + "name": "Parameter_Id_43", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_password_pam_minclass", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_42", + "name": "Parameter_Description_43", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Minimum number of categories of characters that must exist in a password", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_42", + "name": "Parameter_Value_Alternatives_43", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{1: 1, 2: 2, 3: 3, 4: 4, 'default': 3}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_43", + "name": "Parameter_Id_44", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_password_pam_minlen", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_43", + "name": "Parameter_Description_44", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Minimum number of characters in password", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_43", + "name": "Parameter_Value_Alternatives_44", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{10: 10, 12: 12, 14: 14, 15: 15, 17: 17, 18: 18, 20: 20, 6: 6, 7: 7, 8: 8, 'default': 15}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_44", + "name": "Parameter_Id_45", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_password_pam_remember", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_44", + "name": "Parameter_Description_45", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Prevent password re-use using password history lookup", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_44", + "name": "Parameter_Value_Alternatives_45", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'0': '0', 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 8: 8, 9: 9, 24: 24, 'default': 5}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_45", + "name": "Parameter_Id_46", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_password_pam_remember_control_flag", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_45", + "name": "Parameter_Description_46", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "'Specify the control flag required for password remember requirement. If multiple values are allowed write them separated by commas as in \"required,requisite\", for remediations the first value will be taken'", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_45", + "name": "Parameter_Value_Alternatives_46", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'required': 'required', 'optional': 'optional', 'requisite': 'requisite', 'sufficient': 'sufficient', 'binding': 'binding', 'ol8': 'required,requisite', 'requisite_or_required': 'requisite,required', 'default': 'requisite'}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_46", + "name": "Parameter_Id_47", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_postfix_inet_interfaces", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_46", + "name": "Parameter_Description_47", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "The setting for inet_interfaces in /etc/postfix/main.cf", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_46", + "name": "Parameter_Value_Alternatives_47", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'loopback-only': 'loopback-only', 'default': 'loopback-only', 'localhost': 'localhost'}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_47", + "name": "Parameter_Id_48", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_screensaver_lock_delay", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_47", + "name": "Parameter_Description_48", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Choose allowed duration (in seconds) after a screensaver becomes active before displaying an authentication prompt", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_47", + "name": "Parameter_Value_Alternatives_48", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'10_seconds': 10, '5_seconds': 5, 'default': '0', 'immediate': '0'}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_48", + "name": "Parameter_Id_49", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_selinux_policy_name", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_48", + "name": "Parameter_Description_49", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Type of policy in use. Possible values are:
targeted - Only targeted network daemons are protected.
strict - Full SELinux protection.
mls - Multiple levels of security", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_48", + "name": "Parameter_Value_Alternatives_49", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'default': 'targeted', 'mls': 'mls', 'targeted': 'targeted'}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_49", + "name": "Parameter_Id_50", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_sshd_max_sessions", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_49", + "name": "Parameter_Description_50", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Specify the maximum number of open sessions permitted.", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_49", + "name": "Parameter_Value_Alternatives_50", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{10: 10, 4: 4, 3: 3, 2: 2, 1: 1, 0: 0, 'default': 10}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_50", + "name": "Parameter_Id_51", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_sshd_set_keepalive", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_50", + "name": "Parameter_Description_51", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Specify the maximum number of idle message counts before session is terminated.", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_50", + "name": "Parameter_Value_Alternatives_51", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{10: 10, 3: 3, 5: 5, 0: 0, 1: 1, 'default': 0}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_51", + "name": "Parameter_Id_52", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_sshd_set_login_grace_time", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_51", + "name": "Parameter_Description_52", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure parameters for how long the servers stays connected before the user has successfully logged in", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_51", + "name": "Parameter_Value_Alternatives_52", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'default': 60, 60: 60}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_52", + "name": "Parameter_Id_53", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_sshd_set_maxstartups", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_52", + "name": "Parameter_Description_53", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure parameters for maximum concurrent unauthenticated connections to the SSH daemon.", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_52", + "name": "Parameter_Value_Alternatives_53", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'default': '10:30:100', '10:30:60': '10:30:60'}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_53", + "name": "Parameter_Id_54", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_system_crypto_policy", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_53", + "name": "Parameter_Description_54", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Specify the crypto policy for the system.", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_53", + "name": "Parameter_Value_Alternatives_54", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_54", + "name": "Parameter_Id_55", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_user_initialization_files_regex", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_54", + "name": "Parameter_Description_55", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "'A regular expression describing a list of file names for files that are sourced at login time for interactive users'", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_54", + "name": "Parameter_Value_Alternatives_55", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'default': '^(\\\\.bashrc|\\\\.zshrc|\\\\.cshrc|\\\\.profile|\\\\.bash_login|\\\\.bash_profile)$', 'all_dotfiles': '^\\\\.[\\\\w\\\\- ]+$'}", "remarks": "rule_set_000" @@ -9693,6487 +9118,6943 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_tmp", + "value": "kernel_module_cramfs_disabled", "remarks": "rule_set_001" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /tmp Located On Separate Partition", + "value": "Disable Mounting of cramfs", "remarks": "rule_set_001" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_tmp", + "value": "kernel_module_cramfs_disabled", "remarks": "rule_set_001" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /tmp Located On Separate Partition", + "value": "Disable Mounting of cramfs", "remarks": "rule_set_001" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_nodev", + "value": "kernel_module_freevxfs_disabled", "remarks": "rule_set_002" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /tmp", + "value": "Disable Mounting of freevxfs", "remarks": "rule_set_002" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_nodev", + "value": "kernel_module_freevxfs_disabled", "remarks": "rule_set_002" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /tmp", + "value": "Disable Mounting of freevxfs", "remarks": "rule_set_002" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_nosuid", + "value": "kernel_module_hfs_disabled", "remarks": "rule_set_003" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /tmp", + "value": "Disable Mounting of hfs", "remarks": "rule_set_003" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_nosuid", + "value": "kernel_module_hfs_disabled", "remarks": "rule_set_003" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /tmp", + "value": "Disable Mounting of hfs", "remarks": "rule_set_003" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_noexec", + "value": "kernel_module_hfsplus_disabled", "remarks": "rule_set_004" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /tmp", + "value": "Disable Mounting of hfsplus", "remarks": "rule_set_004" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_noexec", + "value": "kernel_module_hfsplus_disabled", "remarks": "rule_set_004" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /tmp", + "value": "Disable Mounting of hfsplus", "remarks": "rule_set_004" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_dev_shm", + "value": "kernel_module_jffs2_disabled", "remarks": "rule_set_005" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /dev/shm is configured", + "value": "Disable Mounting of jffs2", "remarks": "rule_set_005" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_dev_shm", + "value": "kernel_module_jffs2_disabled", "remarks": "rule_set_005" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /dev/shm is configured", + "value": "Disable Mounting of jffs2", "remarks": "rule_set_005" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_nodev", + "value": "partition_for_tmp", "remarks": "rule_set_006" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /dev/shm", + "value": "Ensure /tmp Located On Separate Partition", "remarks": "rule_set_006" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_nodev", + "value": "partition_for_tmp", "remarks": "rule_set_006" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /dev/shm", + "value": "Ensure /tmp Located On Separate Partition", "remarks": "rule_set_006" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_nosuid", + "value": "mount_option_tmp_nodev", "remarks": "rule_set_007" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /dev/shm", + "value": "Add nodev Option to /tmp", "remarks": "rule_set_007" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_nosuid", + "value": "mount_option_tmp_nodev", "remarks": "rule_set_007" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /dev/shm", + "value": "Add nodev Option to /tmp", "remarks": "rule_set_007" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_noexec", + "value": "mount_option_tmp_nosuid", "remarks": "rule_set_008" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /dev/shm", + "value": "Add nosuid Option to /tmp", "remarks": "rule_set_008" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_noexec", + "value": "mount_option_tmp_nosuid", "remarks": "rule_set_008" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /dev/shm", + "value": "Add nosuid Option to /tmp", "remarks": "rule_set_008" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_home_nodev", + "value": "mount_option_tmp_noexec", "remarks": "rule_set_009" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /home", + "value": "Add noexec Option to /tmp", "remarks": "rule_set_009" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_home_nodev", + "value": "mount_option_tmp_noexec", "remarks": "rule_set_009" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /home", + "value": "Add noexec Option to /tmp", "remarks": "rule_set_009" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_home_nosuid", + "value": "partition_for_dev_shm", "remarks": "rule_set_010" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /home", + "value": "Ensure /dev/shm is configured", "remarks": "rule_set_010" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_home_nosuid", + "value": "partition_for_dev_shm", "remarks": "rule_set_010" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /home", + "value": "Ensure /dev/shm is configured", "remarks": "rule_set_010" }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "mount_option_dev_shm_nodev", + "remarks": "rule_set_011" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Add nodev Option to /dev/shm", + "remarks": "rule_set_011" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "mount_option_dev_shm_nodev", + "remarks": "rule_set_011" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Add nodev Option to /dev/shm", + "remarks": "rule_set_011" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "mount_option_dev_shm_nosuid", + "remarks": "rule_set_012" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Add nosuid Option to /dev/shm", + "remarks": "rule_set_012" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "mount_option_dev_shm_nosuid", + "remarks": "rule_set_012" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Add nosuid Option to /dev/shm", + "remarks": "rule_set_012" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "mount_option_dev_shm_noexec", + "remarks": "rule_set_013" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Add noexec Option to /dev/shm", + "remarks": "rule_set_013" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "mount_option_dev_shm_noexec", + "remarks": "rule_set_013" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Add noexec Option to /dev/shm", + "remarks": "rule_set_013" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "mount_option_home_nodev", + "remarks": "rule_set_014" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Add nodev Option to /home", + "remarks": "rule_set_014" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "mount_option_home_nodev", + "remarks": "rule_set_014" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Add nodev Option to /home", + "remarks": "rule_set_014" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "mount_option_home_nosuid", + "remarks": "rule_set_015" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Add nosuid Option to /home", + "remarks": "rule_set_015" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "mount_option_home_nosuid", + "remarks": "rule_set_015" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Add nosuid Option to /home", + "remarks": "rule_set_015" + }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_nodev", - "remarks": "rule_set_011" + "remarks": "rule_set_016" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nodev Option to /var", - "remarks": "rule_set_011" + "remarks": "rule_set_016" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_nodev", - "remarks": "rule_set_011" + "remarks": "rule_set_016" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nodev Option to /var", - "remarks": "rule_set_011" + "remarks": "rule_set_016" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_nosuid", - "remarks": "rule_set_012" + "remarks": "rule_set_017" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nosuid Option to /var", - "remarks": "rule_set_012" + "remarks": "rule_set_017" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_nosuid", - "remarks": "rule_set_012" + "remarks": "rule_set_017" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nosuid Option to /var", - "remarks": "rule_set_012" + "remarks": "rule_set_017" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_tmp_nodev", - "remarks": "rule_set_013" + "remarks": "rule_set_018" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nodev Option to /var/tmp", - "remarks": "rule_set_013" + "remarks": "rule_set_018" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_tmp_nodev", - "remarks": "rule_set_013" + "remarks": "rule_set_018" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nodev Option to /var/tmp", - "remarks": "rule_set_013" + "remarks": "rule_set_018" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_tmp_nosuid", - "remarks": "rule_set_014" + "remarks": "rule_set_019" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nosuid Option to /var/tmp", - "remarks": "rule_set_014" + "remarks": "rule_set_019" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_tmp_nosuid", - "remarks": "rule_set_014" + "remarks": "rule_set_019" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nosuid Option to /var/tmp", - "remarks": "rule_set_014" + "remarks": "rule_set_019" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_tmp_noexec", - "remarks": "rule_set_015" + "remarks": "rule_set_020" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add noexec Option to /var/tmp", - "remarks": "rule_set_015" + "remarks": "rule_set_020" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_tmp_noexec", - "remarks": "rule_set_015" + "remarks": "rule_set_020" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add noexec Option to /var/tmp", - "remarks": "rule_set_015" + "remarks": "rule_set_020" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_nodev", - "remarks": "rule_set_016" + "remarks": "rule_set_021" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nodev Option to /var/log", - "remarks": "rule_set_016" + "remarks": "rule_set_021" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_nodev", - "remarks": "rule_set_016" + "remarks": "rule_set_021" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nodev Option to /var/log", - "remarks": "rule_set_016" + "remarks": "rule_set_021" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_nosuid", - "remarks": "rule_set_017" + "remarks": "rule_set_022" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nosuid Option to /var/log", - "remarks": "rule_set_017" + "remarks": "rule_set_022" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_nosuid", - "remarks": "rule_set_017" + "remarks": "rule_set_022" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nosuid Option to /var/log", - "remarks": "rule_set_017" + "remarks": "rule_set_022" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_noexec", - "remarks": "rule_set_018" + "remarks": "rule_set_023" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add noexec Option to /var/log", - "remarks": "rule_set_018" + "remarks": "rule_set_023" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_noexec", - "remarks": "rule_set_018" + "remarks": "rule_set_023" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add noexec Option to /var/log", - "remarks": "rule_set_018" + "remarks": "rule_set_023" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_audit_nodev", - "remarks": "rule_set_019" + "remarks": "rule_set_024" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nodev Option to /var/log/audit", - "remarks": "rule_set_019" + "remarks": "rule_set_024" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_audit_nodev", - "remarks": "rule_set_019" + "remarks": "rule_set_024" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nodev Option to /var/log/audit", - "remarks": "rule_set_019" + "remarks": "rule_set_024" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_audit_nosuid", - "remarks": "rule_set_020" + "remarks": "rule_set_025" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nosuid Option to /var/log/audit", - "remarks": "rule_set_020" + "remarks": "rule_set_025" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_audit_nosuid", - "remarks": "rule_set_020" + "remarks": "rule_set_025" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nosuid Option to /var/log/audit", - "remarks": "rule_set_020" + "remarks": "rule_set_025" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_audit_noexec", - "remarks": "rule_set_021" + "remarks": "rule_set_026" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add noexec Option to /var/log/audit", - "remarks": "rule_set_021" + "remarks": "rule_set_026" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_audit_noexec", - "remarks": "rule_set_021" + "remarks": "rule_set_026" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add noexec Option to /var/log/audit", - "remarks": "rule_set_021" + "remarks": "rule_set_026" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "ensure_gpgcheck_globally_activated", - "remarks": "rule_set_022" + "remarks": "rule_set_027" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure gpgcheck Enabled In Main dnf Configuration", - "remarks": "rule_set_022" + "remarks": "rule_set_027" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "ensure_gpgcheck_globally_activated", - "remarks": "rule_set_022" + "remarks": "rule_set_027" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure gpgcheck Enabled In Main dnf Configuration", - "remarks": "rule_set_022" + "remarks": "rule_set_027" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_libselinux_installed", - "remarks": "rule_set_023" + "remarks": "rule_set_028" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Install libselinux Package", - "remarks": "rule_set_023" + "remarks": "rule_set_028" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_libselinux_installed", - "remarks": "rule_set_023" + "remarks": "rule_set_028" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Install libselinux Package", - "remarks": "rule_set_023" + "remarks": "rule_set_028" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "grub2_enable_selinux", - "remarks": "rule_set_024" + "remarks": "rule_set_029" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure SELinux Not Disabled in /etc/default/grub", - "remarks": "rule_set_024" + "remarks": "rule_set_029" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "grub2_enable_selinux", - "remarks": "rule_set_024" + "remarks": "rule_set_029" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure SELinux Not Disabled in /etc/default/grub", - "remarks": "rule_set_024" + "remarks": "rule_set_029" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "selinux_policytype", - "remarks": "rule_set_025" + "remarks": "rule_set_030" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure SELinux Policy", - "remarks": "rule_set_025" + "remarks": "rule_set_030" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "selinux_policytype", - "remarks": "rule_set_025" + "remarks": "rule_set_030" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure SELinux Policy", - "remarks": "rule_set_025" + "remarks": "rule_set_030" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "selinux_not_disabled", - "remarks": "rule_set_026" + "remarks": "rule_set_031" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure SELinux is Not Disabled", - "remarks": "rule_set_026" + "remarks": "rule_set_031" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "selinux_not_disabled", - "remarks": "rule_set_026" + "remarks": "rule_set_031" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure SELinux is Not Disabled", - "remarks": "rule_set_026" + "remarks": "rule_set_031" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_mcstrans_removed", - "remarks": "rule_set_027" + "remarks": "rule_set_032" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall mcstrans Package", - "remarks": "rule_set_027" + "remarks": "rule_set_032" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_mcstrans_removed", - "remarks": "rule_set_027" + "remarks": "rule_set_032" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall mcstrans Package", - "remarks": "rule_set_027" + "remarks": "rule_set_032" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "grub2_password", - "remarks": "rule_set_028" + "remarks": "rule_set_033" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Boot Loader Password in grub2", - "remarks": "rule_set_028" + "remarks": "rule_set_033" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "grub2_password", - "remarks": "rule_set_028" + "remarks": "rule_set_033" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Boot Loader Password in grub2", - "remarks": "rule_set_028" + "remarks": "rule_set_033" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_grub2_cfg", - "remarks": "rule_set_029" + "remarks": "rule_set_034" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify /boot/grub2/grub.cfg Group Ownership", - "remarks": "rule_set_029" + "remarks": "rule_set_034" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_grub2_cfg", - "remarks": "rule_set_029" + "remarks": "rule_set_034" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify /boot/grub2/grub.cfg Group Ownership", - "remarks": "rule_set_029" + "remarks": "rule_set_034" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_grub2_cfg", - "remarks": "rule_set_030" + "remarks": "rule_set_035" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify /boot/grub2/grub.cfg User Ownership", - "remarks": "rule_set_030" + "remarks": "rule_set_035" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_grub2_cfg", - "remarks": "rule_set_030" + "remarks": "rule_set_035" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify /boot/grub2/grub.cfg User Ownership", - "remarks": "rule_set_030" + "remarks": "rule_set_035" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_grub2_cfg", - "remarks": "rule_set_031" + "remarks": "rule_set_036" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify /boot/grub2/grub.cfg Permissions", - "remarks": "rule_set_031" + "remarks": "rule_set_036" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_grub2_cfg", + "remarks": "rule_set_036" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify /boot/grub2/grub.cfg Permissions", + "remarks": "rule_set_036" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_groupowner_user_cfg", + "remarks": "rule_set_037" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify /boot/grub2/user.cfg Group Ownership", + "remarks": "rule_set_037" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_groupowner_user_cfg", + "remarks": "rule_set_037" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify /boot/grub2/user.cfg Group Ownership", + "remarks": "rule_set_037" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_owner_user_cfg", + "remarks": "rule_set_038" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify /boot/grub2/user.cfg User Ownership", + "remarks": "rule_set_038" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_owner_user_cfg", + "remarks": "rule_set_038" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify /boot/grub2/user.cfg User Ownership", + "remarks": "rule_set_038" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_user_cfg", + "remarks": "rule_set_039" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify /boot/grub2/user.cfg Permissions", + "remarks": "rule_set_039" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_user_cfg", + "remarks": "rule_set_039" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify /boot/grub2/user.cfg Permissions", + "remarks": "rule_set_039" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "disable_users_coredumps", + "remarks": "rule_set_040" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Disable Core Dumps for All Users", + "remarks": "rule_set_040" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_grub2_cfg", - "remarks": "rule_set_031" + "value": "disable_users_coredumps", + "remarks": "rule_set_040" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/grub.cfg Permissions", - "remarks": "rule_set_031" + "value": "Disable Core Dumps for All Users", + "remarks": "rule_set_040" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_user_cfg", - "remarks": "rule_set_032" + "value": "sysctl_fs_protected_hardlinks", + "remarks": "rule_set_041" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/user.cfg Group Ownership", - "remarks": "rule_set_032" + "value": "Enable Kernel Parameter to Enforce DAC on Hardlinks", + "remarks": "rule_set_041" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_user_cfg", - "remarks": "rule_set_032" + "value": "sysctl_fs_protected_hardlinks", + "remarks": "rule_set_041" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/user.cfg Group Ownership", - "remarks": "rule_set_032" + "value": "Enable Kernel Parameter to Enforce DAC on Hardlinks", + "remarks": "rule_set_041" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_user_cfg", - "remarks": "rule_set_033" + "value": "sysctl_fs_suid_dumpable", + "remarks": "rule_set_042" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/user.cfg User Ownership", - "remarks": "rule_set_033" + "value": "Disable Core Dumps for SUID programs", + "remarks": "rule_set_042" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_user_cfg", - "remarks": "rule_set_033" + "value": "sysctl_fs_suid_dumpable", + "remarks": "rule_set_042" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/user.cfg User Ownership", - "remarks": "rule_set_033" + "value": "Disable Core Dumps for SUID programs", + "remarks": "rule_set_042" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_user_cfg", - "remarks": "rule_set_034" + "value": "sysctl_kernel_dmesg_restrict", + "remarks": "rule_set_043" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/user.cfg Permissions", - "remarks": "rule_set_034" + "value": "Restrict Access to Kernel Message Buffer", + "remarks": "rule_set_043" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_user_cfg", - "remarks": "rule_set_034" + "value": "sysctl_kernel_dmesg_restrict", + "remarks": "rule_set_043" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/user.cfg Permissions", - "remarks": "rule_set_034" + "value": "Restrict Access to Kernel Message Buffer", + "remarks": "rule_set_043" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_kernel_randomize_va_space", - "remarks": "rule_set_035" + "value": "sysctl_kernel_kptr_restrict", + "remarks": "rule_set_044" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Randomized Layout of Virtual Address Space", - "remarks": "rule_set_035" + "value": "Restrict Exposed Kernel Pointer Addresses Access", + "remarks": "rule_set_044" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_kernel_randomize_va_space", - "remarks": "rule_set_035" + "value": "sysctl_kernel_kptr_restrict", + "remarks": "rule_set_044" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Randomized Layout of Virtual Address Space", - "remarks": "rule_set_035" + "value": "Restrict Exposed Kernel Pointer Addresses Access", + "remarks": "rule_set_044" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_kernel_yama_ptrace_scope", - "remarks": "rule_set_036" + "remarks": "rule_set_045" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Restrict usage of ptrace to descendant processes", - "remarks": "rule_set_036" + "remarks": "rule_set_045" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_kernel_yama_ptrace_scope", - "remarks": "rule_set_036" + "remarks": "rule_set_045" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Restrict usage of ptrace to descendant processes", - "remarks": "rule_set_036" + "remarks": "rule_set_045" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_backtraces", - "remarks": "rule_set_037" + "value": "sysctl_kernel_randomize_va_space", + "remarks": "rule_set_046" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable core dump backtraces", - "remarks": "rule_set_037" + "value": "Enable Randomized Layout of Virtual Address Space", + "remarks": "rule_set_046" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_backtraces", - "remarks": "rule_set_037" + "value": "sysctl_kernel_randomize_va_space", + "remarks": "rule_set_046" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable core dump backtraces", - "remarks": "rule_set_037" + "value": "Enable Randomized Layout of Virtual Address Space", + "remarks": "rule_set_046" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_storage", - "remarks": "rule_set_038" + "value": "coredump_disable_backtraces", + "remarks": "rule_set_047" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable storing core dump", - "remarks": "rule_set_038" + "value": "Disable core dump backtraces", + "remarks": "rule_set_047" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_storage", - "remarks": "rule_set_038" + "value": "coredump_disable_backtraces", + "remarks": "rule_set_047" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable storing core dump", - "remarks": "rule_set_038" + "value": "Disable core dump backtraces", + "remarks": "rule_set_047" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_crypto_policy", - "remarks": "rule_set_039" + "value": "coredump_disable_storage", + "remarks": "rule_set_048" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure System Cryptography Policy", - "remarks": "rule_set_039" + "value": "Disable storing core dump", + "remarks": "rule_set_048" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_crypto_policy", - "remarks": "rule_set_039" + "value": "coredump_disable_storage", + "remarks": "rule_set_048" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure System Cryptography Policy", - "remarks": "rule_set_039" + "value": "Disable storing core dump", + "remarks": "rule_set_048" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_ssh_crypto_policy", - "remarks": "rule_set_040" + "value": "configure_crypto_policy", + "remarks": "rule_set_049" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure SSH to use System Crypto Policy", - "remarks": "rule_set_040" + "value": "Configure System Cryptography Policy", + "remarks": "rule_set_049" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_ssh_crypto_policy", - "remarks": "rule_set_040" + "value": "configure_crypto_policy", + "remarks": "rule_set_049" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure SSH to use System Crypto Policy", - "remarks": "rule_set_040" + "value": "Configure System Cryptography Policy", + "remarks": "rule_set_049" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "banner_etc_motd_cis", - "remarks": "rule_set_041" + "remarks": "rule_set_050" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Message Of The Day Is Configured Properly", - "remarks": "rule_set_041" + "remarks": "rule_set_050" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "banner_etc_motd_cis", - "remarks": "rule_set_041" + "remarks": "rule_set_050" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Message Of The Day Is Configured Properly", - "remarks": "rule_set_041" + "remarks": "rule_set_050" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "banner_etc_issue_cis", - "remarks": "rule_set_042" + "remarks": "rule_set_051" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Local Login Warning Banner Is Configured Properly", - "remarks": "rule_set_042" + "remarks": "rule_set_051" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "banner_etc_issue_cis", - "remarks": "rule_set_042" + "remarks": "rule_set_051" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Local Login Warning Banner Is Configured Properly", - "remarks": "rule_set_042" + "remarks": "rule_set_051" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "banner_etc_issue_net_cis", - "remarks": "rule_set_043" + "remarks": "rule_set_052" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Remote Login Warning Banner Is Configured Properly", - "remarks": "rule_set_043" + "remarks": "rule_set_052" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "banner_etc_issue_net_cis", - "remarks": "rule_set_043" + "remarks": "rule_set_052" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Remote Login Warning Banner Is Configured Properly", - "remarks": "rule_set_043" + "remarks": "rule_set_052" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_motd", - "remarks": "rule_set_044" + "remarks": "rule_set_053" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Ownership of Message of the Day Banner", - "remarks": "rule_set_044" + "remarks": "rule_set_053" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_motd", - "remarks": "rule_set_044" + "remarks": "rule_set_053" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Ownership of Message of the Day Banner", - "remarks": "rule_set_044" + "remarks": "rule_set_053" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_motd", - "remarks": "rule_set_045" + "remarks": "rule_set_054" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify ownership of Message of the Day Banner", - "remarks": "rule_set_045" + "remarks": "rule_set_054" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_motd", - "remarks": "rule_set_045" + "remarks": "rule_set_054" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify ownership of Message of the Day Banner", - "remarks": "rule_set_045" + "remarks": "rule_set_054" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_motd", - "remarks": "rule_set_046" + "remarks": "rule_set_055" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify permissions on Message of the Day Banner", - "remarks": "rule_set_046" + "remarks": "rule_set_055" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_motd", - "remarks": "rule_set_046" + "remarks": "rule_set_055" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify permissions on Message of the Day Banner", - "remarks": "rule_set_046" + "remarks": "rule_set_055" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_issue", - "remarks": "rule_set_047" + "remarks": "rule_set_056" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Ownership of System Login Banner", - "remarks": "rule_set_047" + "remarks": "rule_set_056" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_issue", - "remarks": "rule_set_047" + "remarks": "rule_set_056" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Ownership of System Login Banner", - "remarks": "rule_set_047" + "remarks": "rule_set_056" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_issue", - "remarks": "rule_set_048" + "remarks": "rule_set_057" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify ownership of System Login Banner", - "remarks": "rule_set_048" + "remarks": "rule_set_057" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_issue", - "remarks": "rule_set_048" + "remarks": "rule_set_057" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify ownership of System Login Banner", - "remarks": "rule_set_048" + "remarks": "rule_set_057" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_issue", - "remarks": "rule_set_049" + "remarks": "rule_set_058" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify permissions on System Login Banner", - "remarks": "rule_set_049" + "remarks": "rule_set_058" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_issue", - "remarks": "rule_set_049" + "remarks": "rule_set_058" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify permissions on System Login Banner", - "remarks": "rule_set_049" + "remarks": "rule_set_058" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_issue_net", - "remarks": "rule_set_050" + "remarks": "rule_set_059" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Ownership of System Login Banner for Remote Connections", - "remarks": "rule_set_050" + "remarks": "rule_set_059" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_issue_net", - "remarks": "rule_set_050" + "remarks": "rule_set_059" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Ownership of System Login Banner for Remote Connections", - "remarks": "rule_set_050" + "remarks": "rule_set_059" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_issue_net", - "remarks": "rule_set_051" + "remarks": "rule_set_060" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify ownership of System Login Banner for Remote Connections", - "remarks": "rule_set_051" + "remarks": "rule_set_060" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_issue_net", - "remarks": "rule_set_051" + "remarks": "rule_set_060" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify ownership of System Login Banner for Remote Connections", - "remarks": "rule_set_051" + "remarks": "rule_set_060" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_issue_net", - "remarks": "rule_set_052" + "remarks": "rule_set_061" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify permissions on System Login Banner for Remote Connections", - "remarks": "rule_set_052" + "remarks": "rule_set_061" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_issue_net", - "remarks": "rule_set_052" + "remarks": "rule_set_061" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify permissions on System Login Banner for Remote Connections", - "remarks": "rule_set_052" + "remarks": "rule_set_061" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_banner_enabled", - "remarks": "rule_set_053" + "remarks": "rule_set_062" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable GNOME3 Login Warning Banner", - "remarks": "rule_set_053" + "remarks": "rule_set_062" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_banner_enabled", - "remarks": "rule_set_053" + "remarks": "rule_set_062" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable GNOME3 Login Warning Banner", - "remarks": "rule_set_053" + "remarks": "rule_set_062" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_login_banner_text", - "remarks": "rule_set_054" + "remarks": "rule_set_063" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set the GNOME3 Login Warning Banner Text", - "remarks": "rule_set_054" + "remarks": "rule_set_063" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_login_banner_text", - "remarks": "rule_set_054" + "remarks": "rule_set_063" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set the GNOME3 Login Warning Banner Text", - "remarks": "rule_set_054" + "remarks": "rule_set_063" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_disable_user_list", - "remarks": "rule_set_055" + "remarks": "rule_set_064" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable the GNOME3 Login User List", - "remarks": "rule_set_055" + "remarks": "rule_set_064" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_disable_user_list", - "remarks": "rule_set_055" + "remarks": "rule_set_064" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable the GNOME3 Login User List", - "remarks": "rule_set_055" + "remarks": "rule_set_064" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_screensaver_idle_delay", - "remarks": "rule_set_056" + "remarks": "rule_set_065" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set GNOME3 Screensaver Inactivity Timeout", - "remarks": "rule_set_056" + "remarks": "rule_set_065" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_screensaver_idle_delay", - "remarks": "rule_set_056" + "remarks": "rule_set_065" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set GNOME3 Screensaver Inactivity Timeout", - "remarks": "rule_set_056" + "remarks": "rule_set_065" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_screensaver_lock_delay", - "remarks": "rule_set_057" + "remarks": "rule_set_066" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set GNOME3 Screensaver Lock Delay After Activation Period", - "remarks": "rule_set_057" + "remarks": "rule_set_066" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_screensaver_lock_delay", - "remarks": "rule_set_057" + "remarks": "rule_set_066" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set GNOME3 Screensaver Lock Delay After Activation Period", - "remarks": "rule_set_057" + "remarks": "rule_set_066" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_session_idle_user_locks", - "remarks": "rule_set_058" + "remarks": "rule_set_067" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Users Cannot Change GNOME3 Session Idle Settings", - "remarks": "rule_set_058" + "remarks": "rule_set_067" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_session_idle_user_locks", - "remarks": "rule_set_058" + "remarks": "rule_set_067" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Users Cannot Change GNOME3 Session Idle Settings", - "remarks": "rule_set_058" + "remarks": "rule_set_067" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_screensaver_user_locks", - "remarks": "rule_set_059" + "remarks": "rule_set_068" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Users Cannot Change GNOME3 Screensaver Settings", - "remarks": "rule_set_059" + "remarks": "rule_set_068" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_screensaver_user_locks", - "remarks": "rule_set_059" + "remarks": "rule_set_068" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Users Cannot Change GNOME3 Screensaver Settings", - "remarks": "rule_set_059" + "remarks": "rule_set_068" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_disable_autorun", - "remarks": "rule_set_060" + "remarks": "rule_set_069" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable GNOME3 Automount running", - "remarks": "rule_set_060" + "remarks": "rule_set_069" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_disable_autorun", - "remarks": "rule_set_060" + "remarks": "rule_set_069" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable GNOME3 Automount running", - "remarks": "rule_set_060" + "remarks": "rule_set_069" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_kea_removed", - "remarks": "rule_set_061" + "remarks": "rule_set_070" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall kea Package", - "remarks": "rule_set_061" + "remarks": "rule_set_070" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_kea_removed", - "remarks": "rule_set_061" + "remarks": "rule_set_070" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall kea Package", - "remarks": "rule_set_061" + "remarks": "rule_set_070" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_bind_removed", - "remarks": "rule_set_062" + "remarks": "rule_set_071" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall bind Package", - "remarks": "rule_set_062" + "remarks": "rule_set_071" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_bind_removed", - "remarks": "rule_set_062" + "remarks": "rule_set_071" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall bind Package", - "remarks": "rule_set_062" + "remarks": "rule_set_071" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_dnsmasq_removed", - "remarks": "rule_set_063" + "remarks": "rule_set_072" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall dnsmasq Package", - "remarks": "rule_set_063" + "remarks": "rule_set_072" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_dnsmasq_removed", - "remarks": "rule_set_063" + "remarks": "rule_set_072" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall dnsmasq Package", - "remarks": "rule_set_063" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_samba_removed", - "remarks": "rule_set_064" - }, - { - "name": "Rule_Description", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall Samba Package", - "remarks": "rule_set_064" - }, - { - "name": "Check_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_samba_removed", - "remarks": "rule_set_064" - }, - { - "name": "Check_Description", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall Samba Package", - "remarks": "rule_set_064" + "remarks": "rule_set_072" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_vsftpd_removed", - "remarks": "rule_set_065" + "remarks": "rule_set_073" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall vsftpd Package", - "remarks": "rule_set_065" + "remarks": "rule_set_073" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_vsftpd_removed", - "remarks": "rule_set_065" + "remarks": "rule_set_073" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall vsftpd Package", - "remarks": "rule_set_065" + "remarks": "rule_set_073" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_dovecot_removed", - "remarks": "rule_set_066" + "remarks": "rule_set_074" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall dovecot Package", - "remarks": "rule_set_066" + "remarks": "rule_set_074" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_dovecot_removed", - "remarks": "rule_set_066" + "remarks": "rule_set_074" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall dovecot Package", - "remarks": "rule_set_066" + "remarks": "rule_set_074" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_cyrus-imapd_removed", - "remarks": "rule_set_067" + "remarks": "rule_set_075" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall cyrus-imapd Package", - "remarks": "rule_set_067" + "remarks": "rule_set_075" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_cyrus-imapd_removed", - "remarks": "rule_set_067" + "remarks": "rule_set_075" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall cyrus-imapd Package", - "remarks": "rule_set_067" + "remarks": "rule_set_075" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_nfs_disabled", - "remarks": "rule_set_068" + "remarks": "rule_set_076" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Network File System (nfs)", - "remarks": "rule_set_068" + "remarks": "rule_set_076" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_nfs_disabled", - "remarks": "rule_set_068" + "remarks": "rule_set_076" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Network File System (nfs)", - "remarks": "rule_set_068" + "remarks": "rule_set_076" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_rpcbind_disabled", - "remarks": "rule_set_069" + "remarks": "rule_set_077" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable rpcbind Service", - "remarks": "rule_set_069" + "remarks": "rule_set_077" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_rpcbind_disabled", - "remarks": "rule_set_069" + "remarks": "rule_set_077" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable rpcbind Service", - "remarks": "rule_set_069" + "remarks": "rule_set_077" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_rsync_removed", - "remarks": "rule_set_070" + "remarks": "rule_set_078" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall rsync Package", - "remarks": "rule_set_070" + "remarks": "rule_set_078" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_rsync_removed", - "remarks": "rule_set_070" + "remarks": "rule_set_078" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall rsync Package", - "remarks": "rule_set_070" + "remarks": "rule_set_078" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "package_samba_removed", + "remarks": "rule_set_079" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Uninstall Samba Package", + "remarks": "rule_set_079" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "package_samba_removed", + "remarks": "rule_set_079" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Uninstall Samba Package", + "remarks": "rule_set_079" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_net-snmp_removed", - "remarks": "rule_set_071" + "remarks": "rule_set_080" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall net-snmp Package", - "remarks": "rule_set_071" + "remarks": "rule_set_080" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_net-snmp_removed", - "remarks": "rule_set_071" + "remarks": "rule_set_080" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall net-snmp Package", - "remarks": "rule_set_071" + "remarks": "rule_set_080" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_telnet-server_removed", - "remarks": "rule_set_072" + "remarks": "rule_set_081" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall telnet-server Package", - "remarks": "rule_set_072" + "remarks": "rule_set_081" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_telnet-server_removed", - "remarks": "rule_set_072" + "remarks": "rule_set_081" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall telnet-server Package", - "remarks": "rule_set_072" + "remarks": "rule_set_081" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_tftp-server_removed", - "remarks": "rule_set_073" + "remarks": "rule_set_082" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall tftp-server Package", - "remarks": "rule_set_073" + "remarks": "rule_set_082" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_tftp-server_removed", - "remarks": "rule_set_073" + "remarks": "rule_set_082" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall tftp-server Package", - "remarks": "rule_set_073" + "remarks": "rule_set_082" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_squid_removed", - "remarks": "rule_set_074" + "remarks": "rule_set_083" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall squid Package", - "remarks": "rule_set_074" + "remarks": "rule_set_083" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_squid_removed", - "remarks": "rule_set_074" + "remarks": "rule_set_083" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall squid Package", - "remarks": "rule_set_074" + "remarks": "rule_set_083" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_httpd_removed", - "remarks": "rule_set_075" + "remarks": "rule_set_084" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall httpd Package", - "remarks": "rule_set_075" + "remarks": "rule_set_084" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_httpd_removed", - "remarks": "rule_set_075" + "remarks": "rule_set_084" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall httpd Package", - "remarks": "rule_set_075" + "remarks": "rule_set_084" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_nginx_removed", - "remarks": "rule_set_076" + "remarks": "rule_set_085" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall nginx Package", - "remarks": "rule_set_076" + "remarks": "rule_set_085" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_nginx_removed", - "remarks": "rule_set_076" + "remarks": "rule_set_085" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall nginx Package", - "remarks": "rule_set_076" + "remarks": "rule_set_085" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "postfix_network_listening_disabled", - "remarks": "rule_set_077" + "remarks": "rule_set_086" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Postfix Network Listening", - "remarks": "rule_set_077" + "remarks": "rule_set_086" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "postfix_network_listening_disabled", - "remarks": "rule_set_077" + "remarks": "rule_set_086" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Postfix Network Listening", - "remarks": "rule_set_077" + "remarks": "rule_set_086" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "has_nonlocal_mta", - "remarks": "rule_set_078" + "remarks": "rule_set_087" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Mail Transfer Agent is not Listening on any non-loopback Address", - "remarks": "rule_set_078" + "remarks": "rule_set_087" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "has_nonlocal_mta", - "remarks": "rule_set_078" + "remarks": "rule_set_087" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Mail Transfer Agent is not Listening on any non-loopback Address", - "remarks": "rule_set_078" + "remarks": "rule_set_087" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_ftp_removed", - "remarks": "rule_set_079" + "remarks": "rule_set_088" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Remove ftp Package", - "remarks": "rule_set_079" + "remarks": "rule_set_088" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_ftp_removed", - "remarks": "rule_set_079" + "remarks": "rule_set_088" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Remove ftp Package", - "remarks": "rule_set_079" + "remarks": "rule_set_088" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_telnet_removed", - "remarks": "rule_set_080" + "remarks": "rule_set_089" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Remove telnet Clients", - "remarks": "rule_set_080" + "remarks": "rule_set_089" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_telnet_removed", - "remarks": "rule_set_080" + "remarks": "rule_set_089" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Remove telnet Clients", - "remarks": "rule_set_080" + "remarks": "rule_set_089" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_tftp_removed", - "remarks": "rule_set_081" + "remarks": "rule_set_090" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Remove tftp Daemon", - "remarks": "rule_set_081" + "remarks": "rule_set_090" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_tftp_removed", - "remarks": "rule_set_081" + "remarks": "rule_set_090" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Remove tftp Daemon", - "remarks": "rule_set_081" + "remarks": "rule_set_090" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "chronyd_specify_remote_server", - "remarks": "rule_set_082" + "remarks": "rule_set_091" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "A remote time server for Chrony is configured", - "remarks": "rule_set_082" + "remarks": "rule_set_091" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "chronyd_specify_remote_server", - "remarks": "rule_set_082" + "remarks": "rule_set_091" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "A remote time server for Chrony is configured", - "remarks": "rule_set_082" + "remarks": "rule_set_091" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "chronyd_run_as_chrony_user", - "remarks": "rule_set_083" + "remarks": "rule_set_092" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that chronyd is running under chrony user account", - "remarks": "rule_set_083" + "remarks": "rule_set_092" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "chronyd_run_as_chrony_user", - "remarks": "rule_set_083" + "remarks": "rule_set_092" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that chronyd is running under chrony user account", - "remarks": "rule_set_083" + "remarks": "rule_set_092" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_cron_installed", - "remarks": "rule_set_084" + "remarks": "rule_set_093" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Install the cron service", - "remarks": "rule_set_084" + "remarks": "rule_set_093" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_cron_installed", - "remarks": "rule_set_084" + "remarks": "rule_set_093" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Install the cron service", - "remarks": "rule_set_084" + "remarks": "rule_set_093" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_crond_enabled", - "remarks": "rule_set_085" + "remarks": "rule_set_094" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable cron Service", - "remarks": "rule_set_085" + "remarks": "rule_set_094" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_crond_enabled", - "remarks": "rule_set_085" + "remarks": "rule_set_094" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable cron Service", - "remarks": "rule_set_085" + "remarks": "rule_set_094" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_crontab", - "remarks": "rule_set_086" + "remarks": "rule_set_095" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns Crontab", - "remarks": "rule_set_086" + "remarks": "rule_set_095" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_crontab", - "remarks": "rule_set_086" + "remarks": "rule_set_095" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns Crontab", - "remarks": "rule_set_086" + "remarks": "rule_set_095" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_crontab", - "remarks": "rule_set_087" + "remarks": "rule_set_096" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on crontab", - "remarks": "rule_set_087" + "remarks": "rule_set_096" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_crontab", - "remarks": "rule_set_087" + "remarks": "rule_set_096" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on crontab", - "remarks": "rule_set_087" + "remarks": "rule_set_096" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_crontab", - "remarks": "rule_set_088" + "remarks": "rule_set_097" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on crontab", - "remarks": "rule_set_088" + "remarks": "rule_set_097" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_crontab", - "remarks": "rule_set_088" + "remarks": "rule_set_097" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on crontab", - "remarks": "rule_set_088" + "remarks": "rule_set_097" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_cron_hourly", - "remarks": "rule_set_089" + "remarks": "rule_set_098" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns cron.hourly", - "remarks": "rule_set_089" + "remarks": "rule_set_098" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_cron_hourly", - "remarks": "rule_set_089" + "remarks": "rule_set_098" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns cron.hourly", - "remarks": "rule_set_089" + "remarks": "rule_set_098" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_cron_hourly", - "remarks": "rule_set_090" + "remarks": "rule_set_099" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on cron.hourly", - "remarks": "rule_set_090" + "remarks": "rule_set_099" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_cron_hourly", - "remarks": "rule_set_090" + "remarks": "rule_set_099" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on cron.hourly", - "remarks": "rule_set_090" + "remarks": "rule_set_099" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_cron_hourly", - "remarks": "rule_set_091" + "remarks": "rule_set_100" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on cron.hourly", - "remarks": "rule_set_091" + "remarks": "rule_set_100" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_cron_hourly", - "remarks": "rule_set_091" + "remarks": "rule_set_100" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on cron.hourly", - "remarks": "rule_set_091" + "remarks": "rule_set_100" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_cron_daily", - "remarks": "rule_set_092" + "remarks": "rule_set_101" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns cron.daily", - "remarks": "rule_set_092" + "remarks": "rule_set_101" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_cron_daily", - "remarks": "rule_set_092" + "remarks": "rule_set_101" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns cron.daily", - "remarks": "rule_set_092" + "remarks": "rule_set_101" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_cron_daily", - "remarks": "rule_set_093" + "remarks": "rule_set_102" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on cron.daily", - "remarks": "rule_set_093" + "remarks": "rule_set_102" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_cron_daily", - "remarks": "rule_set_093" + "remarks": "rule_set_102" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on cron.daily", - "remarks": "rule_set_093" + "remarks": "rule_set_102" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_cron_daily", - "remarks": "rule_set_094" + "remarks": "rule_set_103" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on cron.daily", - "remarks": "rule_set_094" + "remarks": "rule_set_103" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_cron_daily", - "remarks": "rule_set_094" + "remarks": "rule_set_103" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on cron.daily", - "remarks": "rule_set_094" + "remarks": "rule_set_103" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_cron_weekly", - "remarks": "rule_set_095" + "remarks": "rule_set_104" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns cron.weekly", - "remarks": "rule_set_095" + "remarks": "rule_set_104" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_cron_weekly", - "remarks": "rule_set_095" + "remarks": "rule_set_104" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns cron.weekly", - "remarks": "rule_set_095" + "remarks": "rule_set_104" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_cron_weekly", - "remarks": "rule_set_096" + "remarks": "rule_set_105" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on cron.weekly", - "remarks": "rule_set_096" + "remarks": "rule_set_105" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_cron_weekly", - "remarks": "rule_set_096" + "remarks": "rule_set_105" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on cron.weekly", - "remarks": "rule_set_096" + "remarks": "rule_set_105" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_cron_weekly", - "remarks": "rule_set_097" + "remarks": "rule_set_106" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on cron.weekly", - "remarks": "rule_set_097" + "remarks": "rule_set_106" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_cron_weekly", - "remarks": "rule_set_097" + "remarks": "rule_set_106" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on cron.weekly", - "remarks": "rule_set_097" + "remarks": "rule_set_106" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_cron_monthly", - "remarks": "rule_set_098" + "remarks": "rule_set_107" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns cron.monthly", - "remarks": "rule_set_098" + "remarks": "rule_set_107" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_groupowner_cron_monthly", + "remarks": "rule_set_107" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify Group Who Owns cron.monthly", + "remarks": "rule_set_107" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_owner_cron_monthly", + "remarks": "rule_set_108" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify Owner on cron.monthly", + "remarks": "rule_set_108" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_owner_cron_monthly", + "remarks": "rule_set_108" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify Owner on cron.monthly", + "remarks": "rule_set_108" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_cron_monthly", + "remarks": "rule_set_109" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify Permissions on cron.monthly", + "remarks": "rule_set_109" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_cron_monthly", + "remarks": "rule_set_109" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify Permissions on cron.monthly", + "remarks": "rule_set_109" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_groupowner_cron_d", + "remarks": "rule_set_110" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify Group Who Owns cron.d", + "remarks": "rule_set_110" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_groupowner_cron_d", + "remarks": "rule_set_110" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify Group Who Owns cron.d", + "remarks": "rule_set_110" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_owner_cron_d", + "remarks": "rule_set_111" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify Owner on cron.d", + "remarks": "rule_set_111" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_owner_cron_d", + "remarks": "rule_set_111" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify Owner on cron.d", + "remarks": "rule_set_111" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_cron_d", + "remarks": "rule_set_112" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify Permissions on cron.d", + "remarks": "rule_set_112" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_cron_d", + "remarks": "rule_set_112" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify Permissions on cron.d", + "remarks": "rule_set_112" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_cron_deny_not_exist", + "remarks": "rule_set_113" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure that /etc/cron.deny does not exist", + "remarks": "rule_set_113" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_monthly", - "remarks": "rule_set_098" + "value": "file_cron_deny_not_exist", + "remarks": "rule_set_113" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns cron.monthly", - "remarks": "rule_set_098" + "value": "Ensure that /etc/cron.deny does not exist", + "remarks": "rule_set_113" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_monthly", - "remarks": "rule_set_099" + "value": "file_cron_allow_exists", + "remarks": "rule_set_114" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on cron.monthly", - "remarks": "rule_set_099" + "value": "Ensure that /etc/cron.allow exists", + "remarks": "rule_set_114" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_monthly", - "remarks": "rule_set_099" + "value": "file_cron_allow_exists", + "remarks": "rule_set_114" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on cron.monthly", - "remarks": "rule_set_099" + "value": "Ensure that /etc/cron.allow exists", + "remarks": "rule_set_114" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_monthly", - "remarks": "rule_set_100" + "value": "file_groupowner_cron_allow", + "remarks": "rule_set_115" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on cron.monthly", - "remarks": "rule_set_100" + "value": "Verify Group Who Owns /etc/cron.allow file", + "remarks": "rule_set_115" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_monthly", - "remarks": "rule_set_100" + "value": "file_groupowner_cron_allow", + "remarks": "rule_set_115" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on cron.monthly", - "remarks": "rule_set_100" + "value": "Verify Group Who Owns /etc/cron.allow file", + "remarks": "rule_set_115" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_d", - "remarks": "rule_set_101" + "value": "file_owner_cron_allow", + "remarks": "rule_set_116" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns cron.d", - "remarks": "rule_set_101" + "value": "Verify User Who Owns /etc/cron.allow file", + "remarks": "rule_set_116" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_d", - "remarks": "rule_set_101" + "value": "file_owner_cron_allow", + "remarks": "rule_set_116" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns cron.d", - "remarks": "rule_set_101" + "value": "Verify User Who Owns /etc/cron.allow file", + "remarks": "rule_set_116" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_d", - "remarks": "rule_set_102" + "value": "file_permissions_cron_allow", + "remarks": "rule_set_117" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on cron.d", - "remarks": "rule_set_102" + "value": "Verify Permissions on /etc/cron.allow file", + "remarks": "rule_set_117" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_d", - "remarks": "rule_set_102" + "value": "file_permissions_cron_allow", + "remarks": "rule_set_117" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on cron.d", - "remarks": "rule_set_102" + "value": "Verify Permissions on /etc/cron.allow file", + "remarks": "rule_set_117" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_d", - "remarks": "rule_set_103" + "value": "file_at_deny_not_exist", + "remarks": "rule_set_118" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on cron.d", - "remarks": "rule_set_103" + "value": "Ensure that /etc/at.deny does not exist", + "remarks": "rule_set_118" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_d", - "remarks": "rule_set_103" + "value": "file_at_deny_not_exist", + "remarks": "rule_set_118" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on cron.d", - "remarks": "rule_set_103" + "value": "Ensure that /etc/at.deny does not exist", + "remarks": "rule_set_118" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_cron_deny_not_exist", - "remarks": "rule_set_104" + "value": "file_groupowner_at_allow", + "remarks": "rule_set_119" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that /etc/cron.deny does not exist", - "remarks": "rule_set_104" + "value": "Verify Group Who Owns /etc/at.allow file", + "remarks": "rule_set_119" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_cron_deny_not_exist", - "remarks": "rule_set_104" + "value": "file_groupowner_at_allow", + "remarks": "rule_set_119" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that /etc/cron.deny does not exist", - "remarks": "rule_set_104" + "value": "Verify Group Who Owns /etc/at.allow file", + "remarks": "rule_set_119" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_cron_allow_exists", - "remarks": "rule_set_105" + "value": "file_owner_at_allow", + "remarks": "rule_set_120" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that /etc/cron.allow exists", - "remarks": "rule_set_105" + "value": "Verify User Who Owns /etc/at.allow file", + "remarks": "rule_set_120" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_cron_allow_exists", - "remarks": "rule_set_105" + "value": "file_owner_at_allow", + "remarks": "rule_set_120" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that /etc/cron.allow exists", - "remarks": "rule_set_105" + "value": "Verify User Who Owns /etc/at.allow file", + "remarks": "rule_set_120" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_allow", - "remarks": "rule_set_106" + "value": "file_permissions_at_allow", + "remarks": "rule_set_121" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns /etc/cron.allow file", - "remarks": "rule_set_106" + "value": "Verify Permissions on /etc/at.allow file", + "remarks": "rule_set_121" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_allow", - "remarks": "rule_set_106" + "value": "file_permissions_at_allow", + "remarks": "rule_set_121" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns /etc/cron.allow file", - "remarks": "rule_set_106" + "value": "Verify Permissions on /etc/at.allow file", + "remarks": "rule_set_121" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_allow", - "remarks": "rule_set_107" + "value": "kernel_module_atm_disabled", + "remarks": "rule_set_122" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns /etc/cron.allow file", - "remarks": "rule_set_107" + "value": "Disable ATM Support", + "remarks": "rule_set_122" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_allow", - "remarks": "rule_set_107" + "value": "kernel_module_atm_disabled", + "remarks": "rule_set_122" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns /etc/cron.allow file", - "remarks": "rule_set_107" + "value": "Disable ATM Support", + "remarks": "rule_set_122" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_allow", - "remarks": "rule_set_108" + "value": "kernel_module_can_disabled", + "remarks": "rule_set_123" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on /etc/cron.allow file", - "remarks": "rule_set_108" + "value": "Disable CAN Support", + "remarks": "rule_set_123" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_allow", - "remarks": "rule_set_108" + "value": "kernel_module_can_disabled", + "remarks": "rule_set_123" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on /etc/cron.allow file", - "remarks": "rule_set_108" + "value": "Disable CAN Support", + "remarks": "rule_set_123" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_at_deny_not_exist", - "remarks": "rule_set_109" + "value": "kernel_module_dccp_disabled", + "remarks": "rule_set_124" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that /etc/at.deny does not exist", - "remarks": "rule_set_109" + "value": "Disable DCCP Support", + "remarks": "rule_set_124" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_at_deny_not_exist", - "remarks": "rule_set_109" + "value": "kernel_module_dccp_disabled", + "remarks": "rule_set_124" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that /etc/at.deny does not exist", - "remarks": "rule_set_109" + "value": "Disable DCCP Support", + "remarks": "rule_set_124" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_at_allow", - "remarks": "rule_set_110" + "value": "kernel_module_tipc_disabled", + "remarks": "rule_set_125" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns /etc/at.allow file", - "remarks": "rule_set_110" + "value": "Disable TIPC Support", + "remarks": "rule_set_125" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_at_allow", - "remarks": "rule_set_110" + "value": "kernel_module_tipc_disabled", + "remarks": "rule_set_125" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns /etc/at.allow file", - "remarks": "rule_set_110" + "value": "Disable TIPC Support", + "remarks": "rule_set_125" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_at_allow", - "remarks": "rule_set_111" + "value": "kernel_module_rds_disabled", + "remarks": "rule_set_126" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns /etc/at.allow file", - "remarks": "rule_set_111" + "value": "Disable RDS Support", + "remarks": "rule_set_126" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_at_allow", - "remarks": "rule_set_111" + "value": "kernel_module_rds_disabled", + "remarks": "rule_set_126" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns /etc/at.allow file", - "remarks": "rule_set_111" + "value": "Disable RDS Support", + "remarks": "rule_set_126" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_at_allow", - "remarks": "rule_set_112" + "value": "kernel_module_sctp_disabled", + "remarks": "rule_set_127" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on /etc/at.allow file", - "remarks": "rule_set_112" + "value": "Disable SCTP Support", + "remarks": "rule_set_127" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_at_allow", - "remarks": "rule_set_112" + "value": "kernel_module_sctp_disabled", + "remarks": "rule_set_127" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on /etc/at.allow file", - "remarks": "rule_set_112" + "value": "Disable SCTP Support", + "remarks": "rule_set_127" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_ip_forward", - "remarks": "rule_set_113" + "remarks": "rule_set_128" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Kernel Parameter for IP Forwarding on IPv4 Interfaces", - "remarks": "rule_set_113" + "remarks": "rule_set_128" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_ip_forward", - "remarks": "rule_set_113" + "remarks": "rule_set_128" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Kernel Parameter for IP Forwarding on IPv4 Interfaces", - "remarks": "rule_set_113" + "remarks": "rule_set_128" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_forwarding", - "remarks": "rule_set_114" + "value": "sysctl_net_ipv4_conf_all_forwarding", + "remarks": "rule_set_129" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for IPv6 Forwarding", - "remarks": "rule_set_114" + "value": "Disable Kernel Parameter for IPv4 Forwarding on all IPv4 Interfaces", + "remarks": "rule_set_129" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_forwarding", - "remarks": "rule_set_114" + "value": "sysctl_net_ipv4_conf_all_forwarding", + "remarks": "rule_set_129" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for IPv6 Forwarding", - "remarks": "rule_set_114" + "value": "Disable Kernel Parameter for IPv4 Forwarding on all IPv4 Interfaces", + "remarks": "rule_set_129" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_conf_all_send_redirects", - "remarks": "rule_set_115" + "remarks": "rule_set_130" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces", - "remarks": "rule_set_115" + "remarks": "rule_set_130" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_conf_all_send_redirects", - "remarks": "rule_set_115" + "remarks": "rule_set_130" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces", - "remarks": "rule_set_115" + "remarks": "rule_set_130" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_conf_default_send_redirects", - "remarks": "rule_set_116" + "remarks": "rule_set_131" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces by Default", - "remarks": "rule_set_116" + "remarks": "rule_set_131" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_conf_default_send_redirects", - "remarks": "rule_set_116" + "remarks": "rule_set_131" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces by Default", - "remarks": "rule_set_116" + "remarks": "rule_set_131" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses", - "remarks": "rule_set_117" + "remarks": "rule_set_132" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable Kernel Parameter to Ignore Bogus ICMP Error Responses on IPv4 Interfaces", - "remarks": "rule_set_117" + "remarks": "rule_set_132" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses", - "remarks": "rule_set_117" + "remarks": "rule_set_132" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable Kernel Parameter to Ignore Bogus ICMP Error Responses on IPv4 Interfaces", - "remarks": "rule_set_117" + "remarks": "rule_set_132" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts", - "remarks": "rule_set_118" + "remarks": "rule_set_133" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable Kernel Parameter to Ignore ICMP Broadcast Echo Requests on IPv4 Interfaces", - "remarks": "rule_set_118" + "remarks": "rule_set_133" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts", - "remarks": "rule_set_118" + "remarks": "rule_set_133" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable Kernel Parameter to Ignore ICMP Broadcast Echo Requests on IPv4 Interfaces", - "remarks": "rule_set_118" + "remarks": "rule_set_133" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_conf_all_accept_redirects", - "remarks": "rule_set_119" + "remarks": "rule_set_134" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Accepting ICMP Redirects for All IPv4 Interfaces", - "remarks": "rule_set_119" + "remarks": "rule_set_134" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_conf_all_accept_redirects", - "remarks": "rule_set_119" + "remarks": "rule_set_134" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Accepting ICMP Redirects for All IPv4 Interfaces", - "remarks": "rule_set_119" + "remarks": "rule_set_134" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_conf_default_accept_redirects", - "remarks": "rule_set_120" + "remarks": "rule_set_135" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 Interfaces", - "remarks": "rule_set_120" + "remarks": "rule_set_135" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_conf_default_accept_redirects", - "remarks": "rule_set_120" + "remarks": "rule_set_135" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 Interfaces", - "remarks": "rule_set_120" + "remarks": "rule_set_135" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_redirects", - "remarks": "rule_set_121" + "value": "sysctl_net_ipv4_conf_all_secure_redirects", + "remarks": "rule_set_136" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Accepting ICMP Redirects for All IPv6 Interfaces", - "remarks": "rule_set_121" + "value": "Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces", + "remarks": "rule_set_136" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_redirects", - "remarks": "rule_set_121" + "value": "sysctl_net_ipv4_conf_all_secure_redirects", + "remarks": "rule_set_136" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Accepting ICMP Redirects for All IPv6 Interfaces", - "remarks": "rule_set_121" + "value": "Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces", + "remarks": "rule_set_136" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_redirects", - "remarks": "rule_set_122" + "value": "sysctl_net_ipv4_conf_default_secure_redirects", + "remarks": "rule_set_137" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces", - "remarks": "rule_set_122" + "value": "Configure Kernel Parameter for Accepting Secure Redirects By Default", + "remarks": "rule_set_137" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_redirects", - "remarks": "rule_set_122" + "value": "sysctl_net_ipv4_conf_default_secure_redirects", + "remarks": "rule_set_137" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces", - "remarks": "rule_set_122" + "value": "Configure Kernel Parameter for Accepting Secure Redirects By Default", + "remarks": "rule_set_137" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_secure_redirects", - "remarks": "rule_set_123" + "value": "sysctl_net_ipv4_conf_all_rp_filter", + "remarks": "rule_set_138" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces", - "remarks": "rule_set_123" + "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces", + "remarks": "rule_set_138" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_secure_redirects", - "remarks": "rule_set_123" + "value": "sysctl_net_ipv4_conf_all_rp_filter", + "remarks": "rule_set_138" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces", - "remarks": "rule_set_123" + "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces", + "remarks": "rule_set_138" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_secure_redirects", - "remarks": "rule_set_124" + "value": "sysctl_net_ipv4_conf_default_rp_filter", + "remarks": "rule_set_139" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Kernel Parameter for Accepting Secure Redirects By Default", - "remarks": "rule_set_124" + "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces by Default", + "remarks": "rule_set_139" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_secure_redirects", - "remarks": "rule_set_124" + "value": "sysctl_net_ipv4_conf_default_rp_filter", + "remarks": "rule_set_139" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Kernel Parameter for Accepting Secure Redirects By Default", - "remarks": "rule_set_124" + "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces by Default", + "remarks": "rule_set_139" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_rp_filter", - "remarks": "rule_set_125" + "value": "sysctl_net_ipv4_conf_all_accept_source_route", + "remarks": "rule_set_140" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces", - "remarks": "rule_set_125" + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces", + "remarks": "rule_set_140" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_rp_filter", - "remarks": "rule_set_125" + "value": "sysctl_net_ipv4_conf_all_accept_source_route", + "remarks": "rule_set_140" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces", - "remarks": "rule_set_125" + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces", + "remarks": "rule_set_140" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_rp_filter", - "remarks": "rule_set_126" + "value": "sysctl_net_ipv4_conf_default_accept_source_route", + "remarks": "rule_set_141" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces by Default", - "remarks": "rule_set_126" + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces by Default", + "remarks": "rule_set_141" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_rp_filter", - "remarks": "rule_set_126" + "value": "sysctl_net_ipv4_conf_default_accept_source_route", + "remarks": "rule_set_141" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces by Default", - "remarks": "rule_set_126" + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces by Default", + "remarks": "rule_set_141" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_accept_source_route", - "remarks": "rule_set_127" + "value": "sysctl_net_ipv4_conf_all_log_martians", + "remarks": "rule_set_142" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces", - "remarks": "rule_set_127" + "value": "Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces", + "remarks": "rule_set_142" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_accept_source_route", - "remarks": "rule_set_127" + "value": "sysctl_net_ipv4_conf_all_log_martians", + "remarks": "rule_set_142" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces", - "remarks": "rule_set_127" + "value": "Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces", + "remarks": "rule_set_142" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_accept_source_route", - "remarks": "rule_set_128" + "value": "sysctl_net_ipv4_conf_default_log_martians", + "remarks": "rule_set_143" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces by Default", - "remarks": "rule_set_128" + "value": "Enable Kernel Paremeter to Log Martian Packets on all IPv4 Interfaces by Default", + "remarks": "rule_set_143" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_accept_source_route", - "remarks": "rule_set_128" + "value": "sysctl_net_ipv4_conf_default_log_martians", + "remarks": "rule_set_143" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces by Default", - "remarks": "rule_set_128" + "value": "Enable Kernel Paremeter to Log Martian Packets on all IPv4 Interfaces by Default", + "remarks": "rule_set_143" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_source_route", - "remarks": "rule_set_129" + "value": "sysctl_net_ipv4_tcp_syncookies", + "remarks": "rule_set_144" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces", - "remarks": "rule_set_129" + "value": "Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces", + "remarks": "rule_set_144" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_source_route", - "remarks": "rule_set_129" + "value": "sysctl_net_ipv4_tcp_syncookies", + "remarks": "rule_set_144" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces", - "remarks": "rule_set_129" + "value": "Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces", + "remarks": "rule_set_144" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_source_route", - "remarks": "rule_set_130" + "value": "sysctl_net_ipv6_conf_all_forwarding", + "remarks": "rule_set_145" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces by Default", - "remarks": "rule_set_130" + "value": "Disable Kernel Parameter for IPv6 Forwarding", + "remarks": "rule_set_145" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_source_route", - "remarks": "rule_set_130" + "value": "sysctl_net_ipv6_conf_all_forwarding", + "remarks": "rule_set_145" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces by Default", - "remarks": "rule_set_130" + "value": "Disable Kernel Parameter for IPv6 Forwarding", + "remarks": "rule_set_145" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_log_martians", - "remarks": "rule_set_131" + "value": "sysctl_net_ipv6_conf_default_forwarding", + "remarks": "rule_set_146" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces", - "remarks": "rule_set_131" + "value": "Disable Kernel Parameter for IPv6 Forwarding by default", + "remarks": "rule_set_146" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_log_martians", - "remarks": "rule_set_131" + "value": "sysctl_net_ipv6_conf_default_forwarding", + "remarks": "rule_set_146" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces", - "remarks": "rule_set_131" + "value": "Disable Kernel Parameter for IPv6 Forwarding by default", + "remarks": "rule_set_146" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_log_martians", - "remarks": "rule_set_132" + "value": "sysctl_net_ipv6_conf_all_accept_redirects", + "remarks": "rule_set_147" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Paremeter to Log Martian Packets on all IPv4 Interfaces by Default", - "remarks": "rule_set_132" + "value": "Disable Accepting ICMP Redirects for All IPv6 Interfaces", + "remarks": "rule_set_147" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_log_martians", - "remarks": "rule_set_132" + "value": "sysctl_net_ipv6_conf_all_accept_redirects", + "remarks": "rule_set_147" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Paremeter to Log Martian Packets on all IPv4 Interfaces by Default", - "remarks": "rule_set_132" + "value": "Disable Accepting ICMP Redirects for All IPv6 Interfaces", + "remarks": "rule_set_147" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_tcp_syncookies", - "remarks": "rule_set_133" + "value": "sysctl_net_ipv6_conf_default_accept_redirects", + "remarks": "rule_set_148" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces", - "remarks": "rule_set_133" + "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces", + "remarks": "rule_set_148" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_tcp_syncookies", - "remarks": "rule_set_133" + "value": "sysctl_net_ipv6_conf_default_accept_redirects", + "remarks": "rule_set_148" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces", - "remarks": "rule_set_133" + "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces", + "remarks": "rule_set_148" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_ra", - "remarks": "rule_set_134" + "value": "sysctl_net_ipv6_conf_all_accept_source_route", + "remarks": "rule_set_149" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Accepting Router Advertisements on All IPv6 Interfaces", - "remarks": "rule_set_134" + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces", + "remarks": "rule_set_149" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_ra", - "remarks": "rule_set_134" + "value": "sysctl_net_ipv6_conf_all_accept_source_route", + "remarks": "rule_set_149" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Accepting Router Advertisements on All IPv6 Interfaces", - "remarks": "rule_set_134" + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces", + "remarks": "rule_set_149" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_ra", - "remarks": "rule_set_135" + "value": "sysctl_net_ipv6_conf_default_accept_source_route", + "remarks": "rule_set_150" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Accepting Router Advertisements on all IPv6 Interfaces by Default", - "remarks": "rule_set_135" + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces by Default", + "remarks": "rule_set_150" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_ra", - "remarks": "rule_set_135" + "value": "sysctl_net_ipv6_conf_default_accept_source_route", + "remarks": "rule_set_150" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Accepting Router Advertisements on all IPv6 Interfaces by Default", - "remarks": "rule_set_135" + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces by Default", + "remarks": "rule_set_150" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_nftables_installed", - "remarks": "rule_set_136" + "value": "sysctl_net_ipv6_conf_all_accept_ra", + "remarks": "rule_set_151" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install nftables Package", - "remarks": "rule_set_136" + "value": "Configure Accepting Router Advertisements on All IPv6 Interfaces", + "remarks": "rule_set_151" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_nftables_installed", - "remarks": "rule_set_136" + "value": "sysctl_net_ipv6_conf_all_accept_ra", + "remarks": "rule_set_151" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install nftables Package", - "remarks": "rule_set_136" + "value": "Configure Accepting Router Advertisements on All IPv6 Interfaces", + "remarks": "rule_set_151" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_firewalld_enabled", - "remarks": "rule_set_137" + "value": "sysctl_net_ipv6_conf_default_accept_ra", + "remarks": "rule_set_152" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify firewalld Enabled", - "remarks": "rule_set_137" + "value": "Disable Accepting Router Advertisements on all IPv6 Interfaces by Default", + "remarks": "rule_set_152" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_firewalld_enabled", - "remarks": "rule_set_137" + "value": "sysctl_net_ipv6_conf_default_accept_ra", + "remarks": "rule_set_152" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify firewalld Enabled", - "remarks": "rule_set_137" + "value": "Disable Accepting Router Advertisements on all IPv6 Interfaces by Default", + "remarks": "rule_set_152" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_firewalld_installed", - "remarks": "rule_set_138" + "remarks": "rule_set_153" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Install firewalld Package", - "remarks": "rule_set_138" + "remarks": "rule_set_153" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_firewalld_installed", - "remarks": "rule_set_138" + "remarks": "rule_set_153" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Install firewalld Package", - "remarks": "rule_set_138" + "remarks": "rule_set_153" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_nftables_disabled", - "remarks": "rule_set_139" + "value": "service_firewalld_enabled", + "remarks": "rule_set_154" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify nftables Service is Disabled", - "remarks": "rule_set_139" + "value": "Verify firewalld Enabled", + "remarks": "rule_set_154" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_nftables_disabled", - "remarks": "rule_set_139" + "value": "service_firewalld_enabled", + "remarks": "rule_set_154" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify nftables Service is Disabled", - "remarks": "rule_set_139" + "value": "Verify firewalld Enabled", + "remarks": "rule_set_154" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "firewalld_loopback_traffic_trusted", - "remarks": "rule_set_140" + "remarks": "rule_set_155" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure Firewalld to Trust Loopback Traffic", - "remarks": "rule_set_140" + "remarks": "rule_set_155" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "firewalld_loopback_traffic_trusted", - "remarks": "rule_set_140" + "remarks": "rule_set_155" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure Firewalld to Trust Loopback Traffic", - "remarks": "rule_set_140" + "remarks": "rule_set_155" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "firewalld_loopback_traffic_restricted", - "remarks": "rule_set_141" + "remarks": "rule_set_156" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure Firewalld to Restrict Loopback Traffic", - "remarks": "rule_set_141" + "remarks": "rule_set_156" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "firewalld_loopback_traffic_restricted", - "remarks": "rule_set_141" + "remarks": "rule_set_156" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure Firewalld to Restrict Loopback Traffic", - "remarks": "rule_set_141" + "remarks": "rule_set_156" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_sshd_config", - "remarks": "rule_set_142" + "remarks": "rule_set_157" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns SSH Server config file", - "remarks": "rule_set_142" + "remarks": "rule_set_157" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_sshd_config", - "remarks": "rule_set_142" + "remarks": "rule_set_157" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns SSH Server config file", - "remarks": "rule_set_142" + "remarks": "rule_set_157" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_sshd_config", - "remarks": "rule_set_143" + "remarks": "rule_set_158" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on SSH Server config file", - "remarks": "rule_set_143" + "remarks": "rule_set_158" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_sshd_config", - "remarks": "rule_set_143" + "remarks": "rule_set_158" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on SSH Server config file", - "remarks": "rule_set_143" + "remarks": "rule_set_158" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_sshd_config", - "remarks": "rule_set_144" + "remarks": "rule_set_159" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on SSH Server config file", - "remarks": "rule_set_144" + "remarks": "rule_set_159" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_sshd_config", - "remarks": "rule_set_144" + "remarks": "rule_set_159" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on SSH Server config file", - "remarks": "rule_set_144" + "remarks": "rule_set_159" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_private_key", - "remarks": "rule_set_145" + "value": "file_groupownership_sshd_private_key", + "remarks": "rule_set_160" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on SSH Server Private *_key Key Files", - "remarks": "rule_set_145" + "value": "Verify Group Ownership on SSH Server Private *_key Key Files", + "remarks": "rule_set_160" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_private_key", - "remarks": "rule_set_145" + "value": "file_groupownership_sshd_private_key", + "remarks": "rule_set_160" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on SSH Server Private *_key Key Files", - "remarks": "rule_set_145" + "value": "Verify Group Ownership on SSH Server Private *_key Key Files", + "remarks": "rule_set_160" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_ownership_sshd_private_key", - "remarks": "rule_set_146" + "remarks": "rule_set_161" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Ownership on SSH Server Private *_key Key Files", - "remarks": "rule_set_146" + "remarks": "rule_set_161" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_ownership_sshd_private_key", - "remarks": "rule_set_146" + "remarks": "rule_set_161" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Ownership on SSH Server Private *_key Key Files", - "remarks": "rule_set_146" + "remarks": "rule_set_161" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_sshd_private_key", - "remarks": "rule_set_147" + "value": "file_permissions_sshd_private_key", + "remarks": "rule_set_162" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Ownership on SSH Server Private *_key Key Files", - "remarks": "rule_set_147" + "value": "Verify Permissions on SSH Server Private *_key Key Files", + "remarks": "rule_set_162" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_sshd_private_key", - "remarks": "rule_set_147" + "value": "file_permissions_sshd_private_key", + "remarks": "rule_set_162" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Ownership on SSH Server Private *_key Key Files", - "remarks": "rule_set_147" + "value": "Verify Permissions on SSH Server Private *_key Key Files", + "remarks": "rule_set_162" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_pub_key", - "remarks": "rule_set_148" + "value": "file_groupownership_sshd_pub_key", + "remarks": "rule_set_163" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on SSH Server Public *.pub Key Files", - "remarks": "rule_set_148" + "value": "Verify Group Ownership on SSH Server Public *.pub Key Files", + "remarks": "rule_set_163" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_pub_key", - "remarks": "rule_set_148" + "value": "file_groupownership_sshd_pub_key", + "remarks": "rule_set_163" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on SSH Server Public *.pub Key Files", - "remarks": "rule_set_148" + "value": "Verify Group Ownership on SSH Server Public *.pub Key Files", + "remarks": "rule_set_163" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_ownership_sshd_pub_key", - "remarks": "rule_set_149" + "remarks": "rule_set_164" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Ownership on SSH Server Public *.pub Key Files", - "remarks": "rule_set_149" + "remarks": "rule_set_164" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_ownership_sshd_pub_key", - "remarks": "rule_set_149" + "remarks": "rule_set_164" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Ownership on SSH Server Public *.pub Key Files", - "remarks": "rule_set_149" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_sshd_pub_key", - "remarks": "rule_set_150" - }, - { - "name": "Rule_Description", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Ownership on SSH Server Public *.pub Key Files", - "remarks": "rule_set_150" - }, - { - "name": "Check_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_sshd_pub_key", - "remarks": "rule_set_150" - }, - { - "name": "Check_Description", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Ownership on SSH Server Public *.pub Key Files", - "remarks": "rule_set_150" + "remarks": "rule_set_164" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_kex", - "remarks": "rule_set_151" + "value": "file_permissions_sshd_pub_key", + "remarks": "rule_set_165" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Use Only Strong Key Exchange algorithms", - "remarks": "rule_set_151" + "value": "Verify Permissions on SSH Server Public *.pub Key Files", + "remarks": "rule_set_165" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_kex", - "remarks": "rule_set_151" + "value": "file_permissions_sshd_pub_key", + "remarks": "rule_set_165" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Use Only Strong Key Exchange algorithms", - "remarks": "rule_set_151" + "value": "Verify Permissions on SSH Server Public *.pub Key Files", + "remarks": "rule_set_165" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_macs", - "remarks": "rule_set_152" + "value": "sshd_limit_user_access", + "remarks": "rule_set_166" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Use Only Strong MACs", - "remarks": "rule_set_152" + "value": "Limit Users' SSH Access", + "remarks": "rule_set_166" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_macs", - "remarks": "rule_set_152" + "value": "sshd_limit_user_access", + "remarks": "rule_set_166" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Use Only Strong MACs", - "remarks": "rule_set_152" + "value": "Limit Users' SSH Access", + "remarks": "rule_set_166" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_limit_user_access", - "remarks": "rule_set_153" + "value": "sshd_enable_warning_banner_net", + "remarks": "rule_set_167" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Limit Users' SSH Access", - "remarks": "rule_set_153" + "value": "Enable SSH Warning Banner", + "remarks": "rule_set_167" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_limit_user_access", - "remarks": "rule_set_153" + "value": "sshd_enable_warning_banner_net", + "remarks": "rule_set_167" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Limit Users' SSH Access", - "remarks": "rule_set_153" + "value": "Enable SSH Warning Banner", + "remarks": "rule_set_167" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_enable_warning_banner_net", - "remarks": "rule_set_154" + "value": "sshd_set_idle_timeout", + "remarks": "rule_set_168" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable SSH Warning Banner", - "remarks": "rule_set_154" + "value": "Set SSH Client Alive Interval", + "remarks": "rule_set_168" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_enable_warning_banner_net", - "remarks": "rule_set_154" + "value": "sshd_set_idle_timeout", + "remarks": "rule_set_168" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable SSH Warning Banner", - "remarks": "rule_set_154" + "value": "Set SSH Client Alive Interval", + "remarks": "rule_set_168" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_idle_timeout", - "remarks": "rule_set_155" + "value": "sshd_set_keepalive", + "remarks": "rule_set_169" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set SSH Client Alive Interval", - "remarks": "rule_set_155" + "value": "Set SSH Client Alive Count Max", + "remarks": "rule_set_169" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_idle_timeout", - "remarks": "rule_set_155" + "value": "sshd_set_keepalive", + "remarks": "rule_set_169" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set SSH Client Alive Interval", - "remarks": "rule_set_155" + "value": "Set SSH Client Alive Count Max", + "remarks": "rule_set_169" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_keepalive", - "remarks": "rule_set_156" + "value": "sshd_disable_forwarding", + "remarks": "rule_set_170" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set SSH Client Alive Count Max", - "remarks": "rule_set_156" + "value": "Disable SSH Forwarding", + "remarks": "rule_set_170" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_keepalive", - "remarks": "rule_set_156" + "value": "sshd_disable_forwarding", + "remarks": "rule_set_170" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set SSH Client Alive Count Max", - "remarks": "rule_set_156" + "value": "Disable SSH Forwarding", + "remarks": "rule_set_170" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_disable_gssapi_auth", - "remarks": "rule_set_157" + "remarks": "rule_set_171" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable GSSAPI Authentication", - "remarks": "rule_set_157" + "remarks": "rule_set_171" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_disable_gssapi_auth", - "remarks": "rule_set_157" + "remarks": "rule_set_171" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable GSSAPI Authentication", - "remarks": "rule_set_157" + "remarks": "rule_set_171" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "disable_host_auth", - "remarks": "rule_set_158" + "remarks": "rule_set_172" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Host-Based Authentication", - "remarks": "rule_set_158" + "remarks": "rule_set_172" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "disable_host_auth", - "remarks": "rule_set_158" + "remarks": "rule_set_172" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Host-Based Authentication", - "remarks": "rule_set_158" + "remarks": "rule_set_172" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_disable_rhosts", - "remarks": "rule_set_159" + "remarks": "rule_set_173" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable SSH Support for .rhosts Files", - "remarks": "rule_set_159" + "remarks": "rule_set_173" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_disable_rhosts", - "remarks": "rule_set_159" + "remarks": "rule_set_173" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable SSH Support for .rhosts Files", - "remarks": "rule_set_159" + "remarks": "rule_set_173" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_use_strong_kex", + "remarks": "rule_set_174" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Use Only Strong Key Exchange algorithms", + "remarks": "rule_set_174" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_use_strong_kex", + "remarks": "rule_set_174" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Use Only Strong Key Exchange algorithms", + "remarks": "rule_set_174" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_login_grace_time", - "remarks": "rule_set_160" + "remarks": "rule_set_175" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure SSH LoginGraceTime is configured", - "remarks": "rule_set_160" + "remarks": "rule_set_175" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_login_grace_time", - "remarks": "rule_set_160" + "remarks": "rule_set_175" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure SSH LoginGraceTime is configured", - "remarks": "rule_set_160" + "remarks": "rule_set_175" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_loglevel_verbose", - "remarks": "rule_set_161" + "remarks": "rule_set_176" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set SSH Daemon LogLevel to VERBOSE", - "remarks": "rule_set_161" + "remarks": "rule_set_176" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_loglevel_verbose", - "remarks": "rule_set_161" + "remarks": "rule_set_176" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set SSH Daemon LogLevel to VERBOSE", - "remarks": "rule_set_161" + "remarks": "rule_set_176" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_use_strong_macs", + "remarks": "rule_set_177" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Use Only Strong MACs", + "remarks": "rule_set_177" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_use_strong_macs", + "remarks": "rule_set_177" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Use Only Strong MACs", + "remarks": "rule_set_177" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_max_auth_tries", - "remarks": "rule_set_162" + "remarks": "rule_set_178" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set SSH authentication attempt limit", - "remarks": "rule_set_162" + "remarks": "rule_set_178" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_max_auth_tries", - "remarks": "rule_set_162" + "remarks": "rule_set_178" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set SSH authentication attempt limit", - "remarks": "rule_set_162" + "remarks": "rule_set_178" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_maxstartups", - "remarks": "rule_set_163" + "remarks": "rule_set_179" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure SSH MaxStartups is configured", - "remarks": "rule_set_163" + "remarks": "rule_set_179" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_maxstartups", - "remarks": "rule_set_163" + "remarks": "rule_set_179" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure SSH MaxStartups is configured", - "remarks": "rule_set_163" + "remarks": "rule_set_179" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_max_sessions", - "remarks": "rule_set_164" + "remarks": "rule_set_180" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set SSH MaxSessions limit", - "remarks": "rule_set_164" + "remarks": "rule_set_180" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_max_sessions", - "remarks": "rule_set_164" + "remarks": "rule_set_180" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set SSH MaxSessions limit", - "remarks": "rule_set_164" + "remarks": "rule_set_180" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_disable_empty_passwords", - "remarks": "rule_set_165" + "remarks": "rule_set_181" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable SSH Access via Empty Passwords", - "remarks": "rule_set_165" + "remarks": "rule_set_181" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_disable_empty_passwords", - "remarks": "rule_set_165" + "remarks": "rule_set_181" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable SSH Access via Empty Passwords", - "remarks": "rule_set_165" + "remarks": "rule_set_181" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_disable_root_login", - "remarks": "rule_set_166" + "remarks": "rule_set_182" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable SSH Root Login", - "remarks": "rule_set_166" + "remarks": "rule_set_182" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_disable_root_login", - "remarks": "rule_set_166" + "remarks": "rule_set_182" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable SSH Root Login", - "remarks": "rule_set_166" + "remarks": "rule_set_182" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_do_not_permit_user_env", - "remarks": "rule_set_167" + "remarks": "rule_set_183" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Do Not Allow SSH Environment Options", - "remarks": "rule_set_167" + "remarks": "rule_set_183" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_do_not_permit_user_env", - "remarks": "rule_set_167" + "remarks": "rule_set_183" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Do Not Allow SSH Environment Options", - "remarks": "rule_set_167" + "remarks": "rule_set_183" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_enable_pam", - "remarks": "rule_set_168" + "remarks": "rule_set_184" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable PAM", - "remarks": "rule_set_168" + "remarks": "rule_set_184" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_enable_pam", - "remarks": "rule_set_168" + "remarks": "rule_set_184" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable PAM", - "remarks": "rule_set_168" + "remarks": "rule_set_184" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_sudo_installed", - "remarks": "rule_set_169" + "remarks": "rule_set_185" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Install sudo Package", - "remarks": "rule_set_169" + "remarks": "rule_set_185" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_sudo_installed", - "remarks": "rule_set_169" + "remarks": "rule_set_185" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Install sudo Package", - "remarks": "rule_set_169" + "remarks": "rule_set_185" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sudo_add_use_pty", - "remarks": "rule_set_170" + "remarks": "rule_set_186" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Only Users Logged In To Real tty Can Execute Sudo - sudo use_pty", - "remarks": "rule_set_170" + "remarks": "rule_set_186" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sudo_add_use_pty", - "remarks": "rule_set_170" + "remarks": "rule_set_186" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Only Users Logged In To Real tty Can Execute Sudo - sudo use_pty", - "remarks": "rule_set_170" + "remarks": "rule_set_186" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sudo_custom_logfile", - "remarks": "rule_set_171" + "remarks": "rule_set_187" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Sudo Logfile Exists - sudo logfile", - "remarks": "rule_set_171" + "remarks": "rule_set_187" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sudo_custom_logfile", - "remarks": "rule_set_171" + "remarks": "rule_set_187" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Sudo Logfile Exists - sudo logfile", - "remarks": "rule_set_171" + "remarks": "rule_set_187" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sudo_require_authentication", + "remarks": "rule_set_188" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure Users Re-Authenticate for Privilege Escalation - sudo", + "remarks": "rule_set_188" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sudo_require_authentication", + "remarks": "rule_set_188" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure Users Re-Authenticate for Privilege Escalation - sudo", + "remarks": "rule_set_188" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sudo_require_reauthentication", - "remarks": "rule_set_172" + "remarks": "rule_set_189" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Require Re-Authentication When Using the sudo Command", - "remarks": "rule_set_172" + "remarks": "rule_set_189" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sudo_require_reauthentication", - "remarks": "rule_set_172" + "remarks": "rule_set_189" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Require Re-Authentication When Using the sudo Command", - "remarks": "rule_set_172" + "remarks": "rule_set_189" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "use_pam_wheel_group_for_su", - "remarks": "rule_set_173" + "remarks": "rule_set_190" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enforce Usage of pam_wheel with Group Parameter for su Authentication", - "remarks": "rule_set_173" + "remarks": "rule_set_190" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "use_pam_wheel_group_for_su", - "remarks": "rule_set_173" + "remarks": "rule_set_190" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enforce Usage of pam_wheel with Group Parameter for su Authentication", - "remarks": "rule_set_173" + "remarks": "rule_set_190" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "ensure_pam_wheel_group_empty", - "remarks": "rule_set_174" + "remarks": "rule_set_191" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure the Group Used by pam_wheel.so Module Exists on System and is Empty", - "remarks": "rule_set_174" + "remarks": "rule_set_191" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "ensure_pam_wheel_group_empty", - "remarks": "rule_set_174" + "remarks": "rule_set_191" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure the Group Used by pam_wheel.so Module Exists on System and is Empty", - "remarks": "rule_set_174" + "remarks": "rule_set_191" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_pam_pwquality_installed", - "remarks": "rule_set_175" + "value": "account_password_pam_faillock_password_auth", + "remarks": "rule_set_192" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install pam_pwquality Package", - "remarks": "rule_set_175" + "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth File.", + "remarks": "rule_set_192" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_pam_pwquality_installed", - "remarks": "rule_set_175" + "value": "account_password_pam_faillock_password_auth", + "remarks": "rule_set_192" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install pam_pwquality Package", - "remarks": "rule_set_175" + "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth File.", + "remarks": "rule_set_192" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_password_auth", - "remarks": "rule_set_176" + "value": "account_password_pam_faillock_system_auth", + "remarks": "rule_set_193" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth File.", - "remarks": "rule_set_176" + "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth File.", + "remarks": "rule_set_193" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_password_auth", - "remarks": "rule_set_176" + "value": "account_password_pam_faillock_system_auth", + "remarks": "rule_set_193" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth File.", - "remarks": "rule_set_176" + "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth File.", + "remarks": "rule_set_193" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_system_auth", - "remarks": "rule_set_177" + "value": "package_pam_pwquality_installed", + "remarks": "rule_set_194" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth File.", - "remarks": "rule_set_177" + "value": "Install pam_pwquality Package", + "remarks": "rule_set_194" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_system_auth", - "remarks": "rule_set_177" + "value": "package_pam_pwquality_installed", + "remarks": "rule_set_194" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth File.", - "remarks": "rule_set_177" + "value": "Install pam_pwquality Package", + "remarks": "rule_set_194" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_passwords_pam_faillock_deny", - "remarks": "rule_set_178" + "remarks": "rule_set_195" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Lock Accounts After Failed Password Attempts", - "remarks": "rule_set_178" + "remarks": "rule_set_195" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_passwords_pam_faillock_deny", - "remarks": "rule_set_178" + "remarks": "rule_set_195" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Lock Accounts After Failed Password Attempts", - "remarks": "rule_set_178" + "remarks": "rule_set_195" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_passwords_pam_faillock_unlock_time", - "remarks": "rule_set_179" + "remarks": "rule_set_196" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Lockout Time for Failed Password Attempts", - "remarks": "rule_set_179" + "remarks": "rule_set_196" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_passwords_pam_faillock_unlock_time", - "remarks": "rule_set_179" + "remarks": "rule_set_196" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Lockout Time for Failed Password Attempts", - "remarks": "rule_set_179" + "remarks": "rule_set_196" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_difok", - "remarks": "rule_set_180" + "remarks": "rule_set_197" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure PAM Enforces Password Requirements - Minimum Different Characters", - "remarks": "rule_set_180" + "remarks": "rule_set_197" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_difok", - "remarks": "rule_set_180" + "remarks": "rule_set_197" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure PAM Enforces Password Requirements - Minimum Different Characters", - "remarks": "rule_set_180" + "remarks": "rule_set_197" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_minlen", - "remarks": "rule_set_181" + "remarks": "rule_set_198" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure PAM Enforces Password Requirements - Minimum Length", - "remarks": "rule_set_181" + "remarks": "rule_set_198" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_minlen", - "remarks": "rule_set_181" + "remarks": "rule_set_198" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure PAM Enforces Password Requirements - Minimum Length", - "remarks": "rule_set_181" + "remarks": "rule_set_198" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_minclass", - "remarks": "rule_set_182" + "remarks": "rule_set_199" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure PAM Enforces Password Requirements - Minimum Different Categories", - "remarks": "rule_set_182" + "remarks": "rule_set_199" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_minclass", - "remarks": "rule_set_182" + "remarks": "rule_set_199" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure PAM Enforces Password Requirements - Minimum Different Categories", - "remarks": "rule_set_182" + "remarks": "rule_set_199" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_maxrepeat", - "remarks": "rule_set_183" + "remarks": "rule_set_200" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Password Maximum Consecutive Repeating Characters", - "remarks": "rule_set_183" + "remarks": "rule_set_200" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_maxrepeat", - "remarks": "rule_set_183" + "remarks": "rule_set_200" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Password Maximum Consecutive Repeating Characters", - "remarks": "rule_set_183" + "remarks": "rule_set_200" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_dictcheck", - "remarks": "rule_set_184" + "remarks": "rule_set_201" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure PAM Enforces Password Requirements - Prevent the Use of Dictionary Words", - "remarks": "rule_set_184" + "remarks": "rule_set_201" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_dictcheck", - "remarks": "rule_set_184" + "remarks": "rule_set_201" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure PAM Enforces Password Requirements - Prevent the Use of Dictionary Words", - "remarks": "rule_set_184" + "remarks": "rule_set_201" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_enforce_root", - "remarks": "rule_set_185" + "remarks": "rule_set_202" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure PAM Enforces Password Requirements - Enforce for root User", - "remarks": "rule_set_185" + "remarks": "rule_set_202" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_enforce_root", - "remarks": "rule_set_185" + "remarks": "rule_set_202" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure PAM Enforces Password Requirements - Enforce for root User", - "remarks": "rule_set_185" + "remarks": "rule_set_202" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_pwhistory_remember_password_auth", - "remarks": "rule_set_186" + "remarks": "rule_set_203" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Limit Password Reuse: password-auth", - "remarks": "rule_set_186" + "remarks": "rule_set_203" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_pwhistory_remember_password_auth", - "remarks": "rule_set_186" + "remarks": "rule_set_203" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Limit Password Reuse: password-auth", - "remarks": "rule_set_186" + "remarks": "rule_set_203" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_pwhistory_remember_system_auth", - "remarks": "rule_set_187" + "remarks": "rule_set_204" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Limit Password Reuse: system-auth", - "remarks": "rule_set_187" + "remarks": "rule_set_204" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_pwhistory_remember_system_auth", - "remarks": "rule_set_187" + "remarks": "rule_set_204" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Limit Password Reuse: system-auth", - "remarks": "rule_set_187" + "remarks": "rule_set_204" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_empty_passwords", - "remarks": "rule_set_188" + "remarks": "rule_set_205" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Prevent Login to Accounts With Empty Password", - "remarks": "rule_set_188" + "remarks": "rule_set_205" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_empty_passwords", - "remarks": "rule_set_188" + "remarks": "rule_set_205" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Prevent Login to Accounts With Empty Password", - "remarks": "rule_set_188" + "remarks": "rule_set_205" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "set_password_hashing_algorithm_systemauth", - "remarks": "rule_set_189" + "remarks": "rule_set_206" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set PAM''s Password Hashing Algorithm", - "remarks": "rule_set_189" + "remarks": "rule_set_206" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "set_password_hashing_algorithm_systemauth", - "remarks": "rule_set_189" + "remarks": "rule_set_206" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set PAM''s Password Hashing Algorithm", - "remarks": "rule_set_189" + "remarks": "rule_set_206" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "set_password_hashing_algorithm_passwordauth", - "remarks": "rule_set_190" + "remarks": "rule_set_207" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set PAM''s Password Hashing Algorithm - password-auth", - "remarks": "rule_set_190" + "remarks": "rule_set_207" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "set_password_hashing_algorithm_passwordauth", - "remarks": "rule_set_190" + "remarks": "rule_set_207" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set PAM''s Password Hashing Algorithm - password-auth", - "remarks": "rule_set_190" + "remarks": "rule_set_207" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_maximum_age_login_defs", - "remarks": "rule_set_191" + "remarks": "rule_set_208" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Password Maximum Age", - "remarks": "rule_set_191" + "remarks": "rule_set_208" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_maximum_age_login_defs", - "remarks": "rule_set_191" + "remarks": "rule_set_208" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Password Maximum Age", - "remarks": "rule_set_191" + "remarks": "rule_set_208" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_set_max_life_existing", - "remarks": "rule_set_192" + "remarks": "rule_set_209" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Existing Passwords Maximum Age", - "remarks": "rule_set_192" + "remarks": "rule_set_209" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_set_max_life_existing", - "remarks": "rule_set_192" + "remarks": "rule_set_209" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Existing Passwords Maximum Age", - "remarks": "rule_set_192" + "remarks": "rule_set_209" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_warn_age_login_defs", - "remarks": "rule_set_193" + "remarks": "rule_set_210" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Password Warning Age", - "remarks": "rule_set_193" + "remarks": "rule_set_210" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_warn_age_login_defs", - "remarks": "rule_set_193" + "remarks": "rule_set_210" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Password Warning Age", - "remarks": "rule_set_193" + "remarks": "rule_set_210" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_set_warn_age_existing", - "remarks": "rule_set_194" + "remarks": "rule_set_211" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Existing Passwords Warning Age", - "remarks": "rule_set_194" + "remarks": "rule_set_211" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_set_warn_age_existing", - "remarks": "rule_set_194" + "remarks": "rule_set_211" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Existing Passwords Warning Age", - "remarks": "rule_set_194" + "remarks": "rule_set_211" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "set_password_hashing_algorithm_libuserconf", - "remarks": "rule_set_195" + "remarks": "rule_set_212" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Password Hashing Algorithm in /etc/libuser.conf", - "remarks": "rule_set_195" + "remarks": "rule_set_212" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "set_password_hashing_algorithm_libuserconf", - "remarks": "rule_set_195" + "remarks": "rule_set_212" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Password Hashing Algorithm in /etc/libuser.conf", - "remarks": "rule_set_195" + "remarks": "rule_set_212" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "set_password_hashing_algorithm_logindefs", - "remarks": "rule_set_196" + "remarks": "rule_set_213" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Password Hashing Algorithm in /etc/login.defs", - "remarks": "rule_set_196" + "remarks": "rule_set_213" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "set_password_hashing_algorithm_logindefs", - "remarks": "rule_set_196" + "remarks": "rule_set_213" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Password Hashing Algorithm in /etc/login.defs", - "remarks": "rule_set_196" + "remarks": "rule_set_213" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "account_disable_post_pw_expiration", - "remarks": "rule_set_197" + "remarks": "rule_set_214" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Account Expiration Following Inactivity", - "remarks": "rule_set_197" + "remarks": "rule_set_214" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "account_disable_post_pw_expiration", - "remarks": "rule_set_197" + "remarks": "rule_set_214" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Account Expiration Following Inactivity", - "remarks": "rule_set_197" + "remarks": "rule_set_214" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_set_post_pw_existing", - "remarks": "rule_set_198" + "remarks": "rule_set_215" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set existing passwords a period of inactivity before they been locked", - "remarks": "rule_set_198" + "remarks": "rule_set_215" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_set_post_pw_existing", - "remarks": "rule_set_198" + "remarks": "rule_set_215" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set existing passwords a period of inactivity before they been locked", - "remarks": "rule_set_198" + "remarks": "rule_set_215" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_last_change_is_in_past", - "remarks": "rule_set_199" + "remarks": "rule_set_216" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure all users last password change date is in the past", - "remarks": "rule_set_199" + "remarks": "rule_set_216" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_last_change_is_in_past", - "remarks": "rule_set_199" + "remarks": "rule_set_216" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure all users last password change date is in the past", - "remarks": "rule_set_199" + "remarks": "rule_set_216" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_no_uid_except_zero", - "remarks": "rule_set_200" + "remarks": "rule_set_217" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Only Root Has UID 0", - "remarks": "rule_set_200" + "remarks": "rule_set_217" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_no_uid_except_zero", - "remarks": "rule_set_200" + "remarks": "rule_set_217" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Only Root Has UID 0", - "remarks": "rule_set_200" + "remarks": "rule_set_217" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_root_gid_zero", - "remarks": "rule_set_201" + "remarks": "rule_set_218" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Root Has A Primary GID 0", - "remarks": "rule_set_201" + "remarks": "rule_set_218" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_root_gid_zero", - "remarks": "rule_set_201" + "remarks": "rule_set_218" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Root Has A Primary GID 0", - "remarks": "rule_set_201" + "remarks": "rule_set_218" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "groups_no_zero_gid_except_root", + "remarks": "rule_set_219" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify Only Group Root Has GID 0", + "remarks": "rule_set_219" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "groups_no_zero_gid_except_root", + "remarks": "rule_set_219" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify Only Group Root Has GID 0", + "remarks": "rule_set_219" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "ensure_root_password_configured", - "remarks": "rule_set_202" + "remarks": "rule_set_220" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Authentication Required for Single User Mode", - "remarks": "rule_set_202" + "remarks": "rule_set_220" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "ensure_root_password_configured", - "remarks": "rule_set_202" + "remarks": "rule_set_220" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure Authentication Required for Single User Mode", + "remarks": "rule_set_220" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_root_path_dirs_no_write", + "remarks": "rule_set_221" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure that Root's Path Does Not Include World or Group-Writable Directories", + "remarks": "rule_set_221" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_root_path_dirs_no_write", + "remarks": "rule_set_221" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Authentication Required for Single User Mode", - "remarks": "rule_set_202" + "value": "Ensure that Root's Path Does Not Include World or Group-Writable Directories", + "remarks": "rule_set_221" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_root_path_dirs_no_write", - "remarks": "rule_set_203" + "value": "root_path_no_dot", + "remarks": "rule_set_222" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that Root's Path Does Not Include World or Group-Writable Directories", - "remarks": "rule_set_203" + "value": "Ensure that Root's Path Does Not Include Relative Paths or Null Directories", + "remarks": "rule_set_222" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_root_path_dirs_no_write", - "remarks": "rule_set_203" + "value": "root_path_no_dot", + "remarks": "rule_set_222" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that Root's Path Does Not Include World or Group-Writable Directories", - "remarks": "rule_set_203" + "value": "Ensure that Root's Path Does Not Include Relative Paths or Null Directories", + "remarks": "rule_set_222" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "root_path_no_dot", - "remarks": "rule_set_204" + "value": "accounts_umask_root", + "remarks": "rule_set_223" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that Root's Path Does Not Include Relative Paths or Null Directories", - "remarks": "rule_set_204" + "value": "Ensure the Root Bash Umask is Set Correctly", + "remarks": "rule_set_223" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "root_path_no_dot", - "remarks": "rule_set_204" + "value": "accounts_umask_root", + "remarks": "rule_set_223" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that Root's Path Does Not Include Relative Paths or Null Directories", - "remarks": "rule_set_204" + "value": "Ensure the Root Bash Umask is Set Correctly", + "remarks": "rule_set_223" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_password_auth_for_systemaccounts", - "remarks": "rule_set_205" + "remarks": "rule_set_224" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that System Accounts Are Locked", - "remarks": "rule_set_205" + "remarks": "rule_set_224" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_password_auth_for_systemaccounts", - "remarks": "rule_set_205" + "remarks": "rule_set_224" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that System Accounts Are Locked", - "remarks": "rule_set_205" + "remarks": "rule_set_224" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_shelllogin_for_systemaccounts", - "remarks": "rule_set_206" + "remarks": "rule_set_225" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that System Accounts Do Not Run a Shell Upon Login", - "remarks": "rule_set_206" + "remarks": "rule_set_225" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_shelllogin_for_systemaccounts", - "remarks": "rule_set_206" + "remarks": "rule_set_225" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that System Accounts Do Not Run a Shell Upon Login", - "remarks": "rule_set_206" + "remarks": "rule_set_225" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_tmout", - "remarks": "rule_set_207" + "remarks": "rule_set_226" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Interactive Session Timeout", - "remarks": "rule_set_207" + "remarks": "rule_set_226" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_tmout", - "remarks": "rule_set_207" + "remarks": "rule_set_226" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Interactive Session Timeout", - "remarks": "rule_set_207" + "remarks": "rule_set_226" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_umask_etc_bashrc", - "remarks": "rule_set_208" + "remarks": "rule_set_227" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure the Default Bash Umask is Set Correctly", - "remarks": "rule_set_208" + "remarks": "rule_set_227" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_umask_etc_bashrc", - "remarks": "rule_set_208" + "remarks": "rule_set_227" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure the Default Bash Umask is Set Correctly", - "remarks": "rule_set_208" + "remarks": "rule_set_227" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_umask_etc_login_defs", - "remarks": "rule_set_209" + "remarks": "rule_set_228" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure the Default Umask is Set Correctly in login.defs", - "remarks": "rule_set_209" + "remarks": "rule_set_228" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_umask_etc_login_defs", - "remarks": "rule_set_209" + "remarks": "rule_set_228" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure the Default Umask is Set Correctly in login.defs", - "remarks": "rule_set_209" + "remarks": "rule_set_228" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_umask_etc_profile", - "remarks": "rule_set_210" + "remarks": "rule_set_229" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure the Default Umask is Set Correctly in /etc/profile", - "remarks": "rule_set_210" + "remarks": "rule_set_229" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_umask_etc_profile", - "remarks": "rule_set_210" + "remarks": "rule_set_229" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure the Default Umask is Set Correctly in /etc/profile", - "remarks": "rule_set_210" + "remarks": "rule_set_229" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_aide_installed", - "remarks": "rule_set_211" + "remarks": "rule_set_230" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Install AIDE", - "remarks": "rule_set_211" + "remarks": "rule_set_230" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_aide_installed", - "remarks": "rule_set_211" + "remarks": "rule_set_230" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Install AIDE", - "remarks": "rule_set_211" + "remarks": "rule_set_230" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "aide_build_database", - "remarks": "rule_set_212" + "remarks": "rule_set_231" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Build and Test AIDE Database", - "remarks": "rule_set_212" + "remarks": "rule_set_231" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "aide_build_database", - "remarks": "rule_set_212" + "remarks": "rule_set_231" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Build and Test AIDE Database", - "remarks": "rule_set_212" + "remarks": "rule_set_231" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "aide_periodic_cron_checking", - "remarks": "rule_set_213" + "remarks": "rule_set_232" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure Periodic Execution of AIDE", - "remarks": "rule_set_213" + "remarks": "rule_set_232" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "aide_periodic_cron_checking", - "remarks": "rule_set_213" + "remarks": "rule_set_232" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure Periodic Execution of AIDE", - "remarks": "rule_set_213" + "remarks": "rule_set_232" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "aide_check_audit_tools", - "remarks": "rule_set_214" + "remarks": "rule_set_233" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure AIDE to Verify the Audit Tools", - "remarks": "rule_set_214" + "remarks": "rule_set_233" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "aide_check_audit_tools", - "remarks": "rule_set_214" + "remarks": "rule_set_233" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure AIDE to Verify the Audit Tools", - "remarks": "rule_set_214" + "remarks": "rule_set_233" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_systemd-journald_enabled", - "remarks": "rule_set_215" + "remarks": "rule_set_234" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable systemd-journald Service", - "remarks": "rule_set_215" + "remarks": "rule_set_234" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_systemd-journald_enabled", - "remarks": "rule_set_215" + "remarks": "rule_set_234" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable systemd-journald Service", - "remarks": "rule_set_215" + "remarks": "rule_set_234" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_systemd-journal-remote_installed", - "remarks": "rule_set_216" + "value": "journald_compress", + "remarks": "rule_set_235" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install systemd-journal-remote Package", - "remarks": "rule_set_216" + "value": "Ensure journald is configured to compress large log files", + "remarks": "rule_set_235" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_systemd-journal-remote_installed", - "remarks": "rule_set_216" + "value": "journald_compress", + "remarks": "rule_set_235" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install systemd-journal-remote Package", - "remarks": "rule_set_216" + "value": "Ensure journald is configured to compress large log files", + "remarks": "rule_set_235" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "socket_systemd-journal-remote_disabled", - "remarks": "rule_set_217" + "value": "journald_storage", + "remarks": "rule_set_236" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable systemd-journal-remote Socket", - "remarks": "rule_set_217" + "value": "Ensure journald is configured to write log files to persistent disk", + "remarks": "rule_set_236" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "socket_systemd-journal-remote_disabled", - "remarks": "rule_set_217" + "value": "journald_storage", + "remarks": "rule_set_236" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable systemd-journal-remote Socket", - "remarks": "rule_set_217" + "value": "Ensure journald is configured to write log files to persistent disk", + "remarks": "rule_set_236" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_compress", - "remarks": "rule_set_218" + "value": "package_systemd-journal-remote_installed", + "remarks": "rule_set_237" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure journald is configured to compress large log files", - "remarks": "rule_set_218" + "value": "Install systemd-journal-remote Package", + "remarks": "rule_set_237" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_compress", - "remarks": "rule_set_218" + "value": "package_systemd-journal-remote_installed", + "remarks": "rule_set_237" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure journald is configured to compress large log files", - "remarks": "rule_set_218" + "value": "Install systemd-journal-remote Package", + "remarks": "rule_set_237" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_storage", - "remarks": "rule_set_219" + "value": "socket_systemd-journal-remote_disabled", + "remarks": "rule_set_238" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure journald is configured to write log files to persistent disk", - "remarks": "rule_set_219" + "value": "Disable systemd-journal-remote Socket", + "remarks": "rule_set_238" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_storage", - "remarks": "rule_set_219" + "value": "socket_systemd-journal-remote_disabled", + "remarks": "rule_set_238" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure journald is configured to write log files to persistent disk", - "remarks": "rule_set_219" + "value": "Disable systemd-journal-remote Socket", + "remarks": "rule_set_238" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "rsyslog_files_groupownership", - "remarks": "rule_set_220" + "remarks": "rule_set_239" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Log Files Are Owned By Appropriate Group", - "remarks": "rule_set_220" + "remarks": "rule_set_239" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "rsyslog_files_groupownership", - "remarks": "rule_set_220" + "remarks": "rule_set_239" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Log Files Are Owned By Appropriate Group", - "remarks": "rule_set_220" + "remarks": "rule_set_239" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "rsyslog_files_ownership", - "remarks": "rule_set_221" + "remarks": "rule_set_240" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Log Files Are Owned By Appropriate User", - "remarks": "rule_set_221" + "remarks": "rule_set_240" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "rsyslog_files_ownership", - "remarks": "rule_set_221" + "remarks": "rule_set_240" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Log Files Are Owned By Appropriate User", - "remarks": "rule_set_221" + "remarks": "rule_set_240" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "rsyslog_files_permissions", - "remarks": "rule_set_222" + "remarks": "rule_set_241" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure System Log Files Have Correct Permissions", - "remarks": "rule_set_222" + "remarks": "rule_set_241" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "rsyslog_files_permissions", - "remarks": "rule_set_222" + "remarks": "rule_set_241" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure System Log Files Have Correct Permissions", - "remarks": "rule_set_222" + "remarks": "rule_set_241" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_passwd", - "remarks": "rule_set_223" + "remarks": "rule_set_242" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns passwd File", - "remarks": "rule_set_223" + "remarks": "rule_set_242" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_passwd", - "remarks": "rule_set_223" + "remarks": "rule_set_242" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns passwd File", - "remarks": "rule_set_223" + "remarks": "rule_set_242" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_passwd", - "remarks": "rule_set_224" + "remarks": "rule_set_243" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns passwd File", - "remarks": "rule_set_224" + "remarks": "rule_set_243" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_passwd", - "remarks": "rule_set_224" + "remarks": "rule_set_243" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns passwd File", - "remarks": "rule_set_224" + "remarks": "rule_set_243" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_passwd", - "remarks": "rule_set_225" + "remarks": "rule_set_244" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on passwd File", - "remarks": "rule_set_225" + "remarks": "rule_set_244" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_passwd", - "remarks": "rule_set_225" + "remarks": "rule_set_244" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on passwd File", - "remarks": "rule_set_225" + "remarks": "rule_set_244" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_backup_etc_passwd", - "remarks": "rule_set_226" + "remarks": "rule_set_245" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns Backup passwd File", - "remarks": "rule_set_226" + "remarks": "rule_set_245" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_backup_etc_passwd", - "remarks": "rule_set_226" + "remarks": "rule_set_245" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns Backup passwd File", - "remarks": "rule_set_226" + "remarks": "rule_set_245" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_backup_etc_passwd", - "remarks": "rule_set_227" + "remarks": "rule_set_246" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns Backup passwd File", - "remarks": "rule_set_227" + "remarks": "rule_set_246" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_backup_etc_passwd", - "remarks": "rule_set_227" + "remarks": "rule_set_246" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns Backup passwd File", - "remarks": "rule_set_227" + "remarks": "rule_set_246" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_backup_etc_passwd", - "remarks": "rule_set_228" + "remarks": "rule_set_247" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on Backup passwd File", - "remarks": "rule_set_228" + "remarks": "rule_set_247" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_backup_etc_passwd", - "remarks": "rule_set_228" + "remarks": "rule_set_247" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on Backup passwd File", - "remarks": "rule_set_228" + "remarks": "rule_set_247" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_group", - "remarks": "rule_set_229" + "remarks": "rule_set_248" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns group File", - "remarks": "rule_set_229" + "remarks": "rule_set_248" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_group", - "remarks": "rule_set_229" + "remarks": "rule_set_248" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns group File", - "remarks": "rule_set_229" + "remarks": "rule_set_248" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_group", - "remarks": "rule_set_230" + "remarks": "rule_set_249" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns group File", - "remarks": "rule_set_230" + "remarks": "rule_set_249" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_group", - "remarks": "rule_set_230" + "remarks": "rule_set_249" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns group File", - "remarks": "rule_set_230" + "remarks": "rule_set_249" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_group", - "remarks": "rule_set_231" + "remarks": "rule_set_250" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on group File", - "remarks": "rule_set_231" + "remarks": "rule_set_250" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_group", - "remarks": "rule_set_231" + "remarks": "rule_set_250" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on group File", - "remarks": "rule_set_231" + "remarks": "rule_set_250" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_backup_etc_group", - "remarks": "rule_set_232" + "remarks": "rule_set_251" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns Backup group File", - "remarks": "rule_set_232" + "remarks": "rule_set_251" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_backup_etc_group", - "remarks": "rule_set_232" + "remarks": "rule_set_251" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns Backup group File", - "remarks": "rule_set_232" + "remarks": "rule_set_251" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_backup_etc_group", - "remarks": "rule_set_233" + "remarks": "rule_set_252" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns Backup group File", - "remarks": "rule_set_233" + "remarks": "rule_set_252" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_backup_etc_group", - "remarks": "rule_set_233" + "remarks": "rule_set_252" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns Backup group File", - "remarks": "rule_set_233" + "remarks": "rule_set_252" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_backup_etc_group", - "remarks": "rule_set_234" + "remarks": "rule_set_253" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on Backup group File", - "remarks": "rule_set_234" + "remarks": "rule_set_253" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_backup_etc_group", - "remarks": "rule_set_234" + "remarks": "rule_set_253" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on Backup group File", - "remarks": "rule_set_234" + "remarks": "rule_set_253" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_shadow", - "remarks": "rule_set_235" + "remarks": "rule_set_254" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns shadow File", - "remarks": "rule_set_235" + "remarks": "rule_set_254" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_shadow", - "remarks": "rule_set_235" + "remarks": "rule_set_254" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns shadow File", - "remarks": "rule_set_235" + "remarks": "rule_set_254" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_shadow", - "remarks": "rule_set_236" + "remarks": "rule_set_255" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns shadow File", - "remarks": "rule_set_236" + "remarks": "rule_set_255" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_shadow", - "remarks": "rule_set_236" + "remarks": "rule_set_255" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns shadow File", - "remarks": "rule_set_236" + "remarks": "rule_set_255" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_shadow", - "remarks": "rule_set_237" + "remarks": "rule_set_256" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on shadow File", - "remarks": "rule_set_237" + "remarks": "rule_set_256" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_shadow", - "remarks": "rule_set_237" + "remarks": "rule_set_256" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on shadow File", - "remarks": "rule_set_237" + "remarks": "rule_set_256" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_backup_etc_shadow", - "remarks": "rule_set_238" + "remarks": "rule_set_257" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns Backup shadow File", - "remarks": "rule_set_238" + "remarks": "rule_set_257" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_backup_etc_shadow", - "remarks": "rule_set_238" + "remarks": "rule_set_257" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns Backup shadow File", - "remarks": "rule_set_238" + "remarks": "rule_set_257" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_backup_etc_shadow", - "remarks": "rule_set_239" + "remarks": "rule_set_258" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns Backup shadow File", - "remarks": "rule_set_239" + "remarks": "rule_set_258" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_backup_etc_shadow", - "remarks": "rule_set_239" + "remarks": "rule_set_258" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns Backup shadow File", - "remarks": "rule_set_239" + "remarks": "rule_set_258" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_backup_etc_shadow", - "remarks": "rule_set_240" + "remarks": "rule_set_259" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on Backup shadow File", - "remarks": "rule_set_240" + "remarks": "rule_set_259" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_backup_etc_shadow", - "remarks": "rule_set_240" + "remarks": "rule_set_259" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on Backup shadow File", - "remarks": "rule_set_240" + "remarks": "rule_set_259" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_gshadow", - "remarks": "rule_set_241" + "remarks": "rule_set_260" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns gshadow File", - "remarks": "rule_set_241" + "remarks": "rule_set_260" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_gshadow", - "remarks": "rule_set_241" + "remarks": "rule_set_260" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns gshadow File", - "remarks": "rule_set_241" + "remarks": "rule_set_260" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_gshadow", - "remarks": "rule_set_242" + "remarks": "rule_set_261" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns gshadow File", - "remarks": "rule_set_242" + "remarks": "rule_set_261" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_gshadow", - "remarks": "rule_set_242" + "remarks": "rule_set_261" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns gshadow File", - "remarks": "rule_set_242" + "remarks": "rule_set_261" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_gshadow", - "remarks": "rule_set_243" + "remarks": "rule_set_262" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on gshadow File", - "remarks": "rule_set_243" + "remarks": "rule_set_262" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_gshadow", - "remarks": "rule_set_243" + "remarks": "rule_set_262" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on gshadow File", - "remarks": "rule_set_243" + "remarks": "rule_set_262" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_backup_etc_gshadow", - "remarks": "rule_set_244" + "remarks": "rule_set_263" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns Backup gshadow File", - "remarks": "rule_set_244" + "remarks": "rule_set_263" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_backup_etc_gshadow", - "remarks": "rule_set_244" + "remarks": "rule_set_263" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns Backup gshadow File", - "remarks": "rule_set_244" + "remarks": "rule_set_263" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_backup_etc_gshadow", - "remarks": "rule_set_245" + "remarks": "rule_set_264" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns Backup gshadow File", - "remarks": "rule_set_245" + "remarks": "rule_set_264" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_backup_etc_gshadow", - "remarks": "rule_set_245" + "remarks": "rule_set_264" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns Backup gshadow File", - "remarks": "rule_set_245" + "remarks": "rule_set_264" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_backup_etc_gshadow", - "remarks": "rule_set_246" + "remarks": "rule_set_265" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on Backup gshadow File", - "remarks": "rule_set_246" + "remarks": "rule_set_265" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_backup_etc_gshadow", - "remarks": "rule_set_246" + "remarks": "rule_set_265" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on Backup gshadow File", - "remarks": "rule_set_246" + "remarks": "rule_set_265" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_shells", - "remarks": "rule_set_247" + "remarks": "rule_set_266" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns /etc/shells File", - "remarks": "rule_set_247" + "remarks": "rule_set_266" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_shells", - "remarks": "rule_set_247" + "remarks": "rule_set_266" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns /etc/shells File", - "remarks": "rule_set_247" + "remarks": "rule_set_266" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_shells", - "remarks": "rule_set_248" + "remarks": "rule_set_267" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Who Owns /etc/shells File", - "remarks": "rule_set_248" + "remarks": "rule_set_267" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_shells", - "remarks": "rule_set_248" + "remarks": "rule_set_267" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Who Owns /etc/shells File", - "remarks": "rule_set_248" + "remarks": "rule_set_267" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_shells", - "remarks": "rule_set_249" + "remarks": "rule_set_268" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on /etc/shells File", - "remarks": "rule_set_249" + "remarks": "rule_set_268" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_shells", - "remarks": "rule_set_249" + "remarks": "rule_set_268" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on /etc/shells File", - "remarks": "rule_set_249" + "remarks": "rule_set_268" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_etc_security_opasswd", - "remarks": "rule_set_250" + "remarks": "rule_set_269" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions and Ownership of Old Passwords File", - "remarks": "rule_set_250" + "remarks": "rule_set_269" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_etc_security_opasswd", - "remarks": "rule_set_250" + "remarks": "rule_set_269" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions and Ownership of Old Passwords File", - "remarks": "rule_set_250" + "remarks": "rule_set_269" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_unauthorized_world_writable", - "remarks": "rule_set_251" + "remarks": "rule_set_270" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure No World-Writable Files Exist", - "remarks": "rule_set_251" + "remarks": "rule_set_270" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_unauthorized_world_writable", - "remarks": "rule_set_251" + "remarks": "rule_set_270" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure No World-Writable Files Exist", - "remarks": "rule_set_251" + "remarks": "rule_set_270" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dir_perms_world_writable_sticky_bits", - "remarks": "rule_set_252" + "remarks": "rule_set_271" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify that All World-Writable Directories Have Sticky Bits Set", - "remarks": "rule_set_252" + "remarks": "rule_set_271" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dir_perms_world_writable_sticky_bits", - "remarks": "rule_set_252" + "remarks": "rule_set_271" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify that All World-Writable Directories Have Sticky Bits Set", - "remarks": "rule_set_252" + "remarks": "rule_set_271" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_files_unowned_by_user", - "remarks": "rule_set_253" + "remarks": "rule_set_272" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Files Are Owned by a User", - "remarks": "rule_set_253" + "remarks": "rule_set_272" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_files_unowned_by_user", - "remarks": "rule_set_253" + "remarks": "rule_set_272" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Files Are Owned by a User", - "remarks": "rule_set_253" + "remarks": "rule_set_272" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_ungroupowned", - "remarks": "rule_set_254" + "remarks": "rule_set_273" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Files Are Owned by a Group", - "remarks": "rule_set_254" + "remarks": "rule_set_273" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_ungroupowned", - "remarks": "rule_set_254" + "remarks": "rule_set_273" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Files Are Owned by a Group", - "remarks": "rule_set_254" + "remarks": "rule_set_273" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_all_shadowed", - "remarks": "rule_set_255" + "remarks": "rule_set_274" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify All Account Password Hashes are Shadowed", - "remarks": "rule_set_255" + "remarks": "rule_set_274" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_all_shadowed", - "remarks": "rule_set_255" + "remarks": "rule_set_274" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify All Account Password Hashes are Shadowed", - "remarks": "rule_set_255" + "remarks": "rule_set_274" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_empty_passwords_etc_shadow", - "remarks": "rule_set_256" + "remarks": "rule_set_275" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure There Are No Accounts With Blank or Null Passwords", - "remarks": "rule_set_256" + "remarks": "rule_set_275" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_empty_passwords_etc_shadow", - "remarks": "rule_set_256" + "remarks": "rule_set_275" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure There Are No Accounts With Blank or Null Passwords", - "remarks": "rule_set_256" + "remarks": "rule_set_275" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "gid_passwd_group_same", - "remarks": "rule_set_257" + "remarks": "rule_set_276" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "All GIDs referenced in /etc/passwd must be defined in /etc/group", - "remarks": "rule_set_257" + "remarks": "rule_set_276" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "gid_passwd_group_same", - "remarks": "rule_set_257" + "remarks": "rule_set_276" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "All GIDs referenced in /etc/passwd must be defined in /etc/group", - "remarks": "rule_set_257" + "remarks": "rule_set_276" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "account_unique_id", - "remarks": "rule_set_258" + "remarks": "rule_set_277" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Accounts on the System Have Unique User IDs", - "remarks": "rule_set_258" + "remarks": "rule_set_277" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "account_unique_id", - "remarks": "rule_set_258" + "remarks": "rule_set_277" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Accounts on the System Have Unique User IDs", - "remarks": "rule_set_258" + "remarks": "rule_set_277" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "group_unique_id", - "remarks": "rule_set_259" + "remarks": "rule_set_278" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Groups on the System Have Unique Group ID", - "remarks": "rule_set_259" + "remarks": "rule_set_278" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "group_unique_id", - "remarks": "rule_set_259" + "remarks": "rule_set_278" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Groups on the System Have Unique Group ID", - "remarks": "rule_set_259" + "remarks": "rule_set_278" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "account_unique_name", - "remarks": "rule_set_260" + "remarks": "rule_set_279" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Accounts on the System Have Unique Names", - "remarks": "rule_set_260" + "remarks": "rule_set_279" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "account_unique_name", - "remarks": "rule_set_260" + "remarks": "rule_set_279" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Accounts on the System Have Unique Names", - "remarks": "rule_set_260" + "remarks": "rule_set_279" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "group_unique_name", - "remarks": "rule_set_261" + "remarks": "rule_set_280" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Groups on the System Have Unique Group Names", - "remarks": "rule_set_261" + "remarks": "rule_set_280" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "group_unique_name", - "remarks": "rule_set_261" + "remarks": "rule_set_280" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Groups on the System Have Unique Group Names", - "remarks": "rule_set_261" + "remarks": "rule_set_280" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_user_interactive_home_directory_exists", - "remarks": "rule_set_262" + "remarks": "rule_set_281" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "All Interactive Users Home Directories Must Exist", - "remarks": "rule_set_262" + "remarks": "rule_set_281" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_user_interactive_home_directory_exists", - "remarks": "rule_set_262" + "remarks": "rule_set_281" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "All Interactive Users Home Directories Must Exist", - "remarks": "rule_set_262" + "remarks": "rule_set_281" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_ownership_home_directories", - "remarks": "rule_set_263" + "remarks": "rule_set_282" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "All Interactive User Home Directories Must Be Owned By The Primary User", - "remarks": "rule_set_263" + "remarks": "rule_set_282" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_ownership_home_directories", - "remarks": "rule_set_263" + "remarks": "rule_set_282" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "All Interactive User Home Directories Must Be Owned By The Primary User", - "remarks": "rule_set_263" + "remarks": "rule_set_282" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_home_directories", - "remarks": "rule_set_264" + "remarks": "rule_set_283" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "All Interactive User Home Directories Must Have mode 0750 Or Less Permissive", - "remarks": "rule_set_264" + "remarks": "rule_set_283" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_home_directories", - "remarks": "rule_set_264" + "remarks": "rule_set_283" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "All Interactive User Home Directories Must Have mode 0750 Or Less Permissive", - "remarks": "rule_set_264" + "remarks": "rule_set_283" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_user_dot_group_ownership", - "remarks": "rule_set_265" + "remarks": "rule_set_284" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "User Initialization Files Must Be Group-Owned By The Primary Group", - "remarks": "rule_set_265" + "remarks": "rule_set_284" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_user_dot_group_ownership", - "remarks": "rule_set_265" + "remarks": "rule_set_284" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "User Initialization Files Must Be Group-Owned By The Primary Group", - "remarks": "rule_set_265" + "remarks": "rule_set_284" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_user_dot_user_ownership", - "remarks": "rule_set_266" + "remarks": "rule_set_285" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "User Initialization Files Must Be Owned By the Primary User", - "remarks": "rule_set_266" + "remarks": "rule_set_285" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_user_dot_user_ownership", - "remarks": "rule_set_266" + "remarks": "rule_set_285" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "User Initialization Files Must Be Owned By the Primary User", - "remarks": "rule_set_266" + "remarks": "rule_set_285" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_user_dot_no_world_writable_programs", - "remarks": "rule_set_267" + "remarks": "rule_set_286" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "User Initialization Files Must Not Run World-Writable Programs", - "remarks": "rule_set_267" + "remarks": "rule_set_286" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_user_dot_no_world_writable_programs", - "remarks": "rule_set_267" + "remarks": "rule_set_286" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "User Initialization Files Must Not Run World-Writable Programs", - "remarks": "rule_set_267" + "remarks": "rule_set_286" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permission_user_init_files", - "remarks": "rule_set_268" + "remarks": "rule_set_287" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All User Initialization Files Have Mode 0740 Or Less Permissive", - "remarks": "rule_set_268" + "remarks": "rule_set_287" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permission_user_init_files", - "remarks": "rule_set_268" + "remarks": "rule_set_287" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All User Initialization Files Have Mode 0740 Or Less Permissive", - "remarks": "rule_set_268" + "remarks": "rule_set_287" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_forward_files", - "remarks": "rule_set_269" + "remarks": "rule_set_288" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify No .forward Files Exist", - "remarks": "rule_set_269" + "remarks": "rule_set_288" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_forward_files", - "remarks": "rule_set_269" + "remarks": "rule_set_288" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify No .forward Files Exist", - "remarks": "rule_set_269" + "remarks": "rule_set_288" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_netrc_files", - "remarks": "rule_set_270" + "remarks": "rule_set_289" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify No netrc Files Exist", - "remarks": "rule_set_270" + "remarks": "rule_set_289" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_netrc_files", - "remarks": "rule_set_270" + "remarks": "rule_set_289" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify No netrc Files Exist", - "remarks": "rule_set_270" + "remarks": "rule_set_289" } ], "control-implementations": [ { - "uuid": "2160c428-a0dd-443b-83d6-4253a12170f9", + "uuid": "5ad82e1f-d361-4453-8ddd-9eb89e1043b2", "source": "trestle://profiles/rhel10-cis_rhel10-l1_workstation/profile.json", "description": "REPLACE_ME", "props": [ @@ -16217,13 +16098,13 @@ { "param-id": "sshd_strong_kex", "values": [ - "cis_rhel8" + "cis_rhel10" ] }, { "param-id": "sshd_strong_macs", "values": [ - "cis_rhel8" + "cis_rhel10" ] }, { @@ -16328,807 +16209,204 @@ "disabled" ] }, - { - "param-id": "sysctl_net_ipv6_conf_default_accept_ra_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv6_conf_default_accept_redirects_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv6_conf_default_accept_source_route_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "var_account_disable_post_pw_expiration", - "values": [ - "30" - ] - }, - { - "param-id": "var_accounts_maximum_age_login_defs", - "values": [ - "365" - ] - }, - { - "param-id": "var_accounts_password_warn_age_login_defs", - "values": [ - "7" - ] - }, - { - "param-id": "var_accounts_passwords_pam_faillock_deny", - "values": [ - "5" - ] - }, - { - "param-id": "var_accounts_passwords_pam_faillock_unlock_time", - "values": [ - "900" - ] - }, - { - "param-id": "var_accounts_tmout", - "values": [ - "15_min" - ] - }, - { - "param-id": "var_accounts_user_umask", - "values": [ - "027" - ] - }, - { - "param-id": "var_authselect_profile", - "values": [ - "local" - ] - }, - { - "param-id": "var_multiple_time_servers", - "values": [ - "rhel" - ] - }, - { - "param-id": "var_pam_wheel_group_for_su", - "values": [ - "cis" - ] - }, - { - "param-id": "var_password_hashing_algorithm", - "values": [ - "yescrypt" - ] - }, - { - "param-id": "var_password_hashing_algorithm_pam", - "values": [ - "yescrypt" - ] - }, - { - "param-id": "var_password_pam_dictcheck", - "values": [ - "1" - ] - }, - { - "param-id": "var_password_pam_difok", - "values": [ - "2" - ] - }, - { - "param-id": "var_password_pam_maxrepeat", - "values": [ - "3" - ] - }, - { - "param-id": "var_password_pam_minclass", - "values": [ - "4" - ] - }, - { - "param-id": "var_password_pam_minlen", - "values": [ - "14" - ] - }, - { - "param-id": "var_password_pam_remember", - "values": [ - "24" - ] - }, - { - "param-id": "var_password_pam_remember_control_flag", - "values": [ - "requisite_or_required" - ] - }, - { - "param-id": "var_postfix_inet_interfaces", - "values": [ - "loopback-only" - ] - }, - { - "param-id": "var_screensaver_lock_delay", - "values": [ - "5_seconds" - ] - }, - { - "param-id": "var_selinux_policy_name", - "values": [ - "targeted" - ] - }, - { - "param-id": "var_sshd_max_sessions", - "values": [ - "10" - ] - }, - { - "param-id": "var_sshd_set_keepalive", - "values": [ - "1" - ] - }, - { - "param-id": "var_sshd_set_login_grace_time", - "values": [ - "60" - ] - }, - { - "param-id": "var_sshd_set_maxstartups", - "values": [ - "10:30:60" - ] - }, - { - "param-id": "var_system_crypto_policy", - "values": [ - "default_policy" - ] - }, - { - "param-id": "var_user_initialization_files_regex", - "values": [ - "all_dotfiles" - ] - } - ], - "implemented-requirements": [ - { - "uuid": "4d2b3360-4f3b-4710-9cba-8281a72fca03", - "control-id": "reload_dconf_db", - "description": "This is a helper rule to reload Dconf database correctly.", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_db_up_to_date" - } - ] - }, - { - "uuid": "0c85ed78-06d8-477c-bc35-244e200b49b7", - "control-id": "cis_rhel10_1-1.2.1.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_tmp" - } - ] - }, - { - "uuid": "4d6e280d-bf42-4e94-b750-35136639821a", - "control-id": "cis_rhel10_1-1.2.1.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_nodev" - } - ] - }, - { - "uuid": "a2648efd-c60a-4748-81d1-ae0e50ca19a4", - "control-id": "cis_rhel10_1-1.2.1.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_nosuid" - } + { + "param-id": "sysctl_net_ipv6_conf_default_accept_ra_value", + "values": [ + "disabled" ] }, { - "uuid": "82e2a6f9-b2df-40bb-a933-af36c04f7369", - "control-id": "cis_rhel10_1-1.2.1.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_noexec" - } + "param-id": "sysctl_net_ipv6_conf_default_accept_redirects_value", + "values": [ + "disabled" ] }, { - "uuid": "0bfcf68b-f9f5-4e7f-932b-7026645743e3", - "control-id": "cis_rhel10_1-1.2.2.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_dev_shm" - } + "param-id": "sysctl_net_ipv6_conf_default_accept_source_route_value", + "values": [ + "disabled" ] }, { - "uuid": "8ddccd1a-86d5-4ca6-8fb4-ec671e59c9a0", - "control-id": "cis_rhel10_1-1.2.2.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_nodev" - } + "param-id": "sysctl_net_ipv6_conf_default_forwarding_value", + "values": [ + "disabled" ] }, { - "uuid": "d5eccaf7-afa4-4559-b82a-a179954f9602", - "control-id": "cis_rhel10_1-1.2.2.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_nosuid" - } + "param-id": "var_account_disable_post_pw_expiration", + "values": [ + "30" ] }, { - "uuid": "90e498fa-23a5-4877-b0dc-92651c89888a", - "control-id": "cis_rhel10_1-1.2.2.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_noexec" - } + "param-id": "var_accounts_maximum_age_login_defs", + "values": [ + "365" ] }, { - "uuid": "af53dc7e-9125-453e-b4e0-0d25e1c6e77f", - "control-id": "cis_rhel10_1-1.2.3.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_home_nodev" - } + "param-id": "var_accounts_password_warn_age_login_defs", + "values": [ + "7" ] }, { - "uuid": "b54dc1fd-678a-4aa3-a0f0-af43c88cf384", - "control-id": "cis_rhel10_1-1.2.3.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_home_nosuid" - } + "param-id": "var_accounts_passwords_pam_faillock_deny", + "values": [ + "5" ] }, { - "uuid": "7814653c-b857-4279-85d9-e7eb430aa5bd", - "control-id": "cis_rhel10_1-1.2.4.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_nodev" - } + "param-id": "var_accounts_passwords_pam_faillock_unlock_time", + "values": [ + "900" ] }, { - "uuid": "4f845e7d-730b-4472-9472-efc560321272", - "control-id": "cis_rhel10_1-1.2.4.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_nosuid" - } + "param-id": "var_accounts_tmout", + "values": [ + "15_min" ] }, { - "uuid": "e092ef19-de7e-4c28-91bb-3ad2debf4812", - "control-id": "cis_rhel10_1-1.2.5.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_tmp_nodev" - } + "param-id": "var_accounts_user_umask", + "values": [ + "027" ] }, { - "uuid": "501bc225-aca5-4075-a242-707fb44dc9df", - "control-id": "cis_rhel10_1-1.2.5.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_tmp_nosuid" - } + "param-id": "var_authselect_profile", + "values": [ + "local" ] }, { - "uuid": "1169d650-298e-4e10-8156-0fb216fb296d", - "control-id": "cis_rhel10_1-1.2.5.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_tmp_noexec" - } + "param-id": "var_multiple_time_servers", + "values": [ + "rhel" ] }, { - "uuid": "354d0b72-aced-4775-9172-6a7eff1dfb05", - "control-id": "cis_rhel10_1-1.2.6.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_nodev" - } + "param-id": "var_pam_wheel_group_for_su", + "values": [ + "cis" ] }, { - "uuid": "681ae5a0-4f0a-44e8-879f-1c07ff17cd68", - "control-id": "cis_rhel10_1-1.2.6.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_nosuid" - } + "param-id": "var_password_hashing_algorithm", + "values": [ + "yescrypt" ] }, { - "uuid": "23c84a65-9653-47c5-9bb6-5e0414526c60", - "control-id": "cis_rhel10_1-1.2.6.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_noexec" - } + "param-id": "var_password_hashing_algorithm_pam", + "values": [ + "yescrypt" ] }, { - "uuid": "441f9f8d-abe5-4c4e-a5b3-afe41817dbbe", - "control-id": "cis_rhel10_1-1.2.7.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_audit_nodev" - } + "param-id": "var_password_pam_dictcheck", + "values": [ + "1" ] }, { - "uuid": "f108f8e5-8a86-49fa-8a68-7f8ce99bb30e", - "control-id": "cis_rhel10_1-1.2.7.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_audit_nosuid" - } + "param-id": "var_password_pam_difok", + "values": [ + "2" ] }, { - "uuid": "75a4b2a4-ecf3-48dc-a5ed-8d801fd515a2", - "control-id": "cis_rhel10_1-1.2.7.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_audit_noexec" - } + "param-id": "var_password_pam_maxrepeat", + "values": [ + "3" ] }, { - "uuid": "f3dcc726-f4a9-44b3-aa3b-ae2827984950", - "control-id": "cis_rhel10_1-2.1.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } + "param-id": "var_password_pam_minclass", + "values": [ + "4" ] }, { - "uuid": "c1eee797-e7e5-4f9f-af1b-e834afecbec0", - "control-id": "cis_rhel10_1-2.1.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_gpgcheck_globally_activated" - } + "param-id": "var_password_pam_minlen", + "values": [ + "14" ] }, { - "uuid": "35e0bd74-84fd-4d64-9910-cea8c25a7597", - "control-id": "cis_rhel10_1-2.1.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } + "param-id": "var_password_pam_remember", + "values": [ + "24" ] }, { - "uuid": "136a5749-3517-4177-abe7-269b78afb590", - "control-id": "cis_rhel10_1-2.2.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } + "param-id": "var_password_pam_remember_control_flag", + "values": [ + "requisite_or_required" ] }, { - "uuid": "008afb1b-123b-4626-9bfb-c9830c9b506b", - "control-id": "cis_rhel10_1-3.1.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_libselinux_installed" - } + "param-id": "var_postfix_inet_interfaces", + "values": [ + "loopback-only" ] }, { - "uuid": "0ef3d5ea-68d5-44af-a8dd-2d3b211c0f8e", - "control-id": "cis_rhel10_1-3.1.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "grub2_enable_selinux" - } + "param-id": "var_screensaver_lock_delay", + "values": [ + "5_seconds" ] }, { - "uuid": "73002b76-7c17-4d56-84f4-75e6057cc71a", - "control-id": "cis_rhel10_1-3.1.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "selinux_policytype" - } + "param-id": "var_selinux_policy_name", + "values": [ + "targeted" ] }, { - "uuid": "5186ec38-1ce5-4a5d-baaf-d39166ca96fc", - "control-id": "cis_rhel10_1-3.1.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "selinux_not_disabled" - } + "param-id": "var_sshd_max_sessions", + "values": [ + "10" ] }, { - "uuid": "fe0506c7-1baf-411e-9377-c149de29755e", - "control-id": "cis_rhel10_1-3.1.7", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_mcstrans_removed" - } + "param-id": "var_sshd_set_keepalive", + "values": [ + "1" ] }, { - "uuid": "d64a096d-0412-4e52-bb33-9b3e049735ea", - "control-id": "cis_rhel10_1-4.1", - "description": "There is no automated remediation for this rule and this is intentional.\nMore details in the rule description.", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "grub2_password" - } + "param-id": "var_sshd_set_login_grace_time", + "values": [ + "60" ] }, { - "uuid": "f27edbb6-085d-4ff8-abab-3daa4b391c81", - "control-id": "cis_rhel10_1-4.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "This requirement demands a deeper review of the rules." - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_grub2_cfg" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_grub2_cfg" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_grub2_cfg" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_user_cfg" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_user_cfg" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_user_cfg" - } + "param-id": "var_sshd_set_maxstartups", + "values": [ + "10:30:60" ] }, { - "uuid": "060e78e5-0a4f-4430-a3c4-9527d39ae127", - "control-id": "cis_rhel10_1-5.1", - "description": "Address Space Layout Randomization (ASLR)", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_kernel_randomize_va_space" - } + "param-id": "var_system_crypto_policy", + "values": [ + "default_policy" ] }, { - "uuid": "78b9e05f-d108-426a-80a4-9f7c827d5dc3", - "control-id": "cis_rhel10_1-5.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_kernel_yama_ptrace_scope" - } + "param-id": "var_user_initialization_files_regex", + "values": [ + "all_dotfiles" ] - }, + } + ], + "implemented-requirements": [ { - "uuid": "b6aeddf5-3e49-4fce-a354-16d871ad644e", - "control-id": "cis_rhel10_1-5.3", - "description": "REPLACE_ME", + "uuid": "a29b0ae7-1923-4cc6-bb9d-30a3ddb95405", + "control-id": "reload_dconf_db", + "description": "This is a helper rule to reload Dconf database correctly.", "props": [ { "name": "implementation-status", @@ -17138,13 +16416,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_backtraces" + "value": "dconf_db_up_to_date" } ] }, { - "uuid": "8f3cccfa-9906-482e-95d5-ee05b4729497", - "control-id": "cis_rhel10_1-5.4", + "uuid": "20a87d9a-1f21-4725-834d-53a0100ec643", + "control-id": "cis_rhel10_1-1.2.1.1", "description": "REPLACE_ME", "props": [ { @@ -17155,13 +16433,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_storage" + "value": "partition_for_tmp" } ] }, { - "uuid": "d0b5db6a-d114-4463-8fc4-8b6c2dceae02", - "control-id": "cis_rhel10_1-6.1", + "uuid": "f6b8eac6-7eff-43ed-9700-97808ea327bc", + "control-id": "cis_rhel10_1-1.2.1.2", "description": "REPLACE_ME", "props": [ { @@ -17172,13 +16450,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_crypto_policy" + "value": "mount_option_tmp_nodev" } ] }, { - "uuid": "3535b7db-1dba-49ed-b9af-8e9d5b819f55", - "control-id": "cis_rhel10_1-6.2", + "uuid": "8e6bad9b-26f3-44b2-bee8-79b053d072bb", + "control-id": "cis_rhel10_1-1.2.1.3", "description": "REPLACE_ME", "props": [ { @@ -17189,77 +16467,47 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_ssh_crypto_policy" - } - ] - }, - { - "uuid": "38595467-17d5-4bbc-8b07-7d9131c74e6f", - "control-id": "cis_rhel10_1-6.3", - "description": "This requirement is already satisfied by 1.6.1.", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "mount_option_tmp_nosuid" } ] }, { - "uuid": "3bd9c3ce-d91d-47dc-a221-481a72042b38", - "control-id": "cis_rhel10_1-6.4", + "uuid": "b458e0b0-ab10-42f0-bd89-7008290f9b36", + "control-id": "cis_rhel10_1-1.2.1.4", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary a new rule to ensure a module disabling weak MACs in\n/etc/crypto-policies/policies/modules/ so it can be used by update-crypto-policies command." - } - ] - }, - { - "uuid": "7a547a5c-38e5-4a52-bf69-bf6ca6a0b1b4", - "control-id": "cis_rhel10_1-6.5", - "description": "REPLACE_ME", - "props": [ + "value": "implemented" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary a new rule to ensure a module disabling CBC in\n/etc/crypto-policies/policies/modules/ so it can be used by update-crypto-policies command." + "value": "mount_option_tmp_noexec" } ] }, { - "uuid": "b96f0528-791c-4af2-b98b-d7523f916f90", - "control-id": "cis_rhel10_1-6.6", + "uuid": "522e84b1-5b2e-41b4-bac6-6dbb9e6ef0d4", + "control-id": "cis_rhel10_1-1.2.2.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } - ] - }, - { - "uuid": "fde6eba1-101b-40bb-9cba-c769be2accfb", - "control-id": "cis_rhel10_1-6.7", - "description": "REPLACE_ME", - "props": [ + "value": "implemented" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "partition_for_dev_shm" } ] }, { - "uuid": "19676bf4-7801-4c74-a667-baed311c18f4", - "control-id": "cis_rhel10_1-7.1", + "uuid": "45e30a71-041d-4d0c-b847-14d0c34e91fc", + "control-id": "cis_rhel10_1-1.2.2.2", "description": "REPLACE_ME", "props": [ { @@ -17270,13 +16518,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "banner_etc_motd_cis" + "value": "mount_option_dev_shm_nodev" } ] }, { - "uuid": "53caaf4c-470c-4b6a-b6bd-40196477a8d6", - "control-id": "cis_rhel10_1-7.2", + "uuid": "31f2e654-88eb-465c-9d18-2f1be4a0766c", + "control-id": "cis_rhel10_1-1.2.2.3", "description": "REPLACE_ME", "props": [ { @@ -17287,13 +16535,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "banner_etc_issue_cis" + "value": "mount_option_dev_shm_nosuid" } ] }, { - "uuid": "3bb2dd8e-c266-4d19-abb2-f75881019ebb", - "control-id": "cis_rhel10_1-7.3", + "uuid": "b610ba33-d16d-443b-af5f-dcabe30a1b1e", + "control-id": "cis_rhel10_1-1.2.2.4", "description": "REPLACE_ME", "props": [ { @@ -17304,13 +16552,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "banner_etc_issue_net_cis" + "value": "mount_option_dev_shm_noexec" } ] }, { - "uuid": "e4ceb3cf-22ce-47b8-b589-49d2b414fd45", - "control-id": "cis_rhel10_1-7.4", + "uuid": "ffbc5eb4-80d3-4b58-8bea-214f3b679fe1", + "control-id": "cis_rhel10_1-1.2.3.2", "description": "REPLACE_ME", "props": [ { @@ -17321,23 +16569,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_motd" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_motd" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_motd" + "value": "mount_option_home_nodev" } ] }, { - "uuid": "c44b853f-1d25-4e82-9c93-d84722da3544", - "control-id": "cis_rhel10_1-7.5", + "uuid": "177e3077-e905-4829-a230-e5f0eb1fb9f6", + "control-id": "cis_rhel10_1-1.2.3.3", "description": "REPLACE_ME", "props": [ { @@ -17348,23 +16586,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_issue" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_issue" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_issue" + "value": "mount_option_home_nosuid" } ] }, { - "uuid": "49a312ef-5534-4c9e-baff-bf70828ad25a", - "control-id": "cis_rhel10_1-7.6", + "uuid": "cac4c60c-ecec-4670-9391-1da97062741b", + "control-id": "cis_rhel10_1-1.2.4.2", "description": "REPLACE_ME", "props": [ { @@ -17375,23 +16603,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_issue_net" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_issue_net" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_issue_net" + "value": "mount_option_var_nodev" } ] }, { - "uuid": "b42b4d7c-e822-4f89-a4fe-325b38d2fd65", - "control-id": "cis_rhel10_1-8.2", + "uuid": "bd368aaf-4686-4908-86f1-ab94f6fe40d5", + "control-id": "cis_rhel10_1-1.2.4.3", "description": "REPLACE_ME", "props": [ { @@ -17402,18 +16620,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_banner_enabled" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_login_banner_text" + "value": "mount_option_var_nosuid" } ] }, { - "uuid": "53b71586-d5ff-4b19-8b74-d0360f8a46bc", - "control-id": "cis_rhel10_1-8.3", + "uuid": "34bf2563-9d13-4cfa-8a18-cc02cf82b3dc", + "control-id": "cis_rhel10_1-1.2.5.2", "description": "REPLACE_ME", "props": [ { @@ -17424,13 +16637,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_user_list" + "value": "mount_option_var_tmp_nodev" } ] }, { - "uuid": "e7827c28-e4ec-49f2-9b4c-50bcc1c4a34b", - "control-id": "cis_rhel10_1-8.4", + "uuid": "621f35bb-8ebc-4fad-ba9c-9ab3e021fa5d", + "control-id": "cis_rhel10_1-1.2.5.3", "description": "REPLACE_ME", "props": [ { @@ -17441,18 +16654,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_screensaver_idle_delay" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_screensaver_lock_delay" + "value": "mount_option_var_tmp_nosuid" } ] }, { - "uuid": "e9ee8dc0-2f7d-40c6-aa61-3aeb22ecb723", - "control-id": "cis_rhel10_1-8.5", + "uuid": "cbc0bd5e-f562-4f51-b799-4df0ecb3c6b8", + "control-id": "cis_rhel10_1-1.2.5.4", "description": "REPLACE_ME", "props": [ { @@ -17463,18 +16671,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_session_idle_user_locks" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_screensaver_user_locks" + "value": "mount_option_var_tmp_noexec" } ] }, { - "uuid": "55785449-354e-4306-9f38-8a5103f8917e", - "control-id": "cis_rhel10_1-8.8", + "uuid": "76601845-cf84-47d8-b8f9-82f5d73b1b7e", + "control-id": "cis_rhel10_1-1.2.6.2", "description": "REPLACE_ME", "props": [ { @@ -17485,13 +16688,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_autorun" + "value": "mount_option_var_log_nodev" } ] }, { - "uuid": "0b9d5946-2e6d-4279-96c5-748898bcf9be", - "control-id": "cis_rhel10_1-8.9", + "uuid": "72f0cc45-a3ae-41bf-9c9d-8c2a665f2bc6", + "control-id": "cis_rhel10_1-1.2.6.3", "description": "REPLACE_ME", "props": [ { @@ -17502,25 +16705,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_autorun" - } - ] - }, - { - "uuid": "2084c943-603f-4a26-b1eb-e332db4a3a1f", - "control-id": "cis_rhel10_1-8.10", - "description": "This was inherited from the RHEL 9 profile.\nHowever, it was reported that XDMCP is no\nlonger in RHEL 10.", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "mount_option_var_log_nosuid" } ] }, { - "uuid": "3f1323c8-bcf1-4c23-b364-517f5f2e5a18", - "control-id": "cis_rhel10_2-1.3", + "uuid": "274f7c5c-831a-4780-9b69-1f7c005c3204", + "control-id": "cis_rhel10_1-1.2.6.4", "description": "REPLACE_ME", "props": [ { @@ -17531,13 +16722,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_kea_removed" + "value": "mount_option_var_log_noexec" } ] }, { - "uuid": "93a80822-7a1a-44b3-90ac-835a808f2e9b", - "control-id": "cis_rhel10_2-1.4", + "uuid": "87d8acca-b530-4fea-bc33-c5f33747b64c", + "control-id": "cis_rhel10_1-1.2.7.2", "description": "REPLACE_ME", "props": [ { @@ -17548,13 +16739,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_bind_removed" + "value": "mount_option_var_log_audit_nodev" } ] }, { - "uuid": "862f6fe3-fc0e-412e-a42f-b48e62fb5339", - "control-id": "cis_rhel10_2-1.5", + "uuid": "0f8d10cc-aaa6-45c4-9f4d-83b1fc9d9809", + "control-id": "cis_rhel10_1-1.2.7.3", "description": "REPLACE_ME", "props": [ { @@ -17565,13 +16756,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_dnsmasq_removed" + "value": "mount_option_var_log_audit_nosuid" } ] }, { - "uuid": "f40414d1-3e54-4e9e-a030-e6eb89bcba2d", - "control-id": "cis_rhel10_2-1.6", + "uuid": "12881429-b023-4939-90d0-0089acec11ed", + "control-id": "cis_rhel10_1-1.2.7.4", "description": "REPLACE_ME", "props": [ { @@ -17582,30 +16773,26 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_samba_removed" + "value": "mount_option_var_log_audit_noexec" } ] }, { - "uuid": "5dd1616d-09e0-4fdc-8107-cc7fa40eab14", - "control-id": "cis_rhel10_2-1.7", + "uuid": "abcc35ae-af3f-42cb-b442-fc4cde17061c", + "control-id": "cis_rhel10_1-2.1.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_vsftpd_removed" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "c4a07696-226c-4c06-9277-5616a65e8772", - "control-id": "cis_rhel10_2-1.8", + "uuid": "81a58f8e-31d3-4c32-bfd5-c653092cd40f", + "control-id": "cis_rhel10_1-2.1.2", "description": "REPLACE_ME", "props": [ { @@ -17616,48 +16803,40 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_dovecot_removed" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_cyrus-imapd_removed" + "value": "ensure_gpgcheck_globally_activated" } ] }, { - "uuid": "fd3de0be-8da7-4bda-aebe-bba2c5d715d1", - "control-id": "cis_rhel10_2-1.9", - "description": "Many of the libvirt packages used by Enterprise Linux virtualization are dependent on the\nnfs-utils package.", + "uuid": "4edb45b4-1857-436f-9bd0-46d5ac2b702f", + "control-id": "cis_rhel10_1-2.1.4", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_nfs_disabled" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "43d557cf-7fdc-46ad-baeb-f72cd7ebf163", - "control-id": "cis_rhel10_2-1.10", + "uuid": "210c720d-df8c-47b4-a2fd-fd43cc1868a3", + "control-id": "cis_rhel10_1-2.2.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "1520a300-d69b-494a-9e58-2dc7157cedc2", - "control-id": "cis_rhel10_2-1.12", - "description": "Many of the libvirt packages used by Enterprise Linux virtualization, and the nfs-utils\npackage used for The Network File System (NFS), are dependent on the rpcbind package.", + "uuid": "cb62a914-434f-4c4f-b110-7cf4df5f8fb1", + "control-id": "cis_rhel10_1-3.1.1", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -17667,13 +16846,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_rpcbind_disabled" + "value": "package_libselinux_installed" } ] }, { - "uuid": "e7611381-3282-48c6-aaf5-0f31d431f369", - "control-id": "cis_rhel10_2-1.13", + "uuid": "f7429b31-0170-4f64-a695-ed03e1eb6aca", + "control-id": "cis_rhel10_1-3.1.2", "description": "REPLACE_ME", "props": [ { @@ -17684,13 +16863,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_rsync_removed" + "value": "grub2_enable_selinux" } ] }, { - "uuid": "00dd2b4d-32b1-41a3-b955-11eda87f8a9f", - "control-id": "cis_rhel10_2-1.14", + "uuid": "bacfec52-eb1e-4b3b-9850-21fdfcfbc4dd", + "control-id": "cis_rhel10_1-3.1.3", "description": "REPLACE_ME", "props": [ { @@ -17701,13 +16880,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_net-snmp_removed" + "value": "selinux_policytype" } ] }, { - "uuid": "b7b96ec7-ab8a-4495-8efc-cb860dd75927", - "control-id": "cis_rhel10_2-1.15", + "uuid": "4667e926-8e61-4890-8a79-4c11279dcc7d", + "control-id": "cis_rhel10_1-3.1.4", "description": "REPLACE_ME", "props": [ { @@ -17718,13 +16897,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_telnet-server_removed" + "value": "selinux_not_disabled" } ] }, { - "uuid": "1fdfab76-1ff7-44c2-8ad1-a3d8f909b105", - "control-id": "cis_rhel10_2-1.16", + "uuid": "2bdbef72-7c1a-4d8c-9325-601c3c53a7ef", + "control-id": "cis_rhel10_1-3.1.7", "description": "REPLACE_ME", "props": [ { @@ -17735,14 +16914,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_tftp-server_removed" + "value": "package_mcstrans_removed" } ] }, { - "uuid": "f507c1a5-6e25-4cf4-9746-8c2825254f41", - "control-id": "cis_rhel10_2-1.17", - "description": "REPLACE_ME", + "uuid": "7234dda8-9d0e-4a54-a3e7-3fbc8fe723f9", + "control-id": "cis_rhel10_1-4.1", + "description": "There is no automated remediation for this rule and this is intentional.\nMore details in the rule description.", "props": [ { "name": "implementation-status", @@ -17752,70 +16931,90 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_squid_removed" + "value": "grub2_password" } ] }, { - "uuid": "c9735e52-421a-4af7-a89d-0275d90bbfd5", - "control-id": "cis_rhel10_2-1.18", + "uuid": "831b7937-743f-4495-a13b-7777f8070287", + "control-id": "cis_rhel10_1-4.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "alternative", + "remarks": "This requirement demands a deeper review of the rules." + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_groupowner_grub2_cfg" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_owner_grub2_cfg" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_grub2_cfg" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_groupowner_user_cfg" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_httpd_removed" + "value": "file_owner_user_cfg" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_nginx_removed" + "value": "file_permissions_user_cfg" } ] }, { - "uuid": "f7dda26e-83c6-41cd-b4c2-37f849ab7cc3", - "control-id": "cis_rhel10_2-1.21", - "description": "The rule has_nonlocal_mta currently checks for services listening only on port 25,\nbut the policy checks also for ports 465 and 587", + "uuid": "0ec32df2-1d91-4548-b798-5f628d94cded", + "control-id": "cis_rhel10_1-5.1", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "postfix_network_listening_disabled" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "has_nonlocal_mta" + "value": "disable_users_coredumps" } ] }, { - "uuid": "2de700f9-46cf-48cf-aa27-88e9e54ba20b", - "control-id": "cis_rhel10_2-1.22", + "uuid": "f4e14cd9-cfb9-499d-a476-05885d4ab2ea", + "control-id": "cis_rhel10_1-5.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sysctl_fs_protected_hardlinks" } ] }, { - "uuid": "5365b4bf-1a2a-4721-aea8-12b58485f413", - "control-id": "cis_rhel10_2-2.1", + "uuid": "0c897233-0f1c-48a7-8a8b-8b89128fc022", + "control-id": "cis_rhel10_1-5.4", "description": "REPLACE_ME", "props": [ { @@ -17826,71 +17025,69 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_ftp_removed" + "value": "sysctl_fs_suid_dumpable" } ] }, { - "uuid": "4fa84dc8-5ca5-4244-9018-a4eae8002d7f", - "control-id": "cis_rhel10_2-2.3", + "uuid": "66c95b06-23ce-4d6b-b78e-c8deee98955a", + "control-id": "cis_rhel10_1-6.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "configure_crypto_policy" } ] }, { - "uuid": "84c23927-1729-4eab-b80f-fc9b8ccf1d72", - "control-id": "cis_rhel10_2-2.4", + "uuid": "b374768d-35eb-47c6-8593-5f15eea5e6ad", + "control-id": "cis_rhel10_1-6.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_telnet_removed" + "value": "alternative", + "remarks": "It is necessary a new rule to ensure a module disabling sha1 in\n/etc/crypto-policies/policies/modules/ so it can be used by update-crypto-policies command." } ] }, { - "uuid": "627318bb-9b9d-4d17-8b47-f3724548181d", - "control-id": "cis_rhel10_2-2.5", + "uuid": "b0810482-ccd9-4847-9f9b-2f784758b109", + "control-id": "cis_rhel10_1-6.3", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_tftp_removed" + "value": "alternative", + "remarks": "It is necessary a new rule to ensure a module disabling weak MACs in\n/etc/crypto-policies/policies/modules/ so it can be used by update-crypto-policies command." } ] }, { - "uuid": "ad26e812-e136-4995-8add-931f450dc15e", - "control-id": "cis_rhel10_2-3.1", + "uuid": "505053e2-6c94-4ffa-b331-c9e7e222e712", + "control-id": "cis_rhel10_1-6.4", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "alternative", + "remarks": "It is necessary a new rule to ensure a module disabling CBC in\n/etc/crypto-policies/policies/modules/ so it can be used by update-crypto-policies command." } ] }, { - "uuid": "c631bf80-541a-4234-a5bb-633ca2604c51", - "control-id": "cis_rhel10_2-3.2", + "uuid": "5e2ccf9a-4a6d-4609-ae8b-3e7730720c52", + "control-id": "cis_rhel10_1-7.1", "description": "REPLACE_ME", "props": [ { @@ -17901,13 +17098,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "chronyd_specify_remote_server" + "value": "banner_etc_motd_cis" } ] }, { - "uuid": "f2005f46-e618-44d4-9f85-b272b2a50656", - "control-id": "cis_rhel10_2-3.3", + "uuid": "082a55de-3dd0-46e0-ab2d-8dd57efd833e", + "control-id": "cis_rhel10_1-7.2", "description": "REPLACE_ME", "props": [ { @@ -17918,13 +17115,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "chronyd_run_as_chrony_user" + "value": "banner_etc_issue_cis" } ] }, { - "uuid": "362a69f8-0a6e-4895-95ad-25ce4af47a58", - "control-id": "cis_rhel10_2-4.1.1", + "uuid": "2fe66c97-2e1c-4cde-9295-a88de00bad3a", + "control-id": "cis_rhel10_1-7.3", "description": "REPLACE_ME", "props": [ { @@ -17935,18 +17132,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_cron_installed" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_crond_enabled" + "value": "banner_etc_issue_net_cis" } ] }, { - "uuid": "48b260ef-7d91-46fd-bdb2-5213c6759eeb", - "control-id": "cis_rhel10_2-4.1.2", + "uuid": "490e0d22-4da3-4fa8-b998-62534301b123", + "control-id": "cis_rhel10_1-7.4", "description": "REPLACE_ME", "props": [ { @@ -17957,23 +17149,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_crontab" + "value": "file_groupowner_etc_motd" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_crontab" + "value": "file_owner_etc_motd" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_crontab" + "value": "file_permissions_etc_motd" } ] }, { - "uuid": "aeabe401-f1e7-4c0c-822d-92e1b70e4c83", - "control-id": "cis_rhel10_2-4.1.3", + "uuid": "149a2d9c-fbb4-41fa-a8df-eb7d93bf1f81", + "control-id": "cis_rhel10_1-7.5", "description": "REPLACE_ME", "props": [ { @@ -17984,23 +17176,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_hourly" + "value": "file_groupowner_etc_issue" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_hourly" + "value": "file_owner_etc_issue" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_hourly" + "value": "file_permissions_etc_issue" } ] }, { - "uuid": "1ff01fd2-0cb4-4eaa-9db2-82cd03a8962b", - "control-id": "cis_rhel10_2-4.1.4", + "uuid": "57011bc1-a889-4743-86e7-1133d901d54e", + "control-id": "cis_rhel10_1-7.6", "description": "REPLACE_ME", "props": [ { @@ -18011,23 +17203,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_daily" + "value": "file_groupowner_etc_issue_net" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_daily" + "value": "file_owner_etc_issue_net" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_daily" + "value": "file_permissions_etc_issue_net" } ] }, { - "uuid": "8da26181-5553-4a2c-92cf-bb6c39f8dc3f", - "control-id": "cis_rhel10_2-4.1.5", + "uuid": "d5e090b4-64a0-4cdc-a3c4-db7b45544334", + "control-id": "cis_rhel10_1-8.2", "description": "REPLACE_ME", "props": [ { @@ -18038,23 +17230,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_weekly" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_weekly" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_weekly" + "value": "dconf_gnome_disable_user_list" } ] }, { - "uuid": "c60e5de9-8f6a-497d-a2c8-572525814f85", - "control-id": "cis_rhel10_2-4.1.6", + "uuid": "79864325-fd15-4503-aa32-3c2e452522d9", + "control-id": "cis_rhel10_1-8.3", "description": "REPLACE_ME", "props": [ { @@ -18065,23 +17247,28 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_monthly" + "value": "dconf_gnome_screensaver_idle_delay" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_monthly" + "value": "dconf_gnome_screensaver_lock_delay" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_monthly" + "value": "dconf_gnome_session_idle_user_locks" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "dconf_gnome_screensaver_user_locks" } ] }, { - "uuid": "e515ed5e-7e57-4abd-b1bb-b8f2c8848ec9", - "control-id": "cis_rhel10_2-4.1.7", + "uuid": "d366e990-bbaa-45e1-8dc3-3a34968ff305", + "control-id": "cis_rhel10_1-8.5", "description": "REPLACE_ME", "props": [ { @@ -18092,23 +17279,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_d" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_d" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_d" + "value": "dconf_gnome_disable_autorun" } ] }, { - "uuid": "d8e8f6ea-3d2d-4a0b-92a0-0e893a8e7e6e", - "control-id": "cis_rhel10_2-4.1.8", + "uuid": "b192a786-596b-4eaf-87c7-2227c9fd1741", + "control-id": "cis_rhel10_2-1.4", "description": "REPLACE_ME", "props": [ { @@ -18119,78 +17296,47 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_cron_deny_not_exist" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_cron_allow_exists" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_allow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_allow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_allow" + "value": "package_kea_removed" } ] }, { - "uuid": "65b661b0-eaf6-4c5e-a490-b6753fc7b777", - "control-id": "cis_rhel10_2-4.2.1", - "description": "It is necessary to create a rule to ensure the existence of at.allow.\nfile_cron_allow_exists can be used as reference for a new templated rule.", + "uuid": "853b2128-8338-4db9-9caa-cd691c4d1a8a", + "control-id": "cis_rhel10_2-1.5", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_at_deny_not_exist" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_at_allow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_at_allow" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_at_allow" + "value": "package_bind_removed" } ] }, { - "uuid": "2420c214-cc4f-4200-9e42-32d2ac0821eb", - "control-id": "cis_rhel10_3-1.1", + "uuid": "a9ec5de5-25b8-49f1-b47d-86124d25be2c", + "control-id": "cis_rhel10_2-1.6", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "package_dnsmasq_removed" } ] }, { - "uuid": "ff7e7256-b851-4e1b-ab41-011c4afcd5af", - "control-id": "cis_rhel10_3-3.1", + "uuid": "ccb66d2c-fb00-44ef-826c-e9794a195526", + "control-id": "cis_rhel10_2-1.7", "description": "REPLACE_ME", "props": [ { @@ -18201,18 +17347,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_ip_forward" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_forwarding" + "value": "package_vsftpd_removed" } ] }, { - "uuid": "7a85e195-e034-4030-bc14-42a4d664a5d3", - "control-id": "cis_rhel10_3-3.2", + "uuid": "36e60cf9-a074-4531-ab7a-bfe52de04ff1", + "control-id": "cis_rhel10_2-1.8", "description": "REPLACE_ME", "props": [ { @@ -18223,19 +17364,19 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_send_redirects" + "value": "package_dovecot_removed" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_send_redirects" + "value": "package_cyrus-imapd_removed" } ] }, { - "uuid": "466332fa-e753-47c3-a05e-71c9bdd028f6", - "control-id": "cis_rhel10_3-3.3", - "description": "REPLACE_ME", + "uuid": "3534b742-218f-46c8-8176-11f07b3dbc53", + "control-id": "cis_rhel10_2-1.9", + "description": "Many of the libvirt packages used by Enterprise Linux virtualization are dependent on the\nnfs-utils package.", "props": [ { "name": "implementation-status", @@ -18245,13 +17386,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses" + "value": "service_nfs_disabled" } ] }, { - "uuid": "5c853820-f8c3-44da-a380-192387a91f40", - "control-id": "cis_rhel10_3-3.4", + "uuid": "420805ed-d59b-4e7f-8411-122538662c91", + "control-id": "cis_rhel10_2-1.12", "description": "REPLACE_ME", "props": [ { @@ -18262,13 +17403,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts" + "value": "package_rsync_removed" } ] }, { - "uuid": "594b548f-12d1-475a-8f11-0464803efeff", - "control-id": "cis_rhel10_3-3.5", + "uuid": "d68f3e45-1295-4b5b-ab25-791a487d3d03", + "control-id": "cis_rhel10_2-1.13", "description": "REPLACE_ME", "props": [ { @@ -18279,28 +17420,30 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_accept_redirects" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_accept_redirects" - }, + "value": "package_samba_removed" + } + ] + }, + { + "uuid": "afb05440-da93-47b8-a551-7e9910333cb1", + "control-id": "cis_rhel10_2-1.14", + "description": "REPLACE_ME", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_redirects" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_redirects" + "value": "package_net-snmp_removed" } ] }, { - "uuid": "fe05a19f-2075-4312-8ea6-9b8a58cf5cc4", - "control-id": "cis_rhel10_3-3.6", + "uuid": "c6bcb5f2-44ac-4a06-9eb3-95e12cccffe1", + "control-id": "cis_rhel10_2-1.15", "description": "REPLACE_ME", "props": [ { @@ -18311,18 +17454,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_secure_redirects" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_secure_redirects" + "value": "package_telnet-server_removed" } ] }, { - "uuid": "a00762b1-495c-493e-be49-336824152c35", - "control-id": "cis_rhel10_3-3.7", + "uuid": "e0bef41e-d9d3-4962-9fdc-13e2f590cc0a", + "control-id": "cis_rhel10_2-1.16", "description": "REPLACE_ME", "props": [ { @@ -18333,18 +17471,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_rp_filter" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_rp_filter" + "value": "package_tftp-server_removed" } ] }, { - "uuid": "fb5fafc1-db22-4831-bacb-bc3a72b1554f", - "control-id": "cis_rhel10_3-3.8", + "uuid": "e3223647-4948-4a1c-b43d-a6bf035b84b9", + "control-id": "cis_rhel10_2-1.17", "description": "REPLACE_ME", "props": [ { @@ -18355,67 +17488,70 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_accept_source_route" - }, + "value": "package_squid_removed" + } + ] + }, + { + "uuid": "949be886-aca1-42a6-a07a-73fafe848f09", + "control-id": "cis_rhel10_2-1.18", + "description": "REPLACE_ME", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_accept_source_route" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_source_route" + "value": "package_httpd_removed" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_source_route" + "value": "package_nginx_removed" } ] }, { - "uuid": "4869b820-53e8-4898-8eee-86075b7da0e8", - "control-id": "cis_rhel10_3-3.9", - "description": "REPLACE_ME", + "uuid": "e47054ac-2e0f-48ae-a0a7-5cbcd43fc798", + "control-id": "cis_rhel10_2-1.21", + "description": "The rule has_nonlocal_mta currently checks for services listening only on port 25,\nbut the policy checks also for ports 465 and 587", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "partial" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_log_martians" + "value": "postfix_network_listening_disabled" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_log_martians" + "value": "has_nonlocal_mta" } ] }, { - "uuid": "b888ad4a-4852-4960-96fe-0fc9e1c4b591", - "control-id": "cis_rhel10_3-3.10", + "uuid": "53e5054e-df80-4a53-bb9e-925fca032e6f", + "control-id": "cis_rhel10_2-1.22", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_tcp_syncookies" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "11f67e7f-411b-4997-a2b9-2ad503799788", - "control-id": "cis_rhel10_3-3.11", + "uuid": "e02a1925-8c57-4ba1-866d-4a18e594440d", + "control-id": "cis_rhel10_2-2.1", "description": "REPLACE_ME", "props": [ { @@ -18426,18 +17562,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_ra" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_ra" + "value": "package_ftp_removed" } ] }, { - "uuid": "a56e225c-d9ee-4ff5-bbcf-5eccd6ad994f", - "control-id": "cis_rhel10_4-1.1", + "uuid": "1173d08d-8fe0-4875-a584-8de0192a306e", + "control-id": "cis_rhel10_2-2.3", "description": "REPLACE_ME", "props": [ { @@ -18448,13 +17579,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_nftables_installed" + "value": "package_telnet_removed" } ] }, { - "uuid": "cdfd4c7c-071a-466a-8fca-cb5b1463ccd7", - "control-id": "cis_rhel10_4-1.2", + "uuid": "90f405a0-0ef5-43d0-9c34-067050083586", + "control-id": "cis_rhel10_2-2.4", "description": "REPLACE_ME", "props": [ { @@ -18465,36 +17596,25 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_firewalld_enabled" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_firewalld_installed" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_nftables_disabled" + "value": "package_tftp_removed" } ] }, { - "uuid": "c0483435-a69d-4ab8-bd04-f5f3f565627f", - "control-id": "cis_rhel10_4-2.1", + "uuid": "052228ed-9473-49aa-acec-ea9a644928c1", + "control-id": "cis_rhel10_2-3.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "implemented" } ] }, { - "uuid": "d3f2c8eb-79a7-4e1b-9d20-8a0a2911f3ba", - "control-id": "cis_rhel10_4-2.2", + "uuid": "d81649ca-3b8c-428a-a686-6979e301064e", + "control-id": "cis_rhel10_2-3.2", "description": "REPLACE_ME", "props": [ { @@ -18505,67 +17625,52 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "firewalld_loopback_traffic_trusted" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "firewalld_loopback_traffic_restricted" + "value": "chronyd_specify_remote_server" } ] }, { - "uuid": "ec079927-7fea-43ab-8047-2e29d3f97637", - "control-id": "cis_rhel10_4-3.1", - "description": "RHEL systems use firewalld for firewall management. Although nftables is the default\nback-end for firewalld, it is not recommended to use nftables directly when firewalld\nis in use. When using firewalld the base chains are installed by default.", + "uuid": "4bc891c5-f9ad-4a06-8105-dc832e1a9ca4", + "control-id": "cis_rhel10_2-3.3", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - } - ] - }, - { - "uuid": "549a22ef-25ed-4bb4-bec2-78aa1bf443c1", - "control-id": "cis_rhel10_4-3.2", - "description": "REPLACE_ME", - "props": [ + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "chronyd_run_as_chrony_user" } ] }, { - "uuid": "10711c76-7219-4ec2-91a6-4b51f839c88c", - "control-id": "cis_rhel10_4-3.3", - "description": "RHEL systems use firewalld for firewall management. Although nftables is the default\nback-end for firewalld, it is not recommended to use nftables directly when firewalld\nis in use.", + "uuid": "ba768e8f-86c3-4e04-8fef-cead51a9900b", + "control-id": "cis_rhel10_2-4.1.1", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - } - ] - }, - { - "uuid": "315ce412-5002-457e-aad0-0ecb92e3eafb", - "control-id": "cis_rhel10_4-3.4", - "description": "RHEL systems use firewalld for firewall management. Although nftables is the default\nback-end for firewalld, it is not recommended to use nftables directly when firewalld\nis in use.", - "props": [ + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "package_cron_installed" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "service_crond_enabled" } ] }, { - "uuid": "61b45c24-0f34-44b0-a585-fdcaf7bc6f70", - "control-id": "cis_rhel10_5-1.1", + "uuid": "89930cde-8e30-429b-b4bb-489eb8b5b341", + "control-id": "cis_rhel10_2-4.1.2", "description": "REPLACE_ME", "props": [ { @@ -18576,23 +17681,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_sshd_config" + "value": "file_groupowner_crontab" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_sshd_config" + "value": "file_owner_crontab" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_config" + "value": "file_permissions_crontab" } ] }, { - "uuid": "dff53220-aab7-4eb4-b621-57a1010dd810", - "control-id": "cis_rhel10_5-1.2", + "uuid": "2ea423e6-1fcc-4b75-a9c5-35ecd0e25403", + "control-id": "cis_rhel10_2-4.1.3", "description": "REPLACE_ME", "props": [ { @@ -18603,23 +17708,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_private_key" + "value": "file_groupowner_cron_hourly" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_private_key" + "value": "file_owner_cron_hourly" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_sshd_private_key" + "value": "file_permissions_cron_hourly" } ] }, { - "uuid": "7e0a1d35-0b78-4cb9-8eee-8f61598a610d", - "control-id": "cis_rhel10_5-1.3", + "uuid": "56c7cdf8-60c3-4ef8-a9ff-2cb4f2991ab3", + "control-id": "cis_rhel10_2-4.1.4", "description": "REPLACE_ME", "props": [ { @@ -18630,72 +17735,90 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_pub_key" + "value": "file_groupowner_cron_daily" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_pub_key" + "value": "file_owner_cron_daily" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_sshd_pub_key" + "value": "file_permissions_cron_daily" } ] }, { - "uuid": "9a27ac17-f390-4e51-a63b-51d59b2f7098", - "control-id": "cis_rhel10_5-1.4", + "uuid": "ca20ec72-7736-4e7f-b335-c1e8e6159c99", + "control-id": "cis_rhel10_2-4.1.5", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_groupowner_cron_weekly" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_owner_cron_weekly" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_cron_weekly" } ] }, { - "uuid": "6b3d6edf-af8a-40a1-bb82-dad5752a326f", - "control-id": "cis_rhel10_5-1.5", + "uuid": "ff389e4a-a50a-405b-84bf-066441305f09", + "control-id": "cis_rhel10_2-4.1.6", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_kex" + "value": "file_groupowner_cron_monthly" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_owner_cron_monthly" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_cron_monthly" } ] }, { - "uuid": "9e25bd40-e198-439f-b66f-5c50d497abe6", - "control-id": "cis_rhel10_5-1.6", + "uuid": "96f8ddf8-c989-488e-9f53-58c346642e7e", + "control-id": "cis_rhel10_2-4.1.7", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "alternative", - "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_macs" + "remarks": "REPLACE_ME" } ] }, { - "uuid": "acd43bc6-9d1e-4e8a-8a5e-0efc6be31f49", - "control-id": "cis_rhel10_5-1.7", + "uuid": "9c5a6e9a-5c17-4db7-b5cb-979f8d9f1423", + "control-id": "cis_rhel10_2-4.1.8", "description": "REPLACE_ME", "props": [ { @@ -18706,65 +17829,68 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_limit_user_access" - } - ] - }, - { - "uuid": "3d084e67-9ffa-4aaf-a5c8-a72de169ec38", - "control-id": "cis_rhel10_5-1.8", - "description": "REPLACE_ME", - "props": [ + "value": "file_groupowner_cron_d" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "file_owner_cron_d" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_enable_warning_banner_net" + "value": "file_permissions_cron_d" } ] }, { - "uuid": "c212177f-96c1-48bb-a4be-45c484087bf1", - "control-id": "cis_rhel10_5-1.9", - "description": "The requirement gives an example of 45 seconds, but is flexible about the values. It is only\nnecessary to ensure there is a timeout configured in alignment to the site policy.", + "uuid": "9db916b5-4418-4240-9979-68fa46b5b45e", + "control-id": "cis_rhel10_2-4.2.1", + "description": "It is necessary to create a rule to ensure the existence of at.allow.\nfile_cron_allow_exists can be used as reference for a new templated rule.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "partial" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_idle_timeout" + "value": "file_at_deny_not_exist" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_keepalive" + "value": "file_groupowner_at_allow" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_owner_at_allow" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_at_allow" } ] }, { - "uuid": "45f728b0-d383-4c98-96ba-b497eb03f59b", - "control-id": "cis_rhel10_5-1.10", + "uuid": "d5e335a4-e6b3-4a3d-b20f-f47a27066f2e", + "control-id": "cis_rhel10_3-1.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "alternative", - "remarks": "New templated rule is necessary for \"disableforwarding\" option." + "remarks": "REPLACE_ME" } ] }, { - "uuid": "ed57e34c-031f-472e-bab9-31dfa2f2d9da", - "control-id": "cis_rhel10_5-1.11", + "uuid": "fbe48bee-1fb1-43de-87da-2031ba8e1d74", + "control-id": "cis_rhel10_4-1.1", "description": "REPLACE_ME", "props": [ { @@ -18775,30 +17901,26 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_gssapi_auth" + "value": "package_firewalld_installed" } ] }, { - "uuid": "fc83f136-8975-4fe4-8bad-f25bd8e6336c", - "control-id": "cis_rhel10_5-1.12", + "uuid": "1527ed8b-4680-427e-8a08-4e1c5f560a36", + "control-id": "cis_rhel10_4-1.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "disable_host_auth" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "b7fd054f-3288-4285-b62d-775e4b342d7f", - "control-id": "cis_rhel10_5-1.13", + "uuid": "2f77cf7f-1dfe-41a4-83b0-928c0b9f89fc", + "control-id": "cis_rhel10_5-1.1", "description": "REPLACE_ME", "props": [ { @@ -18809,31 +17931,24 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_rhosts" - } - ] - }, - { - "uuid": "8313733a-226f-430b-a6e6-187a190575d7", - "control-id": "cis_rhel10_5-1.14", - "description": "REPLACE_ME", - "props": [ + "value": "file_groupowner_sshd_config" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "file_owner_sshd_config" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_login_grace_time" + "value": "file_permissions_sshd_config" } ] }, { - "uuid": "a91300a6-5a60-4a5d-a6f6-71a37713ca82", - "control-id": "cis_rhel10_5-1.15", - "description": "The CIS benchmark is not opinionated about which loglevel is selected here. Here, this\nprofile uses VERBOSE by default, as it allows for the capture of login and logout activity\nas well as key fingerprints.", + "uuid": "c527fd41-28bf-4d48-9cbb-75e654bb9ce1", + "control-id": "cis_rhel10_5-1.2", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -18843,30 +17958,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_loglevel_verbose" - } - ] - }, - { - "uuid": "acdb9588-5c8e-43a6-9973-9553e84e48a6", - "control-id": "cis_rhel10_5-1.16", - "description": "REPLACE_ME", - "props": [ + "value": "file_groupownership_sshd_private_key" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "file_ownership_sshd_private_key" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_max_auth_tries" + "value": "file_permissions_sshd_private_key" } ] }, { - "uuid": "5995f4e9-4c54-4fbc-9e7e-63765ed36961", - "control-id": "cis_rhel10_5-1.17", + "uuid": "dd69ef22-7742-4e36-a1f5-88d156feb34c", + "control-id": "cis_rhel10_5-1.3", "description": "REPLACE_ME", "props": [ { @@ -18877,30 +17985,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_maxstartups" - } - ] - }, - { - "uuid": "df60438f-ccde-4de4-812b-a8c356891ba8", - "control-id": "cis_rhel10_5-1.18", - "description": "REPLACE_ME", - "props": [ + "value": "file_groupownership_sshd_pub_key" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "file_ownership_sshd_pub_key" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_max_sessions" + "value": "file_permissions_sshd_pub_key" } ] }, { - "uuid": "7b856f04-f0d8-4545-8731-1adb51ba57e5", - "control-id": "cis_rhel10_5-1.19", + "uuid": "75e9e6a5-2c48-4c65-bad3-076f7e8956b6", + "control-id": "cis_rhel10_5-1.4", "description": "REPLACE_ME", "props": [ { @@ -18911,13 +18012,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_empty_passwords" + "value": "sshd_limit_user_access" } ] }, { - "uuid": "e1935183-99f2-4322-9fed-c9df3e1ec5b8", - "control-id": "cis_rhel10_5-1.20", + "uuid": "b5f1c56d-b388-45ac-8b52-cfea21d3c2b2", + "control-id": "cis_rhel10_5-1.5", "description": "REPLACE_ME", "props": [ { @@ -18928,31 +18029,26 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_root_login" + "value": "sshd_enable_warning_banner_net" } ] }, { - "uuid": "434c039f-9c20-4080-9368-37c09e515919", - "control-id": "cis_rhel10_5-1.21", - "description": "REPLACE_ME", + "uuid": "2b51a75f-c737-41a1-ba73-2ca1f8f643fb", + "control-id": "cis_rhel10_5-1.6", + "description": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_do_not_permit_user_env" } ] }, { - "uuid": "310a8141-05f9-4348-860a-ef8284af2f43", - "control-id": "cis_rhel10_5-1.22", - "description": "REPLACE_ME", + "uuid": "67569e3a-e5ca-4f8e-b214-99ce7c618582", + "control-id": "cis_rhel10_5-1.7", + "description": "The requirement gives an example of 45 seconds, but is flexible about the values. It is only\nnecessary to ensure there is a timeout configured in alignment to the site policy.", "props": [ { "name": "implementation-status", @@ -18962,13 +18058,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_enable_pam" + "value": "sshd_set_idle_timeout" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_set_keepalive" } ] }, { - "uuid": "74b73947-0fd3-4a0d-ae32-c41cfe5b4e76", - "control-id": "cis_rhel10_5-2.1", + "uuid": "490eb97d-045a-42cd-8c18-dd1942297b9c", + "control-id": "cis_rhel10_5-1.8", "description": "REPLACE_ME", "props": [ { @@ -18979,13 +18080,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_sudo_installed" + "value": "sshd_disable_forwarding" } ] }, { - "uuid": "98d5afcf-10e5-4166-9f9f-acac7093f206", - "control-id": "cis_rhel10_5-2.2", + "uuid": "25a2135e-d133-4a16-b30b-8a2534da2b29", + "control-id": "cis_rhel10_5-1.9", "description": "REPLACE_ME", "props": [ { @@ -18996,13 +18097,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_add_use_pty" + "value": "sshd_disable_gssapi_auth" } ] }, { - "uuid": "69f7457c-7605-4cf6-9e47-b65c76a65d81", - "control-id": "cis_rhel10_5-2.3", + "uuid": "2f11004f-f5e3-4434-bebd-d3375bf78d70", + "control-id": "cis_rhel10_5-1.10", "description": "REPLACE_ME", "props": [ { @@ -19013,13 +18114,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_custom_logfile" + "value": "disable_host_auth" } ] }, { - "uuid": "9b86a93b-f41b-4dfe-9ab9-e0d7277e010e", - "control-id": "cis_rhel10_5-2.5", + "uuid": "ee3de947-2a8c-4f78-877c-2ae119edc466", + "control-id": "cis_rhel10_5-1.11", "description": "REPLACE_ME", "props": [ { @@ -19030,31 +18131,32 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_require_reauthentication" + "value": "sshd_disable_rhosts" } ] }, { - "uuid": "3ee05fe1-3313-4619-82d1-c4e6df444af3", - "control-id": "cis_rhel10_5-2.6", + "uuid": "077bb8a9-85ba-4e44-957d-ae0cc1a10a38", + "control-id": "cis_rhel10_5-1.12", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "alternative", + "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_require_reauthentication" + "value": "sshd_use_strong_kex" } ] }, { - "uuid": "025e97df-dd50-4f84-b993-aa683e0d8dee", - "control-id": "cis_rhel10_5-2.7", - "description": "Members of \"wheel\" or GID 0 groups are checked by default if the group option is not set for\npam_wheel.so module. The recommendation states the group should be empty to reinforce the\nuse of \"sudo\" for privileged access. Therefore, members of these groups should be manually\nchecked or a different group should be informed.", + "uuid": "419a9716-f78c-4fb5-a2d0-d66156870040", + "control-id": "cis_rhel10_5-1.13", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -19064,75 +18166,49 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "use_pam_wheel_group_for_su" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_pam_wheel_group_empty" + "value": "sshd_set_login_grace_time" } ] }, { - "uuid": "ca67cc28-f60d-472a-991b-5c75663023f8", - "control-id": "cis_rhel10_5-3.1.1", - "description": "REPLACE_ME", + "uuid": "ce4cbec0-bc49-4d8a-93e9-637d8ae73903", + "control-id": "cis_rhel10_5-1.14", + "description": "The CIS benchmark is not opinionated about which loglevel is selected here. Here, this\nprofile uses VERBOSE by default, as it allows for the capture of login and logout activity\nas well as key fingerprints.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary a new rule to ensure PAM package is updated." - } - ] - }, - { - "uuid": "087e02bc-9517-435b-a8e9-5845411e3991", - "control-id": "cis_rhel10_5-3.1.2", - "description": "REPLACE_ME", - "props": [ + "value": "implemented" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary a new rule to ensure authselect package is updated." + "value": "sshd_set_loglevel_verbose" } ] }, { - "uuid": "11d4c0ae-f677-4c60-8b26-e5c0ed9b3d55", - "control-id": "cis_rhel10_5-3.1.3", + "uuid": "254572bd-b18d-4c46-b7aa-d9fdab9c45fa", + "control-id": "cis_rhel10_5-1.15", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "alternative", - "remarks": "It is necessary a new rule to ensure libpwquality package is updated." + "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_pam_pwquality_installed" - } - ] - }, - { - "uuid": "54f899ab-e53b-4ed0-8b09-2d27c9492ff4", - "control-id": "cis_rhel10_5-3.2.1", - "description": "This requirement is hard to be automated without any specific requirement. The policy even\nstates that provided commands are examples, other custom settings might be in place and the\nsettings might be different depending on site policies. The other rules will already make\nsure there is a correct autheselect profile regardless of the existing settings. It is\nnecessary to better discuss with CIS Community.", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "sshd_use_strong_macs" } ] }, { - "uuid": "ccb2e652-eda1-480e-9404-ae88b893c5af", - "control-id": "cis_rhel10_5-3.2.2", - "description": "This requirement is also indirectly satisfied by the requirement 5.3.3.1.", + "uuid": "7b2afe57-ba73-44a4-9755-cb6134d039a6", + "control-id": "cis_rhel10_5-1.16", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -19142,54 +18218,47 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_password_auth" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_system_auth" + "value": "sshd_set_max_auth_tries" } ] }, { - "uuid": "d6e43107-e27b-48cf-82e9-2e9a4b3b1e3f", - "control-id": "cis_rhel10_5-3.2.3", - "description": "This requirement is also indirectly satisfied by the requirement 5.3.3.2.", + "uuid": "95ff1bc8-743b-4d89-a63c-8bff6a862278", + "control-id": "cis_rhel10_5-1.17", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_set_maxstartups" } ] }, { - "uuid": "a86e3f90-0bf7-4ec5-a2ee-226778365b7e", - "control-id": "cis_rhel10_5-3.2.4", - "description": "The module is properly enabled by the rules mentioned in related_rules.\nRequirements in 5.3.3.3 use these rules.", + "uuid": "46133b8b-46d3-4f85-8ce7-e170a433b864", + "control-id": "cis_rhel10_5-1.18", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - } - ] - }, - { - "uuid": "c4ff6123-04ca-41df-b1e4-b6d8f3fe762c", - "control-id": "cis_rhel10_5-3.2.5", - "description": "This module is always present by default. It is necessary to investigate if a new rule to\ncheck its existence needs to be created. But so far the rule no_empty_passwords, used in\n5.3.3.4 can ensure this requirement is attended.", - "props": [ + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "sshd_set_max_sessions" } ] }, { - "uuid": "f3260c50-ff95-488a-b002-b0e2e2ddb648", - "control-id": "cis_rhel10_5-3.3.1.1", + "uuid": "f85e5e67-fc5f-4548-9cb8-91eecf4b2e8a", + "control-id": "cis_rhel10_5-1.19", "description": "REPLACE_ME", "props": [ { @@ -19200,14 +18269,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_deny" + "value": "sshd_disable_empty_passwords" } ] }, { - "uuid": "ccfc6cfb-49c8-45db-8ceb-bb854bf8e6b8", - "control-id": "cis_rhel10_5-3.3.1.2", - "description": "The policy also accepts value 0, which means the locked accounts should be manually unlocked\nby an administrator. However, it also mentions that using value 0 can facilitate a DoS\nattack to legitimate users.", + "uuid": "1f502ffe-5029-4582-be79-192017488c53", + "control-id": "cis_rhel10_5-1.20", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -19217,13 +18286,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_unlock_time" + "value": "sshd_disable_root_login" } ] }, { - "uuid": "a7d3290c-236d-480a-b227-e10b068a167f", - "control-id": "cis_rhel10_5-3.3.2.1", + "uuid": "aa277f3a-574f-4ecc-a124-c84ff6f5c2d0", + "control-id": "cis_rhel10_5-1.21", "description": "REPLACE_ME", "props": [ { @@ -19234,13 +18303,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_difok" + "value": "sshd_do_not_permit_user_env" } ] }, { - "uuid": "6f00ad16-8ab0-488a-9c5b-a005ccb2ca13", - "control-id": "cis_rhel10_5-3.3.2.2", + "uuid": "e779e9be-6579-48b8-9aa6-d2569b7362ac", + "control-id": "cis_rhel10_5-1.22", "description": "REPLACE_ME", "props": [ { @@ -19251,14 +18320,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_minlen" + "value": "sshd_enable_pam" } ] }, { - "uuid": "9cd2c367-1333-4ad9-b7ab-b962eca8c108", - "control-id": "cis_rhel10_5-3.3.2.3", - "description": "This requirement is expected to be manual. However, in previous versions of the policy\nit was already automated the configuration of \"minclass\" option. This posture was kept for\nRHEL 9 in this new version. Rules related to other options are informed in related_rules.\nIn short, minclass=4 alone can achieve the same result achieved by the combination of the\nother 4 options mentioned in the policy.", + "uuid": "25d4ea21-e7de-4d73-a4a5-409d79ca6ae2", + "control-id": "cis_rhel10_5-2.1", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -19268,13 +18337,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_minclass" + "value": "package_sudo_installed" } ] }, { - "uuid": "9e0a31b2-8976-4839-9185-fb152c404127", - "control-id": "cis_rhel10_5-3.3.2.4", + "uuid": "9f0689ed-d3a7-4a08-8ff6-4c0cc156be8b", + "control-id": "cis_rhel10_5-2.2", "description": "REPLACE_ME", "props": [ { @@ -19285,26 +18354,30 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_maxrepeat" + "value": "sudo_add_use_pty" } ] }, { - "uuid": "8f2f1bb2-b276-42b5-b43b-b3d7ac01e33b", - "control-id": "cis_rhel10_5-3.3.2.5", + "uuid": "ee707c42-74c1-4868-a394-e00e88c1aa34", + "control-id": "cis_rhel10_5-2.3", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "planned", - "remarks": "A new templated rule and variable are necessary for the maxsequence option." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sudo_custom_logfile" } ] }, { - "uuid": "7771ed9b-0361-4751-b19f-085a24359d53", - "control-id": "cis_rhel10_5-3.3.2.6", + "uuid": "2af1e049-4792-4b04-85da-ed63ab10e9fe", + "control-id": "cis_rhel10_5-2.5", "description": "REPLACE_ME", "props": [ { @@ -19315,13 +18388,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_dictcheck" + "value": "sudo_require_authentication" } ] }, { - "uuid": "fcc3f6f2-9165-4656-a70a-ae6632e399fe", - "control-id": "cis_rhel10_5-3.3.2.7", + "uuid": "ae874c35-2ab3-4c39-93aa-bf9e7910ad13", + "control-id": "cis_rhel10_5-2.6", "description": "REPLACE_ME", "props": [ { @@ -19332,14 +18405,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_enforce_root" + "value": "sudo_require_reauthentication" } ] }, { - "uuid": "562f228a-538b-45fc-810e-f62a0c2337ae", - "control-id": "cis_rhel10_5-3.3.3.1", - "description": "Although mentioned in the section 5.3.3.3, there is no explicit requirement to configure\nretry option of pam_pwhistory. If come in the future, the rule accounts_password_pam_retry\ncan be used.", + "uuid": "1309ff8a-d15b-4b32-bf79-3b4f8907f224", + "control-id": "cis_rhel10_5-2.7", + "description": "Members of \"wheel\" or GID 0 groups are checked by default if the group option is not set for\npam_wheel.so module. The recommendation states the group should be empty to reinforce the\nuse of \"sudo\" for privileged access. Therefore, members of these groups should be manually\nchecked or a different group should be informed.", "props": [ { "name": "implementation-status", @@ -19349,32 +18422,19 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_pwhistory_remember_password_auth" + "value": "use_pam_wheel_group_for_su" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_pwhistory_remember_system_auth" - } - ] - }, - { - "uuid": "caa40064-049a-420e-9437-fc271c4fcb1e", - "control-id": "cis_rhel10_5-3.3.3.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "planned", - "remarks": "A new rule needs to be created to check and remediate the enforce_for_root option in\n/etc/security/pwhistory.conf. accounts_password_pam_enforce_root can be used as reference." + "value": "ensure_pam_wheel_group_empty" } ] }, { - "uuid": "d36f6f08-8ea4-4ef4-8b0b-0d0862de7988", - "control-id": "cis_rhel10_5-3.3.3.3", - "description": "In RHEL 9 pam_pwhistory is enabled via authselect feature, as required in 5.3.2.4. The\nfeature automatically set \"use_authok\" option. In any case, we don't have a rule to check\nthis option specifically.", + "uuid": "ce37d911-797f-42fe-815b-f74dabfc748e", + "control-id": "cis_rhel10_5-3.1.1", + "description": "This requirement is hard to be automated without any specific requirement. The policy even\nstates that provided commands are examples, other custom settings might be in place and the\nsettings might be different depending on site policies. The other rules will already make\nsure there is a correct autheselect profile regardless of the existing settings. It is\nnecessary to better discuss with CIS Community.", "props": [ { "name": "implementation-status", @@ -19384,9 +18444,9 @@ ] }, { - "uuid": "54410e0f-c668-47be-96b9-2997b300cb40", - "control-id": "cis_rhel10_5-3.3.4.1", - "description": "The rule more specifically used in this requirement also satify the requirement 5.3.2.5.", + "uuid": "06f1c2fa-28e9-4663-b3e3-e52fd2795be7", + "control-id": "cis_rhel10_5-3.1.2", + "description": "This requirement is also indirectly satisfied by the requirement 5.3.2.1.", "props": [ { "name": "implementation-status", @@ -19396,27 +18456,19 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_empty_passwords" - } - ] - }, - { - "uuid": "3d24526c-e58d-4033-b359-b7698cab984c", - "control-id": "cis_rhel10_5-3.3.4.2", - "description": "REPLACE_ME", - "props": [ + "value": "account_password_pam_faillock_password_auth" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "Usage of pam_unix.so module together with \"remember\" option is deprecated and is not\nrecommened by this policy. Instead, it should be used remember option of pam_pwhistory\nmodule, as required in 5.3.3.3.1. See here for more details about pam_unix.so:\nhttps://bugzilla.redhat.com/show_bug.cgi?id=1778929\nA new rule needs to be created to remove the remember option from pam_unix module." + "value": "account_password_pam_faillock_system_auth" } ] }, { - "uuid": "b9cbe341-836a-49cd-9ad0-a6695163e165", - "control-id": "cis_rhel10_5-3.3.4.3", - "description": "Changes in logindefs mentioned in this requirement are more specifically covered by 5.4.1.4", + "uuid": "4533cdaa-ebb6-4697-be66-f5a9c846bddf", + "control-id": "cis_rhel10_5-3.1.3", + "description": "This requirement is also indirectly satisfied by the requirement 5.3.2.2.", "props": [ { "name": "implementation-status", @@ -19426,29 +18478,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_systemauth" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_passwordauth" - } - ] - }, - { - "uuid": "259e67af-f08c-42a9-9de5-76ac21359ae4", - "control-id": "cis_rhel10_5-3.3.4.4", - "description": "In RHEL 9 pam_unix is enabled by default in all authselect profiles already with the\nuse_authtok option set. In any case, we don't have a rule to check this option specifically,\nlike in 5.3.3.3.3.", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "package_pam_pwquality_installed" } ] }, { - "uuid": "3869f107-c150-43ee-923a-0ae325ccdfeb", + "uuid": "709190b1-0a47-4e56-859a-83aacb077dd1", "control-id": "cis_rhel10_5-4.1.1", "description": "REPLACE_ME", "props": [ @@ -19470,7 +18505,7 @@ ] }, { - "uuid": "976593a0-5e0a-4e78-b874-7181606cba58", + "uuid": "2bf0441b-fcb7-48e9-a3f4-f2f54cf097fe", "control-id": "cis_rhel10_5-4.1.3", "description": "REPLACE_ME", "props": [ @@ -19492,7 +18527,7 @@ ] }, { - "uuid": "1ef2ffde-66dd-4a43-87ad-8761e89cb898", + "uuid": "092102af-1d6a-4837-a719-bedd15266ed6", "control-id": "cis_rhel10_5-4.1.4", "description": "There's a \"new\" set of options in /etc/login.defs file to define the number of iterations\nperformed during the hashing process.", "props": [ @@ -19514,7 +18549,7 @@ ] }, { - "uuid": "c91ff03f-dd71-4474-87fc-9cb46ea3d068", + "uuid": "3be7ef11-fda0-49ed-879f-09497529622c", "control-id": "cis_rhel10_5-4.1.5", "description": "REPLACE_ME", "props": [ @@ -19536,7 +18571,7 @@ ] }, { - "uuid": "db7b472a-1668-4791-bc2c-e96d06aff74e", + "uuid": "40530563-b13a-4d10-a5f8-19ba49b3d596", "control-id": "cis_rhel10_5-4.1.6", "description": "REPLACE_ME", "props": [ @@ -19553,7 +18588,7 @@ ] }, { - "uuid": "23d227f9-e94b-44ac-9059-17f2275b4f5c", + "uuid": "5e196956-7687-4ccb-9092-f7564314a5ae", "control-id": "cis_rhel10_5-4.2.1", "description": "REPLACE_ME", "props": [ @@ -19570,7 +18605,7 @@ ] }, { - "uuid": "6f5e2cc1-498e-422d-9824-5b2e9c35b660", + "uuid": "b902773b-2e35-4674-b621-54e580f150fa", "control-id": "cis_rhel10_5-4.2.2", "description": "The rule confirms the primary group for root, but doesn't check if any other user are also\nusing GID 0. New rule is necessary.\nThere is assessment but no automated remediation for this rule and this sounds reasonable.", "props": [ @@ -19587,20 +18622,24 @@ ] }, { - "uuid": "0e9230fa-a4e3-4e3b-9f11-3453f6470eaf", + "uuid": "a3f93b44-782c-4b07-8220-c1e696ac1b15", "control-id": "cis_rhel10_5-4.2.3", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "New rule is necessary." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "groups_no_zero_gid_except_root" } ] }, { - "uuid": "9f75a79a-bb96-4d80-9a0c-75338bd023ef", + "uuid": "1675ac9f-fe4a-417f-9227-889dedb50249", "control-id": "cis_rhel10_5-4.2.4", "description": "REPLACE_ME", "props": [ @@ -19617,7 +18656,7 @@ ] }, { - "uuid": "4db2c590-7c72-4220-ae11-b0fa5a0fbc71", + "uuid": "4afff113-e768-4fa9-a630-f32314496865", "control-id": "cis_rhel10_5-4.2.5", "description": "REPLACE_ME", "props": [ @@ -19639,20 +18678,24 @@ ] }, { - "uuid": "be0b424b-08d6-4db7-9bdc-70b567294362", + "uuid": "23b04c26-6a3b-4a2f-aa20-b6bcae61881d", "control-id": "cis_rhel10_5-4.2.6", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "There is no rule to ensure umask in /root/.bash_profile and /root/.bashrc. A new rule have\nto be created. It can be based on accounts_umask_interactive_users." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_umask_root" } ] }, { - "uuid": "e0ef5abf-ac56-48e1-8c5d-300f151826fb", + "uuid": "49b45079-623e-490b-8028-5efb90cf00ef", "control-id": "cis_rhel10_5-4.2.7", "description": "REPLACE_ME", "props": [ @@ -19674,20 +18717,19 @@ ] }, { - "uuid": "39c774ee-af41-4e76-b30a-5d0d2d4cb46d", + "uuid": "36ace0e1-90b0-4275-9e41-a503ed16ec2f", "control-id": "cis_rhel10_5-4.2.8", - "description": "REPLACE_ME", + "description": "New rule is necessary.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "New rule is necessary." + "value": "implemented" } ] }, { - "uuid": "b110cde9-1ba2-4f1d-a626-d11c01c19551", + "uuid": "aa999c57-e296-44e5-a7df-2e52bc276081", "control-id": "cis_rhel10_5-4.3.2", "description": "REPLACE_ME", "props": [ @@ -19704,7 +18746,7 @@ ] }, { - "uuid": "635fc002-2dde-4d4f-b7c7-53a93b85832e", + "uuid": "ca2072bf-5967-4d2d-bc11-85f58c86accc", "control-id": "cis_rhel10_5-4.3.3", "description": "REPLACE_ME", "props": [ @@ -19731,7 +18773,7 @@ ] }, { - "uuid": "a980a010-31a5-47d0-bb7c-d788af4cfde0", + "uuid": "1b04c489-371d-418e-873a-fedb93b1b41d", "control-id": "cis_rhel10_6-1.1", "description": "REPLACE_ME", "props": [ @@ -19753,7 +18795,7 @@ ] }, { - "uuid": "79c5848d-c975-428f-a526-09ad91e7bf77", + "uuid": "2c9002ef-a992-4fcc-9d2e-82212e303dc5", "control-id": "cis_rhel10_6-1.2", "description": "REPLACE_ME", "props": [ @@ -19770,7 +18812,7 @@ ] }, { - "uuid": "b63635ff-7120-479e-a25e-d38d81e85410", + "uuid": "aeb12f31-2adc-4391-a8e4-7f10d8a79495", "control-id": "cis_rhel10_6-1.3", "description": "REPLACE_ME", "props": [ @@ -19787,7 +18829,7 @@ ] }, { - "uuid": "6ea9b463-6b5b-4aab-a03c-4832d61379dc", + "uuid": "49af29bc-78ab-40e5-8dbc-15f9473a45e3", "control-id": "cis_rhel10_6-2.1.1", "description": "REPLACE_ME", "props": [ @@ -19804,7 +18846,7 @@ ] }, { - "uuid": "88e9712d-bd1c-41f6-8c62-d3883d982f41", + "uuid": "22f54607-40b1-40f6-9cee-63fc161452a4", "control-id": "cis_rhel10_6-2.1.2", "description": "REPLACE_ME", "props": [ @@ -19817,7 +18859,7 @@ ] }, { - "uuid": "0b11fffc-1fd5-4cfc-963d-14e95bb7efdd", + "uuid": "9f035749-db28-436d-af00-67a2adeafd05", "control-id": "cis_rhel10_6-2.1.3", "description": "REPLACE_ME", "props": [ @@ -19830,7 +18872,7 @@ ] }, { - "uuid": "8649fa47-06f8-4428-8813-13dde8eb2b96", + "uuid": "e3fa9a05-1d27-4390-bca8-c12516a61588", "control-id": "cis_rhel10_6-2.1.4", "description": "REPLACE_ME", "props": [ @@ -19843,51 +18885,55 @@ ] }, { - "uuid": "40e2a99b-9c03-4adf-a702-c77e46813e26", - "control-id": "cis_rhel10_6-2.2.1.1", + "uuid": "b671b910-fd6b-4df8-8d04-bce2a9af4408", + "control-id": "cis_rhel10_6-2.2.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_systemd-journal-remote_installed" + "value": "alternative", + "remarks": "This rule conflicts with 6.2.3.3. More investigation is needed to properly solve this." } ] }, { - "uuid": "35cddcac-047e-440e-8c38-bbdc770af6a6", - "control-id": "cis_rhel10_6-2.2.1.2", + "uuid": "44b97e29-c00b-44ed-bc8e-765cf5850c21", + "control-id": "cis_rhel10_6-2.2.3", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "journald_compress" } ] }, { - "uuid": "ae82416c-a3ea-4f6f-999d-0f5165fad3e5", - "control-id": "cis_rhel10_6-2.2.1.3", + "uuid": "b04c50b5-7c6e-44c4-ae75-eaf02ff719c0", + "control-id": "cis_rhel10_6-2.2.4", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "New templated rule is necessary." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "journald_storage" } ] }, { - "uuid": "e0a8b40a-afb1-4d46-9b19-f33c032b21a4", - "control-id": "cis_rhel10_6-2.2.1.4", + "uuid": "d4e8afde-fc32-4736-9b97-5da934182ec4", + "control-id": "cis_rhel10_6-2.2.1.1", "description": "REPLACE_ME", "props": [ { @@ -19898,43 +18944,39 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "socket_systemd-journal-remote_disabled" + "value": "package_systemd-journal-remote_installed" } ] }, { - "uuid": "ae392687-02f9-4e04-8bbb-adb7c2162021", - "control-id": "cis_rhel10_6-2.2.2", + "uuid": "06990317-0ee4-4bb1-9fd5-3f8a3332adcf", + "control-id": "cis_rhel10_6-2.2.1.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "alternative", - "remarks": "This rule conflicts with 6.2.3.3. More investigation is needed to properly solve this." + "remarks": "REPLACE_ME" } ] }, { - "uuid": "f39cef44-3230-4e81-a73c-3139ad2d4a53", - "control-id": "cis_rhel10_6-2.2.3", + "uuid": "6f5c9d7f-dee0-4218-b6b4-5b8852336fb2", + "control-id": "cis_rhel10_6-2.2.1.3", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_compress" + "value": "alternative", + "remarks": "New templated rule is necessary." } ] }, { - "uuid": "fb5102b2-2047-4bcb-831b-e140b81d6960", - "control-id": "cis_rhel10_6-2.2.4", + "uuid": "7a006f33-a289-4677-8f09-f453f698ac48", + "control-id": "cis_rhel10_6-2.2.1.4", "description": "REPLACE_ME", "props": [ { @@ -19945,12 +18987,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_storage" + "value": "socket_systemd-journal-remote_disabled" } ] }, { - "uuid": "9eda7471-398f-4dde-b1fc-6db3363524f8", + "uuid": "eb1abea1-f398-48a9-a4ac-215369bf44e6", "control-id": "cis_rhel10_6-2.3.1", "description": "REPLACE_ME", "props": [ @@ -19962,7 +19004,7 @@ ] }, { - "uuid": "26dad814-9895-44ca-82d5-996093251e97", + "uuid": "4c829407-bfcc-4d1d-918c-2dd3f572e862", "control-id": "cis_rhel10_6-2.3.2", "description": "REPLACE_ME", "props": [ @@ -19974,7 +19016,7 @@ ] }, { - "uuid": "5f55eb6f-8243-4529-a651-b05f68de5093", + "uuid": "451a412d-07e8-4300-a120-0b023a55db20", "control-id": "cis_rhel10_6-2.3.3", "description": "REPLACE_ME", "props": [ @@ -19986,7 +19028,7 @@ ] }, { - "uuid": "b2a9d59a-fc5b-4791-8b8f-6bca74c9847a", + "uuid": "8facc780-a97a-4d4e-a956-240a4dbaeedb", "control-id": "cis_rhel10_6-2.3.4", "description": "REPLACE_ME", "props": [ @@ -19998,7 +19040,7 @@ ] }, { - "uuid": "0b836d34-ac07-493f-9ad5-a3a70b834839", + "uuid": "79ef13a9-32e0-4c31-89c3-53b09c55ef96", "control-id": "cis_rhel10_6-2.3.5", "description": "REPLACE_ME", "props": [ @@ -20011,7 +19053,7 @@ ] }, { - "uuid": "a7d340dc-1f45-414f-9e11-9c4f562ff75c", + "uuid": "c892faf0-cb2b-4f9f-abf4-999d2a808978", "control-id": "cis_rhel10_6-2.3.6", "description": "REPLACE_ME", "props": [ @@ -20024,7 +19066,7 @@ ] }, { - "uuid": "81449054-b96b-42f8-8bb1-1f58377b6986", + "uuid": "c179720a-d96b-4405-8481-9c6ba49cb5d8", "control-id": "cis_rhel10_6-2.3.7", "description": "REPLACE_ME", "props": [ @@ -20036,7 +19078,7 @@ ] }, { - "uuid": "22502845-a086-4de4-b299-9b4c86e755e3", + "uuid": "a9c509b9-263b-4399-b6e5-b1ad1688b57d", "control-id": "cis_rhel10_6-2.3.8", "description": "REPLACE_ME", "props": [ @@ -20049,7 +19091,7 @@ ] }, { - "uuid": "9cc2d404-6a16-4847-80e8-41aef7796eed", + "uuid": "3e8c213a-e74a-4961-a095-778ccca2723a", "control-id": "cis_rhel10_6-2.4.1", "description": "It is not harmful to run these rules even if rsyslog is not installed or active.", "props": [ @@ -20076,7 +19118,7 @@ ] }, { - "uuid": "6df59d17-2722-42cb-a539-c472ec62ec46", + "uuid": "aa6f25e8-ebda-4595-8c06-498b2a4d0fe0", "control-id": "cis_rhel10_7-1.1", "description": "REPLACE_ME", "props": [ @@ -20103,7 +19145,7 @@ ] }, { - "uuid": "d5234ba3-1e63-4e81-aef0-617e4ffb5cc6", + "uuid": "7788ecf8-bcca-4789-88e9-88110d4a73e9", "control-id": "cis_rhel10_7-1.2", "description": "REPLACE_ME", "props": [ @@ -20130,7 +19172,7 @@ ] }, { - "uuid": "f31c2d6c-d343-4d67-8590-b9730603f7e5", + "uuid": "84e4658b-1211-4543-90b3-ac061d495cba", "control-id": "cis_rhel10_7-1.3", "description": "REPLACE_ME", "props": [ @@ -20157,7 +19199,7 @@ ] }, { - "uuid": "78c8b19e-26a8-40bf-8d5d-fafc237f8e43", + "uuid": "4faf345f-284b-474c-96bb-508f2a52825a", "control-id": "cis_rhel10_7-1.4", "description": "REPLACE_ME", "props": [ @@ -20184,7 +19226,7 @@ ] }, { - "uuid": "407a909a-f565-4313-94c5-ae075a53051d", + "uuid": "a43f67ca-1c0a-440b-9ce8-90331c1f980b", "control-id": "cis_rhel10_7-1.5", "description": "REPLACE_ME", "props": [ @@ -20211,7 +19253,7 @@ ] }, { - "uuid": "5aab59ef-fa0c-4333-9b06-e5441baa6b72", + "uuid": "ba22f72d-7c61-4692-8edc-e6579a0c88af", "control-id": "cis_rhel10_7-1.6", "description": "REPLACE_ME", "props": [ @@ -20238,7 +19280,7 @@ ] }, { - "uuid": "ef2baccb-6bae-4208-8bdf-c5015fba9cde", + "uuid": "588c6f14-8594-479d-ba55-d2d4418539ed", "control-id": "cis_rhel10_7-1.7", "description": "REPLACE_ME", "props": [ @@ -20265,7 +19307,7 @@ ] }, { - "uuid": "17fc979b-94ff-4080-a1b1-a74f8cc9423a", + "uuid": "0271141b-0ae2-47f5-8e3a-538c8bf44432", "control-id": "cis_rhel10_7-1.8", "description": "REPLACE_ME", "props": [ @@ -20292,7 +19334,7 @@ ] }, { - "uuid": "30f93f32-800d-4899-8410-bb863147c100", + "uuid": "ad0ba13c-2984-47ca-80cd-7890f03abed6", "control-id": "cis_rhel10_7-1.9", "description": "REPLACE_ME", "props": [ @@ -20319,14 +19361,14 @@ ] }, { - "uuid": "d458ea56-9676-4b13-ae8c-0cb3578b4011", + "uuid": "7330340a-9681-471a-84d8-ecb25e6175e0", "control-id": "cis_rhel10_7-1.10", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "implemented" }, { "name": "Rule_Id", @@ -20336,7 +19378,7 @@ ] }, { - "uuid": "ba9198a7-a92f-4faa-9e11-a0eb14aa879f", + "uuid": "ce8c161c-acb2-4246-8b01-9fb429186074", "control-id": "cis_rhel10_7-1.11", "description": "REPLACE_ME", "props": [ @@ -20358,7 +19400,7 @@ ] }, { - "uuid": "928315e8-1fe5-4b46-9936-8ba39948c5e5", + "uuid": "a92f38cf-5d72-4247-b5ef-68258ac16959", "control-id": "cis_rhel10_7-1.12", "description": "REPLACE_ME", "props": [ @@ -20380,7 +19422,7 @@ ] }, { - "uuid": "04e01955-3899-41cd-a458-4698095c249f", + "uuid": "cc8eddab-6244-4c90-a54d-ecdefa67762c", "control-id": "cis_rhel10_7-1.13", "description": "REPLACE_ME", "props": [ @@ -20393,7 +19435,7 @@ ] }, { - "uuid": "5972a333-b140-4fea-9145-d2901f6286ce", + "uuid": "92d5d0c2-3caf-4ca4-9af6-c8df33eaaf29", "control-id": "cis_rhel10_7-2.1", "description": "REPLACE_ME", "props": [ @@ -20410,7 +19452,7 @@ ] }, { - "uuid": "fce1ddc3-6c2e-4432-9e62-fdbb20a19de6", + "uuid": "16059566-f590-4b27-b405-4931bf33ff25", "control-id": "cis_rhel10_7-2.2", "description": "REPLACE_ME", "props": [ @@ -20427,7 +19469,7 @@ ] }, { - "uuid": "d26befba-dc0b-4e1a-a0a0-558185d5e823", + "uuid": "b68c074d-2097-48d2-a503-fb3f0f7dd02a", "control-id": "cis_rhel10_7-2.3", "description": "REPLACE_ME", "props": [ @@ -20444,7 +19486,7 @@ ] }, { - "uuid": "42eab31e-6bbe-4a62-9f9f-9b7be62c3d2a", + "uuid": "67ec35f3-e92c-4aae-ac0e-9b0a387d5ae9", "control-id": "cis_rhel10_7-2.4", "description": "REPLACE_ME", "props": [ @@ -20461,7 +19503,7 @@ ] }, { - "uuid": "49bd7ce1-ea32-45a1-9168-7da62fa1ffe3", + "uuid": "15eefe88-17aa-4068-8fab-f89ee76668f9", "control-id": "cis_rhel10_7-2.5", "description": "REPLACE_ME", "props": [ @@ -20478,7 +19520,7 @@ ] }, { - "uuid": "4a2ae6aa-b12d-4166-8349-27232ba63142", + "uuid": "1371c3f9-20ab-4648-a549-ee3f33b21b5f", "control-id": "cis_rhel10_7-2.6", "description": "REPLACE_ME", "props": [ @@ -20495,7 +19537,7 @@ ] }, { - "uuid": "467825d6-6b97-458e-9456-a64d579a9eb7", + "uuid": "fd6ef12e-fc04-4ff8-8e01-041a32649aba", "control-id": "cis_rhel10_7-2.7", "description": "REPLACE_ME", "props": [ @@ -20512,7 +19554,7 @@ ] }, { - "uuid": "fa65b8ea-bd86-4b14-973a-33476979bb1a", + "uuid": "a4670ec2-9145-444a-a496-d6aa21526c27", "control-id": "cis_rhel10_7-2.8", "description": "REPLACE_ME", "props": [ @@ -20539,7 +19581,7 @@ ] }, { - "uuid": "6da1f158-0fb2-421b-b37a-f1041b2621a5", + "uuid": "e57fbef3-6492-46f2-add7-330eb6822f90", "control-id": "cis_rhel10_7-2.9", "description": "Missing a rule to check that .bash_history is mode 0600 or more restrictive.", "props": [ diff --git a/component-definitions/rhel10/rhel10-cis_rhel10-l2_server/component-definition.json b/component-definitions/rhel10/rhel10-cis_rhel10-l2_server/component-definition.json index 0bbaddb9e..d98973c2b 100644 --- a/component-definitions/rhel10/rhel10-cis_rhel10-l2_server/component-definition.json +++ b/component-definitions/rhel10/rhel10-cis_rhel10-l2_server/component-definition.json @@ -3,8 +3,8 @@ "uuid": "6531a0d9-efde-405d-ba52-aab8178414c4", "metadata": { "title": "Component definition for rhel10", - "last-modified": "2025-09-12T14:55:17.013645+08:00", - "version": "1.0", + "last-modified": "2025-09-16T19:14:29.769498+00:00", + "version": "1.1", "oscal-version": "1.1.3" }, "components": [ @@ -131,7 +131,7 @@ { "name": "Parameter_Value_Alternatives_5", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", + "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel10': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", "remarks": "rule_set_000" }, { @@ -149,7 +149,7 @@ { "name": "Parameter_Value_Alternatives_6", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", + "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel10': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", "remarks": "rule_set_000" }, { @@ -515,5343 +515,5625 @@ { "name": "Parameter_Id_27", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_account_disable_post_pw_expiration", + "value": "sysctl_net_ipv6_conf_default_forwarding_value", "remarks": "rule_set_000" }, { "name": "Parameter_Description_27", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The number of days to wait after a password expires, until the account will be permanently disabled.", + "value": "Toggle IPv6 default Forwarding", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_27", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'0': '0', 180: 180, 30: 30, 35: 35, 40: 40, 45: 45, 60: 60, 90: 90, 'default': 35}", + "value": "{'default': '0', 'disabled': '0', 'enabled': 1}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_28", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_maximum_age_login_defs", + "value": "var_account_disable_post_pw_expiration", "remarks": "rule_set_000" }, { "name": "Parameter_Description_28", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Maximum age of password in days", + "value": "The number of days to wait after a password expires, until the account will be permanently disabled.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_28", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{365: 365, 120: 120, 180: 180, 90: 90, 60: 60, 45: 45, 'default': 60}", + "value": "{'0': '0', 180: 180, 30: 30, 35: 35, 40: 40, 45: 45, 60: 60, 90: 90, 'default': 35}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_29", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_minimum_age_login_defs", + "value": "var_accounts_maximum_age_login_defs", "remarks": "rule_set_000" }, { "name": "Parameter_Description_29", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Minimum age of password in days", + "value": "Maximum age of password in days", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_29", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'0': '0', 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 'default': 7}", + "value": "{365: 365, 120: 120, 180: 180, 90: 90, 60: 60, 45: 45, 'default': 60}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_30", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_password_warn_age_login_defs", + "value": "var_accounts_minimum_age_login_defs", "remarks": "rule_set_000" }, { "name": "Parameter_Description_30", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The number of days' warning given before a password expires.", + "value": "Minimum age of password in days", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_30", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'0': '0', 14: 14, 10: 10, 7: 7, 'default': 7}", + "value": "{'0': '0', 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 'default': 7}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_31", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_passwords_pam_faillock_deny", + "value": "var_accounts_password_warn_age_login_defs", "remarks": "rule_set_000" }, { "name": "Parameter_Description_31", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Number of failed login attempts before account lockout", + "value": "The number of days' warning given before a password expires.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_31", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{10: 10, 3: 3, 4: 4, 5: 5, 6: 6, 8: 8, 'default': 3}", + "value": "{'0': '0', 14: 14, 10: 10, 7: 7, 'default': 7}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_32", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_passwords_pam_faillock_dir", + "value": "var_accounts_passwords_pam_faillock_deny", "remarks": "rule_set_000" }, { "name": "Parameter_Description_32", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The directory where the user files with the failure records are kept", + "value": "Number of failed login attempts before account lockout", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_32", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'ol8': '/var/log/faillock', 'default': '/var/log/faillock', 'run': '/var/run/faillock'}", + "value": "{10: 10, 3: 3, 4: 4, 5: 5, 6: 6, 8: 8, 'default': 3}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_33", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_passwords_pam_faillock_unlock_time", + "value": "var_accounts_passwords_pam_faillock_dir", "remarks": "rule_set_000" }, { "name": "Parameter_Description_33", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Seconds before automatic unlocking or permanently locking after excessive failed logins", + "value": "The directory where the user files with the failure records are kept", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_33", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{1800: 1800, 3600: 3600, 600: 600, 604800: 604800, 86400: 86400, 900: 900, 300: 300, 'default': 0, 'never': 0}", + "value": "{'ol8': '/var/log/faillock', 'default': '/var/log/faillock', 'run': '/var/run/faillock'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_34", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_tmout", + "value": "var_accounts_passwords_pam_faillock_unlock_time", "remarks": "rule_set_000" }, { "name": "Parameter_Description_34", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "In an interactive shell, the value is interpreted as the number of seconds to wait for input after issuing the primary prompt. Bash terminates after waiting for that number of seconds if input does not arrive.", + "value": "Seconds before automatic unlocking or permanently locking after excessive failed logins", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_34", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'30_min': 1800, '10_min': 600, '15_min': 900, '5_min': 300, 'default': 600}", + "value": "{1800: 1800, 3600: 3600, 600: 600, 604800: 604800, 86400: 86400, 900: 900, 300: 300, 'default': 0, 'never': 0}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_35", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_user_umask", + "value": "var_accounts_tmout", "remarks": "rule_set_000" }, { "name": "Parameter_Description_35", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enter default user umask", + "value": "In an interactive shell, the value is interpreted as the number of seconds to wait for input after issuing the primary prompt. Bash terminates after waiting for that number of seconds if input does not arrive.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_35", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'007': '007', '022': '022', '027': '027', '077': '077', 'default': '027'}", + "value": "{'30_min': 1800, '10_min': 600, '15_min': 900, '5_min': 300, 'default': 600}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_36", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_auditd_action_mail_acct", + "value": "var_accounts_user_umask", "remarks": "rule_set_000" }, { "name": "Parameter_Description_36", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The setting for action_mail_acct in /etc/audit/auditd.conf", + "value": "Enter default user umask", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_36", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'admin': 'admin', 'default': 'root', 'root': 'root'}", + "value": "{'007': '007', '022': '022', '027': '027', '077': '077', 'default': '027'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_auditd_admin_space_left_action", + "value": "var_auditd_action_mail_acct", "remarks": "rule_set_000" }, { "name": "Parameter_Description_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The setting for admin_space_left_action in /etc/audit/auditd.conf", + "value": "The setting for action_mail_acct in /etc/audit/auditd.conf", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt'}", + "value": "{'admin': 'admin', 'default': 'root', 'root': 'root'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_auditd_disk_error_action", + "value": "var_auditd_admin_space_left_action", "remarks": "rule_set_000" }, { "name": "Parameter_Description_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "'The setting for disk_error_action in /etc/audit/auditd.conf, if multiple values are allowed write them separated by pipes as in \"syslog|single|halt\", for remediations the first value will be taken'", + "value": "The setting for admin_space_left_action in /etc/audit/auditd.conf", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", + "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt', 'cis_rhel10': 'single|halt'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_auditd_disk_full_action", + "value": "var_auditd_disk_error_action", "remarks": "rule_set_000" }, { "name": "Parameter_Description_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "'The setting for disk_full_action in /etc/audit/auditd.conf, if multiple values are allowed write them separated by pipes as in \"syslog|single|halt\", for remediations the first value will be taken'", + "value": "'The setting for disk_error_action in /etc/audit/auditd.conf, if multiple values are allowed write them separated by pipes as in \"syslog|single|halt\", for remediations the first value will be taken'", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_rhel10': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_40", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_auditd_max_log_file", + "value": "var_auditd_disk_full_action", "remarks": "rule_set_000" }, { "name": "Parameter_Description_40", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The setting for max_log_file in /etc/audit/auditd.conf", + "value": "'The setting for disk_full_action in /etc/audit/auditd.conf, if multiple values are allowed write them separated by pipes as in \"syslog|single|halt\", for remediations the first value will be taken'", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_40", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{1: 1, 10: 10, 20: 20, 5: 5, 6: 6, 'default': 6}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_rhel10': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_41", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_auditd_max_log_file_action", + "value": "var_auditd_max_log_file", "remarks": "rule_set_000" }, { "name": "Parameter_Description_41", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The setting for max_log_file_action in /etc/audit/auditd.conf. The following options are available:
ignore - audit daemon does nothing.
syslog - audit daemon will issue a warning to syslog.
suspend - audit daemon will stop writing records to the disk.
rotate - audit daemon will rotate logs in the same convention used by logrotate.
keep_logs - similar to rotate but prevents audit logs to be overwritten. May trigger space_left_action if volume is full.", + "value": "The setting for max_log_file in /etc/audit/auditd.conf", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_41", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'rotate', 'keep_logs': 'keep_logs', 'rotate': 'rotate', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore'}", + "value": "{1: 1, 10: 10, 20: 20, 5: 5, 6: 6, 'default': 6}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_42", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_auditd_space_left_action", + "value": "var_auditd_max_log_file_action", "remarks": "rule_set_000" }, { "name": "Parameter_Description_42", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The setting for space_left_action in /etc/audit/auditd.conf", + "value": "The setting for max_log_file_action in /etc/audit/auditd.conf. The following options are available:
ignore - audit daemon does nothing.
syslog - audit daemon will issue a warning to syslog.
suspend - audit daemon will stop writing records to the disk.
rotate - audit daemon will rotate logs in the same convention used by logrotate.
keep_logs - similar to rotate but prevents audit logs to be overwritten. May trigger space_left_action if volume is full.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_42", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt'}", + "value": "{'default': 'rotate', 'keep_logs': 'keep_logs', 'rotate': 'rotate', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_43", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_authselect_profile", + "value": "var_auditd_space_left_action", "remarks": "rule_set_000" }, { "name": "Parameter_Description_43", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the authselect profile to select", + "value": "The setting for space_left_action in /etc/audit/auditd.conf", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_43", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'local': 'local', 'default': 'minimal', 'minimal': 'minimal', 'sssd': 'sssd'}", + "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt', 'cis_rhel10': 'email|exec|single|halt'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_44", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_multiple_time_servers", + "value": "var_authselect_profile", "remarks": "rule_set_000" }, { "name": "Parameter_Description_44", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The list of vendor-approved time servers", + "value": "Specify the authselect profile to select", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_44", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'generic': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'stig': '0.us.pool.ntp.mil', 'fedora': '0.fedora.pool.ntp.org,1.fedora.pool.ntp.org,2.fedora.pool.ntp.org,3.fedora.pool.ntp.org', 'rhel': '0.rhel.pool.ntp.org,1.rhel.pool.ntp.org,2.rhel.pool.ntp.org,3.rhel.pool.ntp.org', 'ol': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'suse': '0.suse.pool.ntp.org,1.suse.pool.ntp.org,2.suse.pool.ntp.org,3.suse.pool.ntp.org', 'alinux': '0.ntp.cloud.aliyuncs.com,1.ntp.aliyun.com,2.ntp1.aliyun.com,3.ntp1.cloud.aliyuncs.com', 'amazon': '0.rhel.pool.ntp.org,1.rhel.pool.ntp.org,2.rhel.pool.ntp.org,3.rhel.pool.ntp.org', 'ubuntu': '0.ubuntu.pool.ntp.org,1.ubuntu.pool.ntp.org,2.ubuntu.pool.ntp.org,3.ubuntu.pool.ntp.org', 'almalinux': '0.almalinux.pool.ntp.org,1.almalinux.pool.ntp.org,2.almalinux.pool.ntp.org,3.almalinux.pool.ntp.org', 'debian': '0.debian.pool.ntp.org,1.debian.pool.ntp.org,2.debian.pool.ntp.org,3.debian.pool.ntp.org', 'nist': 'time.nist.gov,time-a-g.nist.gov,time-b-g.nist.gov,time-c-g.nist.gov'}", + "value": "{'local': 'local', 'default': 'minimal', 'minimal': 'minimal', 'sssd': 'sssd'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_45", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_pam_wheel_group_for_su", + "value": "var_multiple_time_servers", "remarks": "rule_set_000" }, { "name": "Parameter_Description_45", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "pam_wheel module has a parameter called group, which controls which groups can access the su command. This variable holds the valid value for the parameter.", + "value": "The list of vendor-approved time servers", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_45", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'sugroup', 'cis': 'sugroup'}", + "value": "{'default': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'generic': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'stig': '0.us.pool.ntp.mil', 'fedora': '0.fedora.pool.ntp.org,1.fedora.pool.ntp.org,2.fedora.pool.ntp.org,3.fedora.pool.ntp.org', 'rhel': '0.rhel.pool.ntp.org,1.rhel.pool.ntp.org,2.rhel.pool.ntp.org,3.rhel.pool.ntp.org', 'ol': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'suse': '0.suse.pool.ntp.org,1.suse.pool.ntp.org,2.suse.pool.ntp.org,3.suse.pool.ntp.org', 'alinux': '0.ntp.cloud.aliyuncs.com,1.ntp.aliyun.com,2.ntp1.aliyun.com,3.ntp1.cloud.aliyuncs.com', 'amazon': '0.rhel.pool.ntp.org,1.rhel.pool.ntp.org,2.rhel.pool.ntp.org,3.rhel.pool.ntp.org', 'ubuntu': '0.ubuntu.pool.ntp.org,1.ubuntu.pool.ntp.org,2.ubuntu.pool.ntp.org,3.ubuntu.pool.ntp.org', 'almalinux': '0.almalinux.pool.ntp.org,1.almalinux.pool.ntp.org,2.almalinux.pool.ntp.org,3.almalinux.pool.ntp.org', 'debian': '0.debian.pool.ntp.org,1.debian.pool.ntp.org,2.debian.pool.ntp.org,3.debian.pool.ntp.org', 'nist': 'time.nist.gov,time-a-g.nist.gov,time-b-g.nist.gov,time-c-g.nist.gov'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_46", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_hashing_algorithm", + "value": "var_pam_wheel_group_for_su", "remarks": "rule_set_000" }, { "name": "Parameter_Description_46", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the system default encryption algorithm for encrypting passwords. Defines the value set as ENCRYPT_METHOD in /etc/login.defs.", + "value": "pam_wheel module has a parameter called group, which controls which groups can access the su command. This variable holds the valid value for the parameter.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_46", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'SHA512', 'SHA512': 'SHA512', 'SHA256': 'SHA256', 'yescrypt': 'YESCRYPT', 'cis_ubuntu2404': 'SHA512|YESCRYPT'}", + "value": "{'default': 'sugroup', 'cis': 'sugroup'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_47", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_hashing_algorithm_pam", + "value": "var_password_hashing_algorithm", "remarks": "rule_set_000" }, { "name": "Parameter_Description_47", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the system default encryption algorithm for encrypting passwords. Defines the hashing algorithm to be used in pam_unix.so.", + "value": "Specify the system default encryption algorithm for encrypting passwords. Defines the value set as ENCRYPT_METHOD in /etc/login.defs.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_47", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'sha512', 'sha512': 'sha512', 'yescrypt': 'yescrypt'}", + "value": "{'default': 'SHA512', 'SHA512': 'SHA512', 'SHA256': 'SHA256', 'yescrypt': 'YESCRYPT', 'cis_ubuntu2404': 'SHA512|YESCRYPT'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_48", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_dictcheck", + "value": "var_password_hashing_algorithm_pam", "remarks": "rule_set_000" }, { "name": "Parameter_Description_48", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Prevent the use of dictionary words for passwords.", + "value": "Specify the system default encryption algorithm for encrypting passwords. Defines the hashing algorithm to be used in pam_unix.so.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_48", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{1: 1, 'default': 1}", + "value": "{'default': 'sha512', 'sha512': 'sha512', 'yescrypt': 'yescrypt'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_49", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_difok", + "value": "var_password_pam_dictcheck", "remarks": "rule_set_000" }, { "name": "Parameter_Description_49", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Minimum number of characters not present in old password", + "value": "Prevent the use of dictionary words for passwords.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_49", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{15: 15, 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 8: 8, 'default': 8}", + "value": "{1: 1, 'default': 1}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_50", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_maxrepeat", + "value": "var_password_pam_difok", "remarks": "rule_set_000" }, { "name": "Parameter_Description_50", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Maximum Number of Consecutive Repeating Characters in a Password", + "value": "Minimum number of characters not present in old password", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_50", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{1: 1, 2: 2, 3: 3, 'default': 3}", + "value": "{15: 15, 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 8: 8, 'default': 8}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_51", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_minclass", + "value": "var_password_pam_maxrepeat", "remarks": "rule_set_000" }, { "name": "Parameter_Description_51", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Minimum number of categories of characters that must exist in a password", + "value": "Maximum Number of Consecutive Repeating Characters in a Password", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_51", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{1: 1, 2: 2, 3: 3, 4: 4, 'default': 3}", + "value": "{1: 1, 2: 2, 3: 3, 'default': 3}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_52", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_minlen", + "value": "var_password_pam_minclass", "remarks": "rule_set_000" }, { "name": "Parameter_Description_52", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Minimum number of characters in password", + "value": "Minimum number of categories of characters that must exist in a password", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_52", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{10: 10, 12: 12, 14: 14, 15: 15, 17: 17, 18: 18, 20: 20, 6: 6, 7: 7, 8: 8, 'default': 15}", + "value": "{1: 1, 2: 2, 3: 3, 4: 4, 'default': 3}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_53", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_remember", + "value": "var_password_pam_minlen", "remarks": "rule_set_000" }, { "name": "Parameter_Description_53", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Prevent password re-use using password history lookup", + "value": "Minimum number of characters in password", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_53", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'0': '0', 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 8: 8, 9: 9, 24: 24, 'default': 5}", + "value": "{10: 10, 12: 12, 14: 14, 15: 15, 17: 17, 18: 18, 20: 20, 6: 6, 7: 7, 8: 8, 'default': 15}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_54", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_remember_control_flag", + "value": "var_password_pam_remember", "remarks": "rule_set_000" }, { "name": "Parameter_Description_54", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "'Specify the control flag required for password remember requirement. If multiple values are allowed write them separated by commas as in \"required,requisite\", for remediations the first value will be taken'", + "value": "Prevent password re-use using password history lookup", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_54", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'required': 'required', 'optional': 'optional', 'requisite': 'requisite', 'sufficient': 'sufficient', 'binding': 'binding', 'ol8': 'required,requisite', 'requisite_or_required': 'requisite,required', 'default': 'requisite'}", + "value": "{'0': '0', 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 8: 8, 9: 9, 24: 24, 'default': 5}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_55", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_postfix_inet_interfaces", + "value": "var_password_pam_remember_control_flag", "remarks": "rule_set_000" }, { "name": "Parameter_Description_55", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The setting for inet_interfaces in /etc/postfix/main.cf", + "value": "'Specify the control flag required for password remember requirement. If multiple values are allowed write them separated by commas as in \"required,requisite\", for remediations the first value will be taken'", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_55", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'loopback-only': 'loopback-only', 'default': 'loopback-only', 'localhost': 'localhost'}", + "value": "{'required': 'required', 'optional': 'optional', 'requisite': 'requisite', 'sufficient': 'sufficient', 'binding': 'binding', 'ol8': 'required,requisite', 'requisite_or_required': 'requisite,required', 'default': 'requisite'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_56", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_screensaver_lock_delay", + "value": "var_postfix_inet_interfaces", "remarks": "rule_set_000" }, { "name": "Parameter_Description_56", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Choose allowed duration (in seconds) after a screensaver becomes active before displaying an authentication prompt", + "value": "The setting for inet_interfaces in /etc/postfix/main.cf", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_56", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'10_seconds': 10, '5_seconds': 5, 'default': '0', 'immediate': '0'}", + "value": "{'loopback-only': 'loopback-only', 'default': 'loopback-only', 'localhost': 'localhost'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_57", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_selinux_policy_name", + "value": "var_screensaver_lock_delay", "remarks": "rule_set_000" }, { "name": "Parameter_Description_57", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Type of policy in use. Possible values are:
targeted - Only targeted network daemons are protected.
strict - Full SELinux protection.
mls - Multiple levels of security", + "value": "Choose allowed duration (in seconds) after a screensaver becomes active before displaying an authentication prompt", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_57", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'targeted', 'mls': 'mls', 'targeted': 'targeted'}", + "value": "{'10_seconds': 10, '5_seconds': 5, 'default': '0', 'immediate': '0'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_58", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_selinux_state", + "value": "var_selinux_policy_name", "remarks": "rule_set_000" }, { "name": "Parameter_Description_58", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "enforcing - SELinux security policy is enforced.
permissive - SELinux prints warnings instead of enforcing.
disabled - SELinux is fully disabled.", + "value": "Type of policy in use. Possible values are:
targeted - Only targeted network daemons are protected.
strict - Full SELinux protection.
mls - Multiple levels of security", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_58", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'enforcing', 'disabled': 'disabled', 'enforcing': 'enforcing', 'permissive': 'permissive'}", + "value": "{'default': 'targeted', 'mls': 'mls', 'targeted': 'targeted'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_59", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_sshd_max_sessions", + "value": "var_selinux_state", "remarks": "rule_set_000" }, { "name": "Parameter_Description_59", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the maximum number of open sessions permitted.", + "value": "enforcing - SELinux security policy is enforced.
permissive - SELinux prints warnings instead of enforcing.
disabled - SELinux is fully disabled.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_59", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{10: 10, 4: 4, 3: 3, 2: 2, 1: 1, 0: 0, 'default': 10}", + "value": "{'default': 'enforcing', 'disabled': 'disabled', 'enforcing': 'enforcing', 'permissive': 'permissive'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_60", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_sshd_set_keepalive", + "value": "var_sshd_max_sessions", "remarks": "rule_set_000" }, { "name": "Parameter_Description_60", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the maximum number of idle message counts before session is terminated.", + "value": "Specify the maximum number of open sessions permitted.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_60", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{10: 10, 3: 3, 5: 5, 0: 0, 1: 1, 'default': 0}", + "value": "{10: 10, 4: 4, 3: 3, 2: 2, 1: 1, 0: 0, 'default': 10}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_61", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_sshd_set_login_grace_time", + "value": "var_sshd_set_keepalive", "remarks": "rule_set_000" }, { "name": "Parameter_Description_61", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure parameters for how long the servers stays connected before the user has successfully logged in", + "value": "Specify the maximum number of idle message counts before session is terminated.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_61", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 60, 60: 60}", + "value": "{10: 10, 3: 3, 5: 5, 0: 0, 1: 1, 'default': 0}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_62", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_sshd_set_maxstartups", + "value": "var_sshd_set_login_grace_time", "remarks": "rule_set_000" }, { "name": "Parameter_Description_62", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure parameters for maximum concurrent unauthenticated connections to the SSH daemon.", + "value": "Configure parameters for how long the servers stays connected before the user has successfully logged in", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_62", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': '10:30:100', '10:30:60': '10:30:60'}", + "value": "{'default': 60, 60: 60}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_63", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_system_crypto_policy", + "value": "var_sshd_set_maxstartups", "remarks": "rule_set_000" }, { "name": "Parameter_Description_63", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the crypto policy for the system.", + "value": "Configure parameters for maximum concurrent unauthenticated connections to the SSH daemon.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_63", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': '10:30:100', '10:30:60': '10:30:60'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_64", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_user_initialization_files_regex", + "value": "var_system_crypto_policy", "remarks": "rule_set_000" }, { "name": "Parameter_Description_64", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "'A regular expression describing a list of file names for files that are sourced at login time for interactive users'", + "value": "Specify the crypto policy for the system.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_64", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Id_65", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "var_user_initialization_files_regex", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Description_65", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "'A regular expression describing a list of file names for files that are sourced at login time for interactive users'", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Value_Alternatives_65", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'default': '^(\\\\.bashrc|\\\\.zshrc|\\\\.cshrc|\\\\.profile|\\\\.bash_login|\\\\.bash_profile)$', 'all_dotfiles': '^\\\\.[\\\\w\\\\- ]+$'}", "remarks": "rule_set_000" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_usb-storage_disabled", + "value": "kernel_module_cramfs_disabled", "remarks": "rule_set_001" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Modprobe Loading of USB Storage Driver", + "value": "Disable Mounting of cramfs", "remarks": "rule_set_001" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_tmp", + "value": "kernel_module_freevxfs_disabled", "remarks": "rule_set_002" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /tmp Located On Separate Partition", + "value": "Disable Mounting of freevxfs", "remarks": "rule_set_002" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_nodev", + "value": "kernel_module_hfs_disabled", "remarks": "rule_set_003" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /tmp", + "value": "Disable Mounting of hfs", "remarks": "rule_set_003" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_nosuid", + "value": "kernel_module_hfsplus_disabled", "remarks": "rule_set_004" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /tmp", + "value": "Disable Mounting of hfsplus", "remarks": "rule_set_004" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_noexec", + "value": "kernel_module_jffs2_disabled", "remarks": "rule_set_005" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /tmp", + "value": "Disable Mounting of jffs2", "remarks": "rule_set_005" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_dev_shm", + "value": "kernel_module_firewire-core_disabled", "remarks": "rule_set_006" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /dev/shm is configured", + "value": "Disable IEEE 1394 (FireWire) Support", "remarks": "rule_set_006" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_nodev", + "value": "kernel_module_usb-storage_disabled", "remarks": "rule_set_007" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /dev/shm", + "value": "Disable Modprobe Loading of USB Storage Driver", "remarks": "rule_set_007" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_nosuid", + "value": "partition_for_tmp", "remarks": "rule_set_008" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /dev/shm", + "value": "Ensure /tmp Located On Separate Partition", "remarks": "rule_set_008" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_noexec", + "value": "mount_option_tmp_nodev", "remarks": "rule_set_009" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /dev/shm", + "value": "Add nodev Option to /tmp", "remarks": "rule_set_009" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_home_nodev", + "value": "mount_option_tmp_nosuid", "remarks": "rule_set_010" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /home", + "value": "Add nosuid Option to /tmp", "remarks": "rule_set_010" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_home_nosuid", + "value": "mount_option_tmp_noexec", "remarks": "rule_set_011" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /home", + "value": "Add noexec Option to /tmp", "remarks": "rule_set_011" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_nodev", + "value": "partition_for_dev_shm", "remarks": "rule_set_012" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /var", + "value": "Ensure /dev/shm is configured", "remarks": "rule_set_012" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_nosuid", + "value": "mount_option_dev_shm_nodev", "remarks": "rule_set_013" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /var", + "value": "Add nodev Option to /dev/shm", "remarks": "rule_set_013" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_tmp_nodev", + "value": "mount_option_dev_shm_nosuid", "remarks": "rule_set_014" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /var/tmp", + "value": "Add nosuid Option to /dev/shm", "remarks": "rule_set_014" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_tmp_nosuid", + "value": "mount_option_dev_shm_noexec", "remarks": "rule_set_015" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /var/tmp", + "value": "Add noexec Option to /dev/shm", "remarks": "rule_set_015" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_tmp_noexec", + "value": "mount_option_home_nodev", "remarks": "rule_set_016" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /var/tmp", + "value": "Add nodev Option to /home", "remarks": "rule_set_016" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_nodev", + "value": "mount_option_home_nosuid", "remarks": "rule_set_017" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /var/log", + "value": "Add nosuid Option to /home", "remarks": "rule_set_017" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_nosuid", + "value": "mount_option_var_nodev", "remarks": "rule_set_018" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /var/log", + "value": "Add nodev Option to /var", "remarks": "rule_set_018" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_noexec", + "value": "mount_option_var_nosuid", "remarks": "rule_set_019" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /var/log", + "value": "Add nosuid Option to /var", "remarks": "rule_set_019" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_audit_nodev", + "value": "mount_option_var_tmp_nodev", "remarks": "rule_set_020" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /var/log/audit", + "value": "Add nodev Option to /var/tmp", "remarks": "rule_set_020" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_audit_nosuid", + "value": "mount_option_var_tmp_nosuid", "remarks": "rule_set_021" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /var/log/audit", + "value": "Add nosuid Option to /var/tmp", "remarks": "rule_set_021" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_audit_noexec", + "value": "mount_option_var_tmp_noexec", "remarks": "rule_set_022" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /var/log/audit", + "value": "Add noexec Option to /var/tmp", "remarks": "rule_set_022" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_gpgcheck_globally_activated", + "value": "mount_option_var_log_nodev", "remarks": "rule_set_023" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure gpgcheck Enabled In Main dnf Configuration", + "value": "Add nodev Option to /var/log", "remarks": "rule_set_023" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_libselinux_installed", + "value": "mount_option_var_log_nosuid", "remarks": "rule_set_024" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install libselinux Package", + "value": "Add nosuid Option to /var/log", "remarks": "rule_set_024" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "grub2_enable_selinux", + "value": "mount_option_var_log_noexec", "remarks": "rule_set_025" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure SELinux Not Disabled in /etc/default/grub", + "value": "Add noexec Option to /var/log", "remarks": "rule_set_025" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "selinux_policytype", + "value": "mount_option_var_log_audit_nodev", "remarks": "rule_set_026" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure SELinux Policy", + "value": "Add nodev Option to /var/log/audit", "remarks": "rule_set_026" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "selinux_not_disabled", + "value": "mount_option_var_log_audit_nosuid", "remarks": "rule_set_027" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure SELinux is Not Disabled", + "value": "Add nosuid Option to /var/log/audit", "remarks": "rule_set_027" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_mcstrans_removed", + "value": "mount_option_var_log_audit_noexec", "remarks": "rule_set_028" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall mcstrans Package", + "value": "Add noexec Option to /var/log/audit", "remarks": "rule_set_028" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_setroubleshoot_removed", + "value": "ensure_gpgcheck_globally_activated", "remarks": "rule_set_029" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall setroubleshoot Package", + "value": "Ensure gpgcheck Enabled In Main dnf Configuration", "remarks": "rule_set_029" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "grub2_password", + "value": "package_libselinux_installed", "remarks": "rule_set_030" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Boot Loader Password in grub2", + "value": "Install libselinux Package", "remarks": "rule_set_030" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_grub2_cfg", + "value": "grub2_enable_selinux", "remarks": "rule_set_031" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/grub.cfg Group Ownership", + "value": "Ensure SELinux Not Disabled in /etc/default/grub", "remarks": "rule_set_031" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_grub2_cfg", + "value": "selinux_policytype", "remarks": "rule_set_032" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/grub.cfg User Ownership", + "value": "Configure SELinux Policy", "remarks": "rule_set_032" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_grub2_cfg", + "value": "selinux_not_disabled", "remarks": "rule_set_033" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/grub.cfg Permissions", + "value": "Ensure SELinux is Not Disabled", "remarks": "rule_set_033" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_user_cfg", + "value": "package_mcstrans_removed", "remarks": "rule_set_034" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/user.cfg Group Ownership", + "value": "Uninstall mcstrans Package", "remarks": "rule_set_034" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_user_cfg", + "value": "package_setroubleshoot_removed", "remarks": "rule_set_035" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/user.cfg User Ownership", + "value": "Uninstall setroubleshoot Package", "remarks": "rule_set_035" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_user_cfg", + "value": "grub2_password", "remarks": "rule_set_036" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/user.cfg Permissions", + "value": "Set Boot Loader Password in grub2", "remarks": "rule_set_036" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_kernel_randomize_va_space", + "value": "file_groupowner_grub2_cfg", "remarks": "rule_set_037" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Randomized Layout of Virtual Address Space", + "value": "Verify /boot/grub2/grub.cfg Group Ownership", "remarks": "rule_set_037" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_kernel_yama_ptrace_scope", + "value": "file_owner_grub2_cfg", "remarks": "rule_set_038" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Restrict usage of ptrace to descendant processes", + "value": "Verify /boot/grub2/grub.cfg User Ownership", "remarks": "rule_set_038" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_backtraces", + "value": "file_permissions_grub2_cfg", "remarks": "rule_set_039" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable core dump backtraces", + "value": "Verify /boot/grub2/grub.cfg Permissions", "remarks": "rule_set_039" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_storage", + "value": "file_groupowner_user_cfg", "remarks": "rule_set_040" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable storing core dump", + "value": "Verify /boot/grub2/user.cfg Group Ownership", "remarks": "rule_set_040" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_crypto_policy", + "value": "file_owner_user_cfg", "remarks": "rule_set_041" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure System Cryptography Policy", + "value": "Verify /boot/grub2/user.cfg User Ownership", "remarks": "rule_set_041" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_ssh_crypto_policy", + "value": "file_permissions_user_cfg", "remarks": "rule_set_042" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure SSH to use System Crypto Policy", + "value": "Verify /boot/grub2/user.cfg Permissions", "remarks": "rule_set_042" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "banner_etc_motd_cis", + "value": "disable_users_coredumps", "remarks": "rule_set_043" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Message Of The Day Is Configured Properly", + "value": "Disable Core Dumps for All Users", "remarks": "rule_set_043" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "banner_etc_issue_cis", + "value": "sysctl_fs_protected_hardlinks", "remarks": "rule_set_044" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Local Login Warning Banner Is Configured Properly", + "value": "Enable Kernel Parameter to Enforce DAC on Hardlinks", "remarks": "rule_set_044" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "banner_etc_issue_net_cis", + "value": "sysctl_fs_suid_dumpable", "remarks": "rule_set_045" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Remote Login Warning Banner Is Configured Properly", + "value": "Disable Core Dumps for SUID programs", "remarks": "rule_set_045" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_motd", + "value": "sysctl_kernel_dmesg_restrict", "remarks": "rule_set_046" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Ownership of Message of the Day Banner", + "value": "Restrict Access to Kernel Message Buffer", "remarks": "rule_set_046" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_motd", + "value": "sysctl_kernel_kptr_restrict", "remarks": "rule_set_047" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify ownership of Message of the Day Banner", + "value": "Restrict Exposed Kernel Pointer Addresses Access", "remarks": "rule_set_047" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_motd", + "value": "sysctl_kernel_yama_ptrace_scope", "remarks": "rule_set_048" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify permissions on Message of the Day Banner", + "value": "Restrict usage of ptrace to descendant processes", "remarks": "rule_set_048" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_issue", + "value": "sysctl_kernel_randomize_va_space", "remarks": "rule_set_049" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Ownership of System Login Banner", + "value": "Enable Randomized Layout of Virtual Address Space", "remarks": "rule_set_049" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_issue", + "value": "coredump_disable_backtraces", "remarks": "rule_set_050" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify ownership of System Login Banner", + "value": "Disable core dump backtraces", "remarks": "rule_set_050" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_issue", + "value": "coredump_disable_storage", "remarks": "rule_set_051" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify permissions on System Login Banner", + "value": "Disable storing core dump", "remarks": "rule_set_051" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_issue_net", + "value": "configure_crypto_policy", "remarks": "rule_set_052" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Ownership of System Login Banner for Remote Connections", + "value": "Configure System Cryptography Policy", "remarks": "rule_set_052" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_issue_net", + "value": "banner_etc_motd_cis", "remarks": "rule_set_053" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify ownership of System Login Banner for Remote Connections", + "value": "Ensure Message Of The Day Is Configured Properly", "remarks": "rule_set_053" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_issue_net", + "value": "banner_etc_issue_cis", "remarks": "rule_set_054" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify permissions on System Login Banner for Remote Connections", + "value": "Ensure Local Login Warning Banner Is Configured Properly", "remarks": "rule_set_054" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_banner_enabled", + "value": "banner_etc_issue_net_cis", "remarks": "rule_set_055" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable GNOME3 Login Warning Banner", + "value": "Ensure Remote Login Warning Banner Is Configured Properly", "remarks": "rule_set_055" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_login_banner_text", + "value": "file_groupowner_etc_motd", "remarks": "rule_set_056" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set the GNOME3 Login Warning Banner Text", + "value": "Verify Group Ownership of Message of the Day Banner", "remarks": "rule_set_056" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_user_list", + "value": "file_owner_etc_motd", "remarks": "rule_set_057" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable the GNOME3 Login User List", + "value": "Verify ownership of Message of the Day Banner", "remarks": "rule_set_057" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_screensaver_idle_delay", + "value": "file_permissions_etc_motd", "remarks": "rule_set_058" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set GNOME3 Screensaver Inactivity Timeout", + "value": "Verify permissions on Message of the Day Banner", "remarks": "rule_set_058" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_screensaver_lock_delay", + "value": "file_groupowner_etc_issue", "remarks": "rule_set_059" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set GNOME3 Screensaver Lock Delay After Activation Period", + "value": "Verify Group Ownership of System Login Banner", "remarks": "rule_set_059" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_session_idle_user_locks", + "value": "file_owner_etc_issue", "remarks": "rule_set_060" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Users Cannot Change GNOME3 Session Idle Settings", + "value": "Verify ownership of System Login Banner", "remarks": "rule_set_060" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_screensaver_user_locks", + "value": "file_permissions_etc_issue", "remarks": "rule_set_061" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Users Cannot Change GNOME3 Screensaver Settings", + "value": "Verify permissions on System Login Banner", "remarks": "rule_set_061" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_automount", + "value": "file_groupowner_etc_issue_net", "remarks": "rule_set_062" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable GNOME3 Automounting", + "value": "Verify Group Ownership of System Login Banner for Remote Connections", "remarks": "rule_set_062" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_automount_open", + "value": "file_owner_etc_issue_net", "remarks": "rule_set_063" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable GNOME3 Automount Opening", + "value": "Verify ownership of System Login Banner for Remote Connections", "remarks": "rule_set_063" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_autorun", + "value": "file_permissions_etc_issue_net", "remarks": "rule_set_064" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable GNOME3 Automount running", + "value": "Verify permissions on System Login Banner for Remote Connections", "remarks": "rule_set_064" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_autofs_disabled", + "value": "dconf_gnome_banner_enabled", "remarks": "rule_set_065" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable the Automounter", + "value": "Enable GNOME3 Login Warning Banner", "remarks": "rule_set_065" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_avahi-daemon_disabled", + "value": "dconf_gnome_login_banner_text", "remarks": "rule_set_066" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Avahi Server Software", + "value": "Set the GNOME3 Login Warning Banner Text", "remarks": "rule_set_066" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_kea_removed", + "value": "dconf_gnome_disable_user_list", "remarks": "rule_set_067" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall kea Package", + "value": "Disable the GNOME3 Login User List", "remarks": "rule_set_067" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_bind_removed", + "value": "dconf_gnome_screensaver_idle_delay", "remarks": "rule_set_068" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall bind Package", + "value": "Set GNOME3 Screensaver Inactivity Timeout", "remarks": "rule_set_068" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_dnsmasq_removed", + "value": "dconf_gnome_screensaver_lock_delay", "remarks": "rule_set_069" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall dnsmasq Package", + "value": "Set GNOME3 Screensaver Lock Delay After Activation Period", "remarks": "rule_set_069" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_samba_removed", + "value": "dconf_gnome_session_idle_user_locks", "remarks": "rule_set_070" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall Samba Package", + "value": "Ensure Users Cannot Change GNOME3 Session Idle Settings", "remarks": "rule_set_070" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_vsftpd_removed", + "value": "dconf_gnome_screensaver_user_locks", "remarks": "rule_set_071" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall vsftpd Package", + "value": "Ensure Users Cannot Change GNOME3 Screensaver Settings", "remarks": "rule_set_071" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_dovecot_removed", + "value": "dconf_gnome_disable_automount", "remarks": "rule_set_072" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall dovecot Package", + "value": "Disable GNOME3 Automounting", "remarks": "rule_set_072" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_cyrus-imapd_removed", + "value": "dconf_gnome_disable_automount_open", "remarks": "rule_set_073" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall cyrus-imapd Package", + "value": "Disable GNOME3 Automount Opening", "remarks": "rule_set_073" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_nfs_disabled", + "value": "dconf_gnome_disable_autorun", "remarks": "rule_set_074" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Network File System (nfs)", + "value": "Disable GNOME3 Automount running", "remarks": "rule_set_074" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_cups_disabled", + "value": "service_autofs_disabled", "remarks": "rule_set_075" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable the CUPS Service", + "value": "Disable the Automounter", "remarks": "rule_set_075" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_rpcbind_disabled", + "value": "service_avahi-daemon_disabled", "remarks": "rule_set_076" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable rpcbind Service", + "value": "Disable Avahi Server Software", "remarks": "rule_set_076" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_rsync_removed", + "value": "package_kea_removed", "remarks": "rule_set_077" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall rsync Package", + "value": "Uninstall kea Package", "remarks": "rule_set_077" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_net-snmp_removed", + "value": "package_bind_removed", "remarks": "rule_set_078" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall net-snmp Package", + "value": "Uninstall bind Package", "remarks": "rule_set_078" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_telnet-server_removed", + "value": "package_dnsmasq_removed", "remarks": "rule_set_079" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall telnet-server Package", + "value": "Uninstall dnsmasq Package", "remarks": "rule_set_079" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_tftp-server_removed", + "value": "package_vsftpd_removed", "remarks": "rule_set_080" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall tftp-server Package", + "value": "Uninstall vsftpd Package", "remarks": "rule_set_080" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_squid_removed", + "value": "package_dovecot_removed", "remarks": "rule_set_081" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall squid Package", + "value": "Uninstall dovecot Package", "remarks": "rule_set_081" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_httpd_removed", + "value": "package_cyrus-imapd_removed", "remarks": "rule_set_082" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall httpd Package", + "value": "Uninstall cyrus-imapd Package", "remarks": "rule_set_082" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_nginx_removed", + "value": "service_nfs_disabled", "remarks": "rule_set_083" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall nginx Package", + "value": "Disable Network File System (nfs)", "remarks": "rule_set_083" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "postfix_network_listening_disabled", + "value": "service_cups_disabled", "remarks": "rule_set_084" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Postfix Network Listening", + "value": "Disable the CUPS Service", "remarks": "rule_set_084" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "has_nonlocal_mta", + "value": "service_rpcbind_disabled", "remarks": "rule_set_085" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Mail Transfer Agent is not Listening on any non-loopback Address", + "value": "Disable rpcbind Service", "remarks": "rule_set_085" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_ftp_removed", + "value": "package_rsync_removed", "remarks": "rule_set_086" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Remove ftp Package", + "value": "Uninstall rsync Package", "remarks": "rule_set_086" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_telnet_removed", + "value": "package_samba_removed", "remarks": "rule_set_087" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Remove telnet Clients", + "value": "Uninstall Samba Package", "remarks": "rule_set_087" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_tftp_removed", + "value": "package_net-snmp_removed", "remarks": "rule_set_088" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Remove tftp Daemon", + "value": "Uninstall net-snmp Package", "remarks": "rule_set_088" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "chronyd_specify_remote_server", + "value": "package_telnet-server_removed", "remarks": "rule_set_089" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "A remote time server for Chrony is configured", + "value": "Uninstall telnet-server Package", "remarks": "rule_set_089" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "chronyd_run_as_chrony_user", + "value": "package_tftp-server_removed", "remarks": "rule_set_090" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that chronyd is running under chrony user account", + "value": "Uninstall tftp-server Package", "remarks": "rule_set_090" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_cron_installed", + "value": "package_squid_removed", "remarks": "rule_set_091" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install the cron service", + "value": "Uninstall squid Package", "remarks": "rule_set_091" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_crond_enabled", + "value": "package_httpd_removed", "remarks": "rule_set_092" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable cron Service", + "value": "Uninstall httpd Package", "remarks": "rule_set_092" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_crontab", + "value": "package_nginx_removed", "remarks": "rule_set_093" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns Crontab", + "value": "Uninstall nginx Package", "remarks": "rule_set_093" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_crontab", + "value": "postfix_network_listening_disabled", "remarks": "rule_set_094" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on crontab", + "value": "Disable Postfix Network Listening", "remarks": "rule_set_094" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_crontab", + "value": "has_nonlocal_mta", "remarks": "rule_set_095" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on crontab", + "value": "Ensure Mail Transfer Agent is not Listening on any non-loopback Address", "remarks": "rule_set_095" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_hourly", + "value": "package_ftp_removed", "remarks": "rule_set_096" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns cron.hourly", + "value": "Remove ftp Package", "remarks": "rule_set_096" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_hourly", + "value": "package_telnet_removed", "remarks": "rule_set_097" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on cron.hourly", + "value": "Remove telnet Clients", "remarks": "rule_set_097" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_hourly", + "value": "package_tftp_removed", "remarks": "rule_set_098" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on cron.hourly", + "value": "Remove tftp Daemon", "remarks": "rule_set_098" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_daily", + "value": "chronyd_specify_remote_server", "remarks": "rule_set_099" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns cron.daily", + "value": "A remote time server for Chrony is configured", "remarks": "rule_set_099" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_daily", + "value": "chronyd_run_as_chrony_user", "remarks": "rule_set_100" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on cron.daily", + "value": "Ensure that chronyd is running under chrony user account", "remarks": "rule_set_100" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_daily", + "value": "package_cron_installed", "remarks": "rule_set_101" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on cron.daily", + "value": "Install the cron service", "remarks": "rule_set_101" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_weekly", + "value": "service_crond_enabled", "remarks": "rule_set_102" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns cron.weekly", + "value": "Enable cron Service", "remarks": "rule_set_102" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_weekly", + "value": "file_groupowner_crontab", "remarks": "rule_set_103" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on cron.weekly", + "value": "Verify Group Who Owns Crontab", "remarks": "rule_set_103" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_weekly", + "value": "file_owner_crontab", "remarks": "rule_set_104" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on cron.weekly", + "value": "Verify Owner on crontab", "remarks": "rule_set_104" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_monthly", + "value": "file_permissions_crontab", "remarks": "rule_set_105" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns cron.monthly", + "value": "Verify Permissions on crontab", "remarks": "rule_set_105" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_monthly", + "value": "file_groupowner_cron_hourly", "remarks": "rule_set_106" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on cron.monthly", + "value": "Verify Group Who Owns cron.hourly", "remarks": "rule_set_106" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_monthly", + "value": "file_owner_cron_hourly", "remarks": "rule_set_107" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on cron.monthly", + "value": "Verify Owner on cron.hourly", "remarks": "rule_set_107" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_d", + "value": "file_permissions_cron_hourly", "remarks": "rule_set_108" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns cron.d", + "value": "Verify Permissions on cron.hourly", "remarks": "rule_set_108" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_d", + "value": "file_groupowner_cron_daily", "remarks": "rule_set_109" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on cron.d", + "value": "Verify Group Who Owns cron.daily", "remarks": "rule_set_109" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_d", + "value": "file_owner_cron_daily", "remarks": "rule_set_110" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on cron.d", + "value": "Verify Owner on cron.daily", "remarks": "rule_set_110" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_cron_deny_not_exist", + "value": "file_permissions_cron_daily", "remarks": "rule_set_111" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that /etc/cron.deny does not exist", + "value": "Verify Permissions on cron.daily", "remarks": "rule_set_111" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_cron_allow_exists", + "value": "file_groupowner_cron_weekly", "remarks": "rule_set_112" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that /etc/cron.allow exists", + "value": "Verify Group Who Owns cron.weekly", "remarks": "rule_set_112" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_allow", + "value": "file_owner_cron_weekly", "remarks": "rule_set_113" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns /etc/cron.allow file", + "value": "Verify Owner on cron.weekly", "remarks": "rule_set_113" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_allow", + "value": "file_permissions_cron_weekly", "remarks": "rule_set_114" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns /etc/cron.allow file", + "value": "Verify Permissions on cron.weekly", "remarks": "rule_set_114" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_allow", + "value": "file_groupowner_cron_monthly", "remarks": "rule_set_115" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on /etc/cron.allow file", + "value": "Verify Group Who Owns cron.monthly", "remarks": "rule_set_115" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_at_deny_not_exist", + "value": "file_owner_cron_monthly", "remarks": "rule_set_116" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that /etc/at.deny does not exist", + "value": "Verify Owner on cron.monthly", "remarks": "rule_set_116" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_at_allow", + "value": "file_permissions_cron_monthly", "remarks": "rule_set_117" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns /etc/at.allow file", + "value": "Verify Permissions on cron.monthly", "remarks": "rule_set_117" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_at_allow", + "value": "file_groupowner_cron_d", "remarks": "rule_set_118" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns /etc/at.allow file", + "value": "Verify Group Who Owns cron.d", "remarks": "rule_set_118" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_at_allow", + "value": "file_owner_cron_d", "remarks": "rule_set_119" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on /etc/at.allow file", + "value": "Verify Owner on cron.d", "remarks": "rule_set_119" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "wireless_disable_interfaces", + "value": "file_permissions_cron_d", "remarks": "rule_set_120" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Deactivate Wireless Network Interfaces", + "value": "Verify Permissions on cron.d", "remarks": "rule_set_120" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_bluetooth_disabled", + "value": "file_cron_deny_not_exist", "remarks": "rule_set_121" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Bluetooth Service", + "value": "Ensure that /etc/cron.deny does not exist", "remarks": "rule_set_121" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_ip_forward", + "value": "file_cron_allow_exists", "remarks": "rule_set_122" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for IP Forwarding on IPv4 Interfaces", + "value": "Ensure that /etc/cron.allow exists", "remarks": "rule_set_122" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_forwarding", + "value": "file_groupowner_cron_allow", "remarks": "rule_set_123" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for IPv6 Forwarding", + "value": "Verify Group Who Owns /etc/cron.allow file", "remarks": "rule_set_123" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_send_redirects", + "value": "file_owner_cron_allow", "remarks": "rule_set_124" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces", + "value": "Verify User Who Owns /etc/cron.allow file", "remarks": "rule_set_124" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_send_redirects", + "value": "file_permissions_cron_allow", "remarks": "rule_set_125" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces by Default", + "value": "Verify Permissions on /etc/cron.allow file", "remarks": "rule_set_125" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses", + "value": "file_at_deny_not_exist", "remarks": "rule_set_126" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Ignore Bogus ICMP Error Responses on IPv4 Interfaces", + "value": "Ensure that /etc/at.deny does not exist", "remarks": "rule_set_126" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts", + "value": "file_groupowner_at_allow", "remarks": "rule_set_127" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Ignore ICMP Broadcast Echo Requests on IPv4 Interfaces", + "value": "Verify Group Who Owns /etc/at.allow file", "remarks": "rule_set_127" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_accept_redirects", + "value": "file_owner_at_allow", "remarks": "rule_set_128" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Accepting ICMP Redirects for All IPv4 Interfaces", + "value": "Verify User Who Owns /etc/at.allow file", "remarks": "rule_set_128" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_accept_redirects", + "value": "file_permissions_at_allow", "remarks": "rule_set_129" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 Interfaces", + "value": "Verify Permissions on /etc/at.allow file", "remarks": "rule_set_129" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_redirects", + "value": "wireless_disable_interfaces", "remarks": "rule_set_130" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Accepting ICMP Redirects for All IPv6 Interfaces", + "value": "Deactivate Wireless Network Interfaces", "remarks": "rule_set_130" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_redirects", + "value": "service_bluetooth_disabled", "remarks": "rule_set_131" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces", + "value": "Disable Bluetooth Service", "remarks": "rule_set_131" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_secure_redirects", + "value": "kernel_module_atm_disabled", "remarks": "rule_set_132" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces", + "value": "Disable ATM Support", "remarks": "rule_set_132" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_secure_redirects", + "value": "kernel_module_can_disabled", "remarks": "rule_set_133" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Kernel Parameter for Accepting Secure Redirects By Default", + "value": "Disable CAN Support", "remarks": "rule_set_133" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_rp_filter", + "value": "kernel_module_dccp_disabled", "remarks": "rule_set_134" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces", + "value": "Disable DCCP Support", "remarks": "rule_set_134" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_rp_filter", + "value": "kernel_module_tipc_disabled", "remarks": "rule_set_135" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces by Default", + "value": "Disable TIPC Support", "remarks": "rule_set_135" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_accept_source_route", + "value": "kernel_module_rds_disabled", "remarks": "rule_set_136" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces", + "value": "Disable RDS Support", "remarks": "rule_set_136" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_accept_source_route", + "value": "kernel_module_sctp_disabled", "remarks": "rule_set_137" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces by Default", + "value": "Disable SCTP Support", "remarks": "rule_set_137" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_source_route", + "value": "sysctl_net_ipv4_conf_all_forwarding", "remarks": "rule_set_138" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces", + "value": "Disable Kernel Parameter for IPv4 Forwarding on all IPv4 Interfaces", "remarks": "rule_set_138" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_source_route", + "value": "sysctl_net_ipv4_conf_all_send_redirects", "remarks": "rule_set_139" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces by Default", + "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces", "remarks": "rule_set_139" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_log_martians", + "value": "sysctl_net_ipv4_conf_default_send_redirects", "remarks": "rule_set_140" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces", + "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces by Default", "remarks": "rule_set_140" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_log_martians", + "value": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses", "remarks": "rule_set_141" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Paremeter to Log Martian Packets on all IPv4 Interfaces by Default", + "value": "Enable Kernel Parameter to Ignore Bogus ICMP Error Responses on IPv4 Interfaces", "remarks": "rule_set_141" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_tcp_syncookies", + "value": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts", "remarks": "rule_set_142" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces", + "value": "Enable Kernel Parameter to Ignore ICMP Broadcast Echo Requests on IPv4 Interfaces", "remarks": "rule_set_142" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_ra", + "value": "sysctl_net_ipv4_conf_all_accept_redirects", "remarks": "rule_set_143" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Accepting Router Advertisements on All IPv6 Interfaces", + "value": "Disable Accepting ICMP Redirects for All IPv4 Interfaces", "remarks": "rule_set_143" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_ra", + "value": "sysctl_net_ipv4_conf_default_accept_redirects", "remarks": "rule_set_144" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Accepting Router Advertisements on all IPv6 Interfaces by Default", + "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 Interfaces", "remarks": "rule_set_144" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_nftables_installed", + "value": "sysctl_net_ipv4_conf_all_secure_redirects", "remarks": "rule_set_145" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install nftables Package", + "value": "Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces", "remarks": "rule_set_145" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_firewalld_enabled", + "value": "sysctl_net_ipv4_conf_default_secure_redirects", "remarks": "rule_set_146" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify firewalld Enabled", + "value": "Configure Kernel Parameter for Accepting Secure Redirects By Default", "remarks": "rule_set_146" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_firewalld_installed", + "value": "sysctl_net_ipv4_conf_all_rp_filter", "remarks": "rule_set_147" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install firewalld Package", + "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces", "remarks": "rule_set_147" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_nftables_disabled", + "value": "sysctl_net_ipv4_conf_default_rp_filter", "remarks": "rule_set_148" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify nftables Service is Disabled", + "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces by Default", "remarks": "rule_set_148" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "firewalld_loopback_traffic_trusted", + "value": "sysctl_net_ipv4_conf_all_accept_source_route", "remarks": "rule_set_149" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Firewalld to Trust Loopback Traffic", + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces", "remarks": "rule_set_149" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "firewalld_loopback_traffic_restricted", + "value": "sysctl_net_ipv4_conf_default_accept_source_route", "remarks": "rule_set_150" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Firewalld to Restrict Loopback Traffic", + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces by Default", "remarks": "rule_set_150" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_sshd_config", + "value": "sysctl_net_ipv4_conf_all_log_martians", "remarks": "rule_set_151" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns SSH Server config file", + "value": "Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces", "remarks": "rule_set_151" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_sshd_config", + "value": "sysctl_net_ipv4_conf_default_log_martians", "remarks": "rule_set_152" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on SSH Server config file", + "value": "Enable Kernel Paremeter to Log Martian Packets on all IPv4 Interfaces by Default", "remarks": "rule_set_152" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_config", + "value": "sysctl_net_ipv4_tcp_syncookies", "remarks": "rule_set_153" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on SSH Server config file", + "value": "Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces", "remarks": "rule_set_153" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_private_key", + "value": "sysctl_net_ipv6_conf_all_forwarding", "remarks": "rule_set_154" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on SSH Server Private *_key Key Files", + "value": "Disable Kernel Parameter for IPv6 Forwarding", "remarks": "rule_set_154" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_private_key", + "value": "sysctl_net_ipv6_conf_default_forwarding", "remarks": "rule_set_155" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Ownership on SSH Server Private *_key Key Files", + "value": "Disable Kernel Parameter for IPv6 Forwarding by default", "remarks": "rule_set_155" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_sshd_private_key", + "value": "sysctl_net_ipv6_conf_all_accept_redirects", "remarks": "rule_set_156" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Ownership on SSH Server Private *_key Key Files", + "value": "Disable Accepting ICMP Redirects for All IPv6 Interfaces", "remarks": "rule_set_156" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_pub_key", + "value": "sysctl_net_ipv6_conf_default_accept_redirects", "remarks": "rule_set_157" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on SSH Server Public *.pub Key Files", + "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces", "remarks": "rule_set_157" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_pub_key", + "value": "sysctl_net_ipv6_conf_all_accept_source_route", "remarks": "rule_set_158" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Ownership on SSH Server Public *.pub Key Files", + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces", "remarks": "rule_set_158" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_sshd_pub_key", + "value": "sysctl_net_ipv6_conf_default_accept_source_route", "remarks": "rule_set_159" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Ownership on SSH Server Public *.pub Key Files", + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces by Default", "remarks": "rule_set_159" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_kex", + "value": "sysctl_net_ipv6_conf_all_accept_ra", "remarks": "rule_set_160" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Use Only Strong Key Exchange algorithms", + "value": "Configure Accepting Router Advertisements on All IPv6 Interfaces", "remarks": "rule_set_160" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_macs", + "value": "sysctl_net_ipv6_conf_default_accept_ra", "remarks": "rule_set_161" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Use Only Strong MACs", + "value": "Disable Accepting Router Advertisements on all IPv6 Interfaces by Default", "remarks": "rule_set_161" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_limit_user_access", + "value": "package_firewalld_installed", "remarks": "rule_set_162" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Limit Users' SSH Access", + "value": "Install firewalld Package", "remarks": "rule_set_162" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_enable_warning_banner_net", + "value": "service_firewalld_enabled", "remarks": "rule_set_163" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable SSH Warning Banner", + "value": "Verify firewalld Enabled", "remarks": "rule_set_163" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_idle_timeout", + "value": "firewalld_loopback_traffic_trusted", "remarks": "rule_set_164" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set SSH Client Alive Interval", + "value": "Configure Firewalld to Trust Loopback Traffic", "remarks": "rule_set_164" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_keepalive", + "value": "firewalld_loopback_traffic_restricted", "remarks": "rule_set_165" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set SSH Client Alive Count Max", + "value": "Configure Firewalld to Restrict Loopback Traffic", "remarks": "rule_set_165" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "disable_host_auth", + "value": "file_groupowner_sshd_config", "remarks": "rule_set_166" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Host-Based Authentication", + "value": "Verify Group Who Owns SSH Server config file", "remarks": "rule_set_166" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_rhosts", + "value": "file_owner_sshd_config", "remarks": "rule_set_167" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable SSH Support for .rhosts Files", + "value": "Verify Owner on SSH Server config file", "remarks": "rule_set_167" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_login_grace_time", + "value": "file_permissions_sshd_config", "remarks": "rule_set_168" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure SSH LoginGraceTime is configured", + "value": "Verify Permissions on SSH Server config file", "remarks": "rule_set_168" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_loglevel_verbose", + "value": "file_groupownership_sshd_private_key", "remarks": "rule_set_169" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set SSH Daemon LogLevel to VERBOSE", + "value": "Verify Group Ownership on SSH Server Private *_key Key Files", "remarks": "rule_set_169" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_max_auth_tries", + "value": "file_ownership_sshd_private_key", "remarks": "rule_set_170" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set SSH authentication attempt limit", + "value": "Verify Ownership on SSH Server Private *_key Key Files", "remarks": "rule_set_170" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_maxstartups", + "value": "file_permissions_sshd_private_key", "remarks": "rule_set_171" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure SSH MaxStartups is configured", + "value": "Verify Permissions on SSH Server Private *_key Key Files", "remarks": "rule_set_171" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_max_sessions", + "value": "file_groupownership_sshd_pub_key", "remarks": "rule_set_172" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set SSH MaxSessions limit", + "value": "Verify Group Ownership on SSH Server Public *.pub Key Files", "remarks": "rule_set_172" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_empty_passwords", + "value": "file_ownership_sshd_pub_key", "remarks": "rule_set_173" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable SSH Access via Empty Passwords", + "value": "Verify Ownership on SSH Server Public *.pub Key Files", "remarks": "rule_set_173" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_root_login", + "value": "file_permissions_sshd_pub_key", "remarks": "rule_set_174" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable SSH Root Login", + "value": "Verify Permissions on SSH Server Public *.pub Key Files", "remarks": "rule_set_174" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_do_not_permit_user_env", + "value": "sshd_limit_user_access", "remarks": "rule_set_175" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Do Not Allow SSH Environment Options", + "value": "Limit Users' SSH Access", "remarks": "rule_set_175" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_enable_pam", + "value": "sshd_enable_warning_banner_net", "remarks": "rule_set_176" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable PAM", + "value": "Enable SSH Warning Banner", "remarks": "rule_set_176" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_sudo_installed", + "value": "sshd_set_idle_timeout", "remarks": "rule_set_177" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install sudo Package", + "value": "Set SSH Client Alive Interval", "remarks": "rule_set_177" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_add_use_pty", + "value": "sshd_set_keepalive", "remarks": "rule_set_178" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Only Users Logged In To Real tty Can Execute Sudo - sudo use_pty", + "value": "Set SSH Client Alive Count Max", "remarks": "rule_set_178" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_custom_logfile", + "value": "disable_host_auth", "remarks": "rule_set_179" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Sudo Logfile Exists - sudo logfile", + "value": "Disable Host-Based Authentication", "remarks": "rule_set_179" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_require_reauthentication", + "value": "sshd_disable_rhosts", "remarks": "rule_set_180" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Require Re-Authentication When Using the sudo Command", + "value": "Disable SSH Support for .rhosts Files", "remarks": "rule_set_180" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "use_pam_wheel_group_for_su", + "value": "sshd_use_strong_kex", "remarks": "rule_set_181" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enforce Usage of pam_wheel with Group Parameter for su Authentication", + "value": "Use Only Strong Key Exchange algorithms", "remarks": "rule_set_181" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_pam_wheel_group_empty", + "value": "sshd_set_login_grace_time", "remarks": "rule_set_182" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure the Group Used by pam_wheel.so Module Exists on System and is Empty", + "value": "Ensure SSH LoginGraceTime is configured", "remarks": "rule_set_182" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_pam_pwquality_installed", + "value": "sshd_set_loglevel_verbose", "remarks": "rule_set_183" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install pam_pwquality Package", + "value": "Set SSH Daemon LogLevel to VERBOSE", "remarks": "rule_set_183" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_password_auth", + "value": "sshd_use_strong_macs", "remarks": "rule_set_184" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth File.", + "value": "Use Only Strong MACs", "remarks": "rule_set_184" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_system_auth", + "value": "sshd_set_max_auth_tries", "remarks": "rule_set_185" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth File.", + "value": "Set SSH authentication attempt limit", "remarks": "rule_set_185" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_deny", + "value": "sshd_set_maxstartups", "remarks": "rule_set_186" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Lock Accounts After Failed Password Attempts", + "value": "Ensure SSH MaxStartups is configured", "remarks": "rule_set_186" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_unlock_time", + "value": "sshd_set_max_sessions", "remarks": "rule_set_187" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Lockout Time for Failed Password Attempts", + "value": "Set SSH MaxSessions limit", "remarks": "rule_set_187" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_difok", + "value": "sshd_disable_empty_passwords", "remarks": "rule_set_188" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure PAM Enforces Password Requirements - Minimum Different Characters", + "value": "Disable SSH Access via Empty Passwords", "remarks": "rule_set_188" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_minlen", + "value": "sshd_disable_root_login", "remarks": "rule_set_189" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure PAM Enforces Password Requirements - Minimum Length", + "value": "Disable SSH Root Login", "remarks": "rule_set_189" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_minclass", + "value": "sshd_do_not_permit_user_env", "remarks": "rule_set_190" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure PAM Enforces Password Requirements - Minimum Different Categories", + "value": "Do Not Allow SSH Environment Options", "remarks": "rule_set_190" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_maxrepeat", + "value": "sshd_enable_pam", "remarks": "rule_set_191" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Password Maximum Consecutive Repeating Characters", + "value": "Enable PAM", "remarks": "rule_set_191" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_dictcheck", + "value": "package_sudo_installed", "remarks": "rule_set_192" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure PAM Enforces Password Requirements - Prevent the Use of Dictionary Words", + "value": "Install sudo Package", "remarks": "rule_set_192" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_enforce_root", + "value": "sudo_add_use_pty", "remarks": "rule_set_193" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure PAM Enforces Password Requirements - Enforce for root User", + "value": "Ensure Only Users Logged In To Real tty Can Execute Sudo - sudo use_pty", "remarks": "rule_set_193" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_pwhistory_remember_password_auth", + "value": "sudo_custom_logfile", "remarks": "rule_set_194" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Limit Password Reuse: password-auth", + "value": "Ensure Sudo Logfile Exists - sudo logfile", "remarks": "rule_set_194" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_pwhistory_remember_system_auth", + "value": "sudo_require_authentication", "remarks": "rule_set_195" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Limit Password Reuse: system-auth", + "value": "Ensure Users Re-Authenticate for Privilege Escalation - sudo", "remarks": "rule_set_195" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_empty_passwords", + "value": "sudo_require_reauthentication", "remarks": "rule_set_196" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Prevent Login to Accounts With Empty Password", + "value": "Require Re-Authentication When Using the sudo Command", "remarks": "rule_set_196" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_systemauth", + "value": "use_pam_wheel_group_for_su", "remarks": "rule_set_197" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set PAM''s Password Hashing Algorithm", + "value": "Enforce Usage of pam_wheel with Group Parameter for su Authentication", "remarks": "rule_set_197" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_passwordauth", + "value": "ensure_pam_wheel_group_empty", "remarks": "rule_set_198" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set PAM''s Password Hashing Algorithm - password-auth", + "value": "Ensure the Group Used by pam_wheel.so Module Exists on System and is Empty", "remarks": "rule_set_198" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_maximum_age_login_defs", + "value": "account_password_pam_faillock_password_auth", "remarks": "rule_set_199" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Password Maximum Age", + "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth File.", "remarks": "rule_set_199" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_set_max_life_existing", + "value": "account_password_pam_faillock_system_auth", "remarks": "rule_set_200" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Existing Passwords Maximum Age", + "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth File.", "remarks": "rule_set_200" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_warn_age_login_defs", + "value": "package_pam_pwquality_installed", "remarks": "rule_set_201" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Password Warning Age", + "value": "Install pam_pwquality Package", "remarks": "rule_set_201" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_set_warn_age_existing", + "value": "accounts_passwords_pam_faillock_deny", "remarks": "rule_set_202" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Existing Passwords Warning Age", + "value": "Lock Accounts After Failed Password Attempts", "remarks": "rule_set_202" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_libuserconf", + "value": "accounts_passwords_pam_faillock_unlock_time", "remarks": "rule_set_203" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Password Hashing Algorithm in /etc/libuser.conf", + "value": "Set Lockout Time for Failed Password Attempts", "remarks": "rule_set_203" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_logindefs", + "value": "accounts_password_pam_difok", "remarks": "rule_set_204" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Password Hashing Algorithm in /etc/login.defs", + "value": "Ensure PAM Enforces Password Requirements - Minimum Different Characters", "remarks": "rule_set_204" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_disable_post_pw_expiration", + "value": "accounts_password_pam_minlen", "remarks": "rule_set_205" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Account Expiration Following Inactivity", + "value": "Ensure PAM Enforces Password Requirements - Minimum Length", "remarks": "rule_set_205" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_set_post_pw_existing", + "value": "accounts_password_pam_minclass", "remarks": "rule_set_206" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set existing passwords a period of inactivity before they been locked", + "value": "Ensure PAM Enforces Password Requirements - Minimum Different Categories", "remarks": "rule_set_206" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_last_change_is_in_past", + "value": "accounts_password_pam_maxrepeat", "remarks": "rule_set_207" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure all users last password change date is in the past", + "value": "Set Password Maximum Consecutive Repeating Characters", "remarks": "rule_set_207" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_no_uid_except_zero", + "value": "accounts_password_pam_dictcheck", "remarks": "rule_set_208" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Only Root Has UID 0", + "value": "Ensure PAM Enforces Password Requirements - Prevent the Use of Dictionary Words", "remarks": "rule_set_208" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_root_gid_zero", + "value": "accounts_password_pam_enforce_root", "remarks": "rule_set_209" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Root Has A Primary GID 0", + "value": "Ensure PAM Enforces Password Requirements - Enforce for root User", "remarks": "rule_set_209" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_root_password_configured", + "value": "accounts_password_pam_pwhistory_remember_password_auth", "remarks": "rule_set_210" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Authentication Required for Single User Mode", + "value": "Limit Password Reuse: password-auth", "remarks": "rule_set_210" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_root_path_dirs_no_write", + "value": "accounts_password_pam_pwhistory_remember_system_auth", "remarks": "rule_set_211" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that Root's Path Does Not Include World or Group-Writable Directories", + "value": "Limit Password Reuse: system-auth", "remarks": "rule_set_211" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "root_path_no_dot", + "value": "no_empty_passwords", "remarks": "rule_set_212" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that Root's Path Does Not Include Relative Paths or Null Directories", + "value": "Prevent Login to Accounts With Empty Password", "remarks": "rule_set_212" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_password_auth_for_systemaccounts", + "value": "set_password_hashing_algorithm_systemauth", "remarks": "rule_set_213" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that System Accounts Are Locked", + "value": "Set PAM''s Password Hashing Algorithm", "remarks": "rule_set_213" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_shelllogin_for_systemaccounts", + "value": "set_password_hashing_algorithm_passwordauth", "remarks": "rule_set_214" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that System Accounts Do Not Run a Shell Upon Login", + "value": "Set PAM''s Password Hashing Algorithm - password-auth", "remarks": "rule_set_214" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_tmout", + "value": "accounts_maximum_age_login_defs", "remarks": "rule_set_215" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Interactive Session Timeout", + "value": "Set Password Maximum Age", "remarks": "rule_set_215" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_umask_etc_bashrc", + "value": "accounts_password_set_max_life_existing", "remarks": "rule_set_216" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure the Default Bash Umask is Set Correctly", + "value": "Set Existing Passwords Maximum Age", "remarks": "rule_set_216" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_umask_etc_login_defs", + "value": "accounts_password_warn_age_login_defs", "remarks": "rule_set_217" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure the Default Umask is Set Correctly in login.defs", + "value": "Set Password Warning Age", "remarks": "rule_set_217" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_umask_etc_profile", + "value": "accounts_password_set_warn_age_existing", "remarks": "rule_set_218" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure the Default Umask is Set Correctly in /etc/profile", + "value": "Set Existing Passwords Warning Age", "remarks": "rule_set_218" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_aide_installed", + "value": "set_password_hashing_algorithm_libuserconf", "remarks": "rule_set_219" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install AIDE", + "value": "Set Password Hashing Algorithm in /etc/libuser.conf", "remarks": "rule_set_219" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "aide_build_database", + "value": "set_password_hashing_algorithm_logindefs", "remarks": "rule_set_220" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Build and Test AIDE Database", + "value": "Set Password Hashing Algorithm in /etc/login.defs", "remarks": "rule_set_220" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "aide_periodic_cron_checking", + "value": "account_disable_post_pw_expiration", "remarks": "rule_set_221" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Periodic Execution of AIDE", + "value": "Set Account Expiration Following Inactivity", "remarks": "rule_set_221" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "aide_check_audit_tools", + "value": "accounts_set_post_pw_existing", "remarks": "rule_set_222" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure AIDE to Verify the Audit Tools", + "value": "Set existing passwords a period of inactivity before they been locked", "remarks": "rule_set_222" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_systemd-journald_enabled", + "value": "accounts_password_last_change_is_in_past", "remarks": "rule_set_223" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable systemd-journald Service", + "value": "Ensure all users last password change date is in the past", "remarks": "rule_set_223" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_systemd-journal-remote_installed", + "value": "accounts_no_uid_except_zero", "remarks": "rule_set_224" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install systemd-journal-remote Package", + "value": "Verify Only Root Has UID 0", "remarks": "rule_set_224" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "socket_systemd-journal-remote_disabled", + "value": "accounts_root_gid_zero", "remarks": "rule_set_225" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable systemd-journal-remote Socket", + "value": "Verify Root Has A Primary GID 0", "remarks": "rule_set_225" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_compress", + "value": "groups_no_zero_gid_except_root", "remarks": "rule_set_226" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure journald is configured to compress large log files", + "value": "Verify Only Group Root Has GID 0", "remarks": "rule_set_226" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_storage", + "value": "ensure_root_password_configured", "remarks": "rule_set_227" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure journald is configured to write log files to persistent disk", + "value": "Ensure Authentication Required for Single User Mode", "remarks": "rule_set_227" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "rsyslog_files_groupownership", + "value": "accounts_root_path_dirs_no_write", "remarks": "rule_set_228" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Log Files Are Owned By Appropriate Group", + "value": "Ensure that Root's Path Does Not Include World or Group-Writable Directories", "remarks": "rule_set_228" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "rsyslog_files_ownership", + "value": "root_path_no_dot", "remarks": "rule_set_229" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Log Files Are Owned By Appropriate User", + "value": "Ensure that Root's Path Does Not Include Relative Paths or Null Directories", "remarks": "rule_set_229" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "rsyslog_files_permissions", + "value": "accounts_umask_root", "remarks": "rule_set_230" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure System Log Files Have Correct Permissions", + "value": "Ensure the Root Bash Umask is Set Correctly", "remarks": "rule_set_230" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_passwd", + "value": "no_password_auth_for_systemaccounts", "remarks": "rule_set_231" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns passwd File", + "value": "Ensure that System Accounts Are Locked", "remarks": "rule_set_231" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_passwd", + "value": "no_shelllogin_for_systemaccounts", "remarks": "rule_set_232" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns passwd File", + "value": "Ensure that System Accounts Do Not Run a Shell Upon Login", "remarks": "rule_set_232" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_passwd", + "value": "accounts_tmout", "remarks": "rule_set_233" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on passwd File", + "value": "Set Interactive Session Timeout", "remarks": "rule_set_233" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_passwd", + "value": "accounts_umask_etc_bashrc", "remarks": "rule_set_234" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns Backup passwd File", + "value": "Ensure the Default Bash Umask is Set Correctly", "remarks": "rule_set_234" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_passwd", + "value": "accounts_umask_etc_login_defs", "remarks": "rule_set_235" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns Backup passwd File", + "value": "Ensure the Default Umask is Set Correctly in login.defs", "remarks": "rule_set_235" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_passwd", + "value": "accounts_umask_etc_profile", "remarks": "rule_set_236" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on Backup passwd File", + "value": "Ensure the Default Umask is Set Correctly in /etc/profile", "remarks": "rule_set_236" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_group", + "value": "package_aide_installed", "remarks": "rule_set_237" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns group File", + "value": "Install AIDE", "remarks": "rule_set_237" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_group", + "value": "aide_build_database", "remarks": "rule_set_238" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns group File", + "value": "Build and Test AIDE Database", "remarks": "rule_set_238" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_group", + "value": "aide_periodic_cron_checking", "remarks": "rule_set_239" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on group File", + "value": "Configure Periodic Execution of AIDE", "remarks": "rule_set_239" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_group", + "value": "aide_check_audit_tools", "remarks": "rule_set_240" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns Backup group File", + "value": "Configure AIDE to Verify the Audit Tools", "remarks": "rule_set_240" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_group", + "value": "service_systemd-journald_enabled", "remarks": "rule_set_241" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns Backup group File", + "value": "Enable systemd-journald Service", "remarks": "rule_set_241" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_group", + "value": "journald_compress", "remarks": "rule_set_242" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on Backup group File", + "value": "Ensure journald is configured to compress large log files", "remarks": "rule_set_242" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_shadow", + "value": "journald_storage", "remarks": "rule_set_243" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns shadow File", + "value": "Ensure journald is configured to write log files to persistent disk", "remarks": "rule_set_243" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_shadow", + "value": "package_systemd-journal-remote_installed", "remarks": "rule_set_244" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns shadow File", + "value": "Install systemd-journal-remote Package", "remarks": "rule_set_244" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_shadow", + "value": "socket_systemd-journal-remote_disabled", "remarks": "rule_set_245" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on shadow File", + "value": "Disable systemd-journal-remote Socket", "remarks": "rule_set_245" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_shadow", + "value": "rsyslog_files_groupownership", "remarks": "rule_set_246" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns Backup shadow File", + "value": "Ensure Log Files Are Owned By Appropriate Group", "remarks": "rule_set_246" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_shadow", + "value": "rsyslog_files_ownership", "remarks": "rule_set_247" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns Backup shadow File", + "value": "Ensure Log Files Are Owned By Appropriate User", "remarks": "rule_set_247" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_shadow", + "value": "rsyslog_files_permissions", "remarks": "rule_set_248" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on Backup shadow File", + "value": "Ensure System Log Files Have Correct Permissions", "remarks": "rule_set_248" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_gshadow", + "value": "file_groupowner_etc_passwd", "remarks": "rule_set_249" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns gshadow File", + "value": "Verify Group Who Owns passwd File", "remarks": "rule_set_249" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_gshadow", + "value": "file_owner_etc_passwd", "remarks": "rule_set_250" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns gshadow File", + "value": "Verify User Who Owns passwd File", "remarks": "rule_set_250" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_gshadow", + "value": "file_permissions_etc_passwd", "remarks": "rule_set_251" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on gshadow File", + "value": "Verify Permissions on passwd File", "remarks": "rule_set_251" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_gshadow", + "value": "file_groupowner_backup_etc_passwd", "remarks": "rule_set_252" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns Backup gshadow File", + "value": "Verify Group Who Owns Backup passwd File", "remarks": "rule_set_252" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_gshadow", + "value": "file_owner_backup_etc_passwd", "remarks": "rule_set_253" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns Backup gshadow File", + "value": "Verify User Who Owns Backup passwd File", "remarks": "rule_set_253" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_gshadow", + "value": "file_permissions_backup_etc_passwd", "remarks": "rule_set_254" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on Backup gshadow File", + "value": "Verify Permissions on Backup passwd File", "remarks": "rule_set_254" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_shells", + "value": "file_groupowner_etc_group", "remarks": "rule_set_255" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns /etc/shells File", + "value": "Verify Group Who Owns group File", "remarks": "rule_set_255" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_shells", + "value": "file_owner_etc_group", "remarks": "rule_set_256" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Who Owns /etc/shells File", + "value": "Verify User Who Owns group File", "remarks": "rule_set_256" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_shells", + "value": "file_permissions_etc_group", "remarks": "rule_set_257" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on /etc/shells File", + "value": "Verify Permissions on group File", "remarks": "rule_set_257" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_etc_security_opasswd", + "value": "file_groupowner_backup_etc_group", "remarks": "rule_set_258" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions and Ownership of Old Passwords File", + "value": "Verify Group Who Owns Backup group File", "remarks": "rule_set_258" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_unauthorized_world_writable", + "value": "file_owner_backup_etc_group", "remarks": "rule_set_259" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure No World-Writable Files Exist", + "value": "Verify User Who Owns Backup group File", "remarks": "rule_set_259" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dir_perms_world_writable_sticky_bits", + "value": "file_permissions_backup_etc_group", "remarks": "rule_set_260" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify that All World-Writable Directories Have Sticky Bits Set", + "value": "Verify Permissions on Backup group File", "remarks": "rule_set_260" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_files_unowned_by_user", + "value": "file_owner_etc_shadow", "remarks": "rule_set_261" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Files Are Owned by a User", + "value": "Verify User Who Owns shadow File", "remarks": "rule_set_261" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_ungroupowned", + "value": "file_groupowner_etc_shadow", "remarks": "rule_set_262" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Files Are Owned by a Group", + "value": "Verify Group Who Owns shadow File", "remarks": "rule_set_262" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_all_shadowed", + "value": "file_permissions_etc_shadow", "remarks": "rule_set_263" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify All Account Password Hashes are Shadowed", + "value": "Verify Permissions on shadow File", "remarks": "rule_set_263" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_empty_passwords_etc_shadow", + "value": "file_groupowner_backup_etc_shadow", "remarks": "rule_set_264" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure There Are No Accounts With Blank or Null Passwords", + "value": "Verify User Who Owns Backup shadow File", "remarks": "rule_set_264" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "gid_passwd_group_same", + "value": "file_owner_backup_etc_shadow", "remarks": "rule_set_265" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "All GIDs referenced in /etc/passwd must be defined in /etc/group", + "value": "Verify Group Who Owns Backup shadow File", "remarks": "rule_set_265" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_unique_id", + "value": "file_permissions_backup_etc_shadow", "remarks": "rule_set_266" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Accounts on the System Have Unique User IDs", + "value": "Verify Permissions on Backup shadow File", "remarks": "rule_set_266" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "group_unique_id", + "value": "file_groupowner_etc_gshadow", "remarks": "rule_set_267" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Groups on the System Have Unique Group ID", + "value": "Verify Group Who Owns gshadow File", "remarks": "rule_set_267" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_unique_name", + "value": "file_owner_etc_gshadow", "remarks": "rule_set_268" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Accounts on the System Have Unique Names", + "value": "Verify User Who Owns gshadow File", "remarks": "rule_set_268" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "group_unique_name", + "value": "file_permissions_etc_gshadow", "remarks": "rule_set_269" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Groups on the System Have Unique Group Names", + "value": "Verify Permissions on gshadow File", "remarks": "rule_set_269" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_user_interactive_home_directory_exists", + "value": "file_groupowner_backup_etc_gshadow", "remarks": "rule_set_270" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "All Interactive Users Home Directories Must Exist", + "value": "Verify Group Who Owns Backup gshadow File", "remarks": "rule_set_270" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_home_directories", + "value": "file_owner_backup_etc_gshadow", "remarks": "rule_set_271" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "All Interactive User Home Directories Must Be Owned By The Primary User", + "value": "Verify User Who Owns Backup gshadow File", "remarks": "rule_set_271" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_home_directories", + "value": "file_permissions_backup_etc_gshadow", "remarks": "rule_set_272" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "All Interactive User Home Directories Must Have mode 0750 Or Less Permissive", + "value": "Verify Permissions on Backup gshadow File", "remarks": "rule_set_272" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_user_dot_group_ownership", + "value": "file_groupowner_etc_shells", "remarks": "rule_set_273" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "User Initialization Files Must Be Group-Owned By The Primary Group", + "value": "Verify Group Who Owns /etc/shells File", "remarks": "rule_set_273" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_user_dot_user_ownership", + "value": "file_owner_etc_shells", "remarks": "rule_set_274" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "User Initialization Files Must Be Owned By the Primary User", + "value": "Verify Who Owns /etc/shells File", "remarks": "rule_set_274" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_user_dot_no_world_writable_programs", + "value": "file_permissions_etc_shells", "remarks": "rule_set_275" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "User Initialization Files Must Not Run World-Writable Programs", + "value": "Verify Permissions on /etc/shells File", "remarks": "rule_set_275" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permission_user_init_files", + "value": "file_etc_security_opasswd", "remarks": "rule_set_276" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All User Initialization Files Have Mode 0740 Or Less Permissive", + "value": "Verify Permissions and Ownership of Old Passwords File", "remarks": "rule_set_276" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_forward_files", + "value": "file_permissions_unauthorized_world_writable", "remarks": "rule_set_277" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify No .forward Files Exist", + "value": "Ensure No World-Writable Files Exist", "remarks": "rule_set_277" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_netrc_files", + "value": "dir_perms_world_writable_sticky_bits", "remarks": "rule_set_278" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify No netrc Files Exist", + "value": "Verify that All World-Writable Directories Have Sticky Bits Set", "remarks": "rule_set_278" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_squashfs_disabled", + "value": "no_files_unowned_by_user", "remarks": "rule_set_279" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Mounting of squashfs", + "value": "Ensure All Files Are Owned by a User", "remarks": "rule_set_279" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_udf_disabled", + "value": "file_permissions_ungroupowned", "remarks": "rule_set_280" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Mounting of udf", + "value": "Ensure All Files Are Owned by a Group", "remarks": "rule_set_280" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_home", + "value": "accounts_password_all_shadowed", "remarks": "rule_set_281" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /home Located On Separate Partition", + "value": "Verify All Account Password Hashes are Shadowed", "remarks": "rule_set_281" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_var", + "value": "no_empty_passwords_etc_shadow", "remarks": "rule_set_282" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /var Located On Separate Partition", + "value": "Ensure There Are No Accounts With Blank or Null Passwords", "remarks": "rule_set_282" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_var_tmp", + "value": "gid_passwd_group_same", "remarks": "rule_set_283" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /var/tmp Located On Separate Partition", + "value": "All GIDs referenced in /etc/passwd must be defined in /etc/group", "remarks": "rule_set_283" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_var_log", + "value": "account_unique_id", "remarks": "rule_set_284" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /var/log Located On Separate Partition", + "value": "Ensure All Accounts on the System Have Unique User IDs", "remarks": "rule_set_284" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_var_log_audit", + "value": "group_unique_id", "remarks": "rule_set_285" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /var/log/audit Located On Separate Partition", + "value": "Ensure All Groups on the System Have Unique Group ID", "remarks": "rule_set_285" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "selinux_state", + "value": "account_unique_name", "remarks": "rule_set_286" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure SELinux State is Enforcing", + "value": "Ensure All Accounts on the System Have Unique Names", "remarks": "rule_set_286" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_gdm_removed", + "value": "group_unique_name", "remarks": "rule_set_287" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Remove the GDM Package Group", + "value": "Ensure All Groups on the System Have Unique Group Names", "remarks": "rule_set_287" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "xwindows_runlevel_target", + "value": "accounts_user_interactive_home_directory_exists", "remarks": "rule_set_288" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Graphical Environment Startup By Setting Default Target", + "value": "All Interactive Users Home Directories Must Exist", "remarks": "rule_set_288" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_openldap-clients_removed", + "value": "file_ownership_home_directories", "remarks": "rule_set_289" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure LDAP client is not installed", + "value": "All Interactive User Home Directories Must Be Owned By The Primary User", "remarks": "rule_set_289" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_tipc_disabled", + "value": "file_permissions_home_directories", "remarks": "rule_set_290" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable TIPC Support", + "value": "All Interactive User Home Directories Must Have mode 0750 Or Less Permissive", "remarks": "rule_set_290" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_sctp_disabled", + "value": "accounts_user_dot_group_ownership", "remarks": "rule_set_291" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable SCTP Support", + "value": "User Initialization Files Must Be Group-Owned By The Primary Group", "remarks": "rule_set_291" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_gssapi_auth", + "value": "accounts_user_dot_user_ownership", "remarks": "rule_set_292" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable GSSAPI Authentication", + "value": "User Initialization Files Must Be Owned By the Primary User", "remarks": "rule_set_292" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_require_authentication", + "value": "accounts_user_dot_no_world_writable_programs", "remarks": "rule_set_293" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Users Re-Authenticate for Privilege Escalation - sudo", + "value": "User Initialization Files Must Not Run World-Writable Programs", "remarks": "rule_set_293" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_deny_root", + "value": "file_permission_user_init_files", "remarks": "rule_set_294" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure the root Account for Failed Password Attempts", + "value": "Ensure All User Initialization Files Have Mode 0740 Or Less Permissive", "remarks": "rule_set_294" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_minimum_age_login_defs", + "value": "no_forward_files", "remarks": "rule_set_295" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Password Minimum Age", + "value": "Verify No .forward Files Exist", "remarks": "rule_set_295" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_set_min_life_existing", + "value": "no_netrc_files", "remarks": "rule_set_296" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Existing Passwords Minimum Age", + "value": "Verify No netrc Files Exist", "remarks": "rule_set_296" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_audit_installed", + "value": "kernel_module_overlayfs_disabled", "remarks": "rule_set_297" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure the audit Subsystem is Installed", + "value": "Ensure overlayfs kernel module is not available", "remarks": "rule_set_297" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_audit-libs_installed", + "value": "kernel_module_squashfs_disabled", "remarks": "rule_set_298" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure the audit-libs package as a part of audit Subsystem is Installed", + "value": "Disable Mounting of squashfs", "remarks": "rule_set_298" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "grub2_audit_argument", + "value": "kernel_module_udf_disabled", "remarks": "rule_set_299" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Auditing for Processes Which Start Prior to the Audit Daemon", + "value": "Disable Mounting of udf", "remarks": "rule_set_299" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "grub2_audit_backlog_limit_argument", + "value": "partition_for_home", "remarks": "rule_set_300" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Extend Audit Backlog Limit for the Audit Daemon", + "value": "Ensure /home Located On Separate Partition", "remarks": "rule_set_300" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_auditd_enabled", + "value": "partition_for_var", "remarks": "rule_set_301" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable auditd Service", + "value": "Ensure /var Located On Separate Partition", "remarks": "rule_set_301" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_retention_max_log_file", + "value": "partition_for_var_tmp", "remarks": "rule_set_302" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure auditd Max Log File Size", + "value": "Ensure /var/tmp Located On Separate Partition", "remarks": "rule_set_302" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_retention_max_log_file_action", + "value": "partition_for_var_log", "remarks": "rule_set_303" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure auditd max_log_file_action Upon Reaching Maximum Log Size", + "value": "Ensure /var/log Located On Separate Partition", "remarks": "rule_set_303" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_disk_error_action", + "value": "partition_for_var_log_audit", "remarks": "rule_set_304" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure auditd Disk Error Action on Disk Error", + "value": "Ensure /var/log/audit Located On Separate Partition", "remarks": "rule_set_304" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_disk_full_action", + "value": "selinux_state", "remarks": "rule_set_305" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure auditd Disk Full Action when Disk Space Is Full", + "value": "Ensure SELinux State is Enforcing", "remarks": "rule_set_305" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_retention_action_mail_acct", + "value": "sysctl_fs_protected_symlinks", "remarks": "rule_set_306" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure auditd mail_acct Action on Low Disk Space", + "value": "Enable Kernel Parameter to Enforce DAC on Symlinks", "remarks": "rule_set_306" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_retention_admin_space_left_action", + "value": "service_cockpit_disabled", "remarks": "rule_set_307" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure auditd admin_space_left Action on Low Disk Space", + "value": "Disable Cockpit Management Server", "remarks": "rule_set_307" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_retention_space_left_action", + "value": "package_gdm_removed", "remarks": "rule_set_308" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure auditd space_left Action on Low Disk Space", + "value": "Remove the GDM Package Group", "remarks": "rule_set_308" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_sysadmin_actions", + "value": "xwindows_runlevel_target", "remarks": "rule_set_309" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects System Administrator Actions", + "value": "Disable Graphical Environment Startup By Setting Default Target", "remarks": "rule_set_309" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_suid_auid_privilege_function", + "value": "package_openldap-clients_removed", "remarks": "rule_set_310" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events When Executables Are Run As Another User", + "value": "Ensure LDAP client is not installed", "remarks": "rule_set_310" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_sudo_log_events", + "value": "sysctl_net_ipv4_ip_forward", "remarks": "rule_set_311" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Attempts to perform maintenance activities", + "value": "Disable Kernel Parameter for IP Forwarding on IPv4 Interfaces", "remarks": "rule_set_311" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_time_adjtimex", + "value": "sshd_disable_forwarding", "remarks": "rule_set_312" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record attempts to alter time through adjtimex", + "value": "Disable SSH Forwarding", "remarks": "rule_set_312" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_time_settimeofday", + "value": "sshd_disable_gssapi_auth", "remarks": "rule_set_313" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record attempts to alter time through settimeofday", + "value": "Disable GSSAPI Authentication", "remarks": "rule_set_313" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_time_clock_settime", + "value": "accounts_passwords_pam_faillock_deny_root", "remarks": "rule_set_314" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Attempts to Alter Time Through clock_settime", + "value": "Configure the root Account for Failed Password Attempts", "remarks": "rule_set_314" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_time_watch_localtime", + "value": "accounts_minimum_age_login_defs", "remarks": "rule_set_315" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Attempts to Alter the localtime File", + "value": "Set Password Minimum Age", "remarks": "rule_set_315" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_networkconfig_modification", + "value": "accounts_password_set_min_life_existing", "remarks": "rule_set_316" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Network Environment", + "value": "Set Existing Passwords Minimum Age", "remarks": "rule_set_316" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_networkconfig_modification_network_scripts", + "value": "no_nologin_in_shells", "remarks": "rule_set_317" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Network Environment", + "value": "Ensure nologin Shell is Not Listed in /etc/shells", "remarks": "rule_set_317" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_privileged_commands", + "value": "package_audit_installed", "remarks": "rule_set_318" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on the Use of Privileged Commands", + "value": "Ensure the audit Subsystem is Installed", "remarks": "rule_set_318" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_unsuccessful_file_modification_creat", + "value": "package_audit-libs_installed", "remarks": "rule_set_319" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Unsuccessful Access Attempts to Files - creat", + "value": "Ensure the audit-libs package as a part of audit Subsystem is Installed", "remarks": "rule_set_319" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_unsuccessful_file_modification_ftruncate", + "value": "grub2_audit_argument", "remarks": "rule_set_320" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Unsuccessful Access Attempts to Files - ftruncate", + "value": "Enable Auditing for Processes Which Start Prior to the Audit Daemon", "remarks": "rule_set_320" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_unsuccessful_file_modification_open", + "value": "grub2_audit_backlog_limit_argument", "remarks": "rule_set_321" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Unsuccessful Access Attempts to Files - open", + "value": "Extend Audit Backlog Limit for the Audit Daemon", "remarks": "rule_set_321" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_unsuccessful_file_modification_openat", + "value": "service_auditd_enabled", "remarks": "rule_set_322" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Unsuccessful Access Attempts to Files - openat", + "value": "Enable auditd Service", "remarks": "rule_set_322" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_unsuccessful_file_modification_truncate", + "value": "auditd_data_retention_max_log_file", "remarks": "rule_set_323" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Unsuccessful Access Attempts to Files - truncate", + "value": "Configure auditd Max Log File Size", "remarks": "rule_set_323" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_group", + "value": "auditd_data_retention_max_log_file_action", "remarks": "rule_set_324" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify User/Group Information - /etc/group", + "value": "Configure auditd max_log_file_action Upon Reaching Maximum Log Size", "remarks": "rule_set_324" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_gshadow", + "value": "auditd_data_disk_error_action", "remarks": "rule_set_325" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify User/Group Information - /etc/gshadow", + "value": "Configure auditd Disk Error Action on Disk Error", "remarks": "rule_set_325" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_opasswd", + "value": "auditd_data_disk_full_action", "remarks": "rule_set_326" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify User/Group Information - /etc/security/opasswd", + "value": "Configure auditd Disk Full Action when Disk Space Is Full", "remarks": "rule_set_326" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_passwd", + "value": "auditd_data_retention_action_mail_acct", "remarks": "rule_set_327" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify User/Group Information - /etc/passwd", + "value": "Configure auditd mail_acct Action on Low Disk Space", "remarks": "rule_set_327" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_shadow", + "value": "auditd_data_retention_admin_space_left_action", "remarks": "rule_set_328" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify User/Group Information - /etc/shadow", + "value": "Configure auditd admin_space_left Action on Low Disk Space", "remarks": "rule_set_328" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_chmod", + "value": "auditd_data_retention_space_left_action", "remarks": "rule_set_329" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - chmod", + "value": "Configure auditd space_left Action on Low Disk Space", "remarks": "rule_set_329" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_chown", + "value": "audit_rules_sysadmin_actions", "remarks": "rule_set_330" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - chown", + "value": "Ensure auditd Collects System Administrator Actions", "remarks": "rule_set_330" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchmod", + "value": "audit_rules_suid_auid_privilege_function", "remarks": "rule_set_331" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fchmod", + "value": "Record Events When Executables Are Run As Another User", "remarks": "rule_set_331" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchmodat", + "value": "audit_sudo_log_events", "remarks": "rule_set_332" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fchmodat", + "value": "Record Attempts to perform maintenance activities", "remarks": "rule_set_332" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchmodat2", + "value": "audit_rules_time_adjtimex", "remarks": "rule_set_333" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fchmodat2", + "value": "Record attempts to alter time through adjtimex", "remarks": "rule_set_333" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchown", + "value": "audit_rules_time_settimeofday", "remarks": "rule_set_334" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fchown", + "value": "Record attempts to alter time through settimeofday", "remarks": "rule_set_334" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchownat", + "value": "audit_rules_time_clock_settime", "remarks": "rule_set_335" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fchownat", + "value": "Record Attempts to Alter Time Through clock_settime", "remarks": "rule_set_335" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fremovexattr", + "value": "audit_rules_time_watch_localtime", "remarks": "rule_set_336" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fremovexattr", + "value": "Record Attempts to Alter the localtime File", "remarks": "rule_set_336" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fsetxattr", + "value": "audit_rules_networkconfig_modification", "remarks": "rule_set_337" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fsetxattr", + "value": "Record Events that Modify the System's Network Environment", "remarks": "rule_set_337" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_lchown", + "value": "audit_rules_networkconfig_modification_network_scripts", "remarks": "rule_set_338" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - lchown", + "value": "Record Events that Modify the System's Network Environment", "remarks": "rule_set_338" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_lremovexattr", + "value": "audit_rules_privileged_commands", "remarks": "rule_set_339" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - lremovexattr", + "value": "Ensure auditd Collects Information on the Use of Privileged Commands", "remarks": "rule_set_339" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_lsetxattr", + "value": "audit_rules_unsuccessful_file_modification_creat", "remarks": "rule_set_340" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - lsetxattr", + "value": "Record Unsuccessful Access Attempts to Files - creat", "remarks": "rule_set_340" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_removexattr", + "value": "audit_rules_unsuccessful_file_modification_ftruncate", "remarks": "rule_set_341" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - removexattr", + "value": "Record Unsuccessful Access Attempts to Files - ftruncate", "remarks": "rule_set_341" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_setxattr", + "value": "audit_rules_unsuccessful_file_modification_open", "remarks": "rule_set_342" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - setxattr", + "value": "Record Unsuccessful Access Attempts to Files - open", "remarks": "rule_set_342" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_media_export", + "value": "audit_rules_unsuccessful_file_modification_openat", "remarks": "rule_set_343" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on Exporting to Media (successful)", + "value": "Record Unsuccessful Access Attempts to Files - openat", "remarks": "rule_set_343" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_session_events_utmp", + "value": "audit_rules_unsuccessful_file_modification_truncate", "remarks": "rule_set_344" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Attempts to Alter Process and Session Initiation Information utmp", + "value": "Record Unsuccessful Access Attempts to Files - truncate", "remarks": "rule_set_344" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_session_events_btmp", + "value": "audit_rules_usergroup_modification_group", "remarks": "rule_set_345" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Attempts to Alter Process and Session Initiation Information btmp", + "value": "Record Events that Modify User/Group Information - /etc/group", "remarks": "rule_set_345" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_session_events_wtmp", + "value": "audit_rules_usergroup_modification_passwd", "remarks": "rule_set_346" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Attempts to Alter Process and Session Initiation Information wtmp", + "value": "Record Events that Modify User/Group Information - /etc/passwd", "remarks": "rule_set_346" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_login_events_faillock", + "value": "audit_rules_usergroup_modification_gshadow", "remarks": "rule_set_347" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Attempts to Alter Logon and Logout Events - faillock", + "value": "Record Events that Modify User/Group Information - /etc/gshadow", "remarks": "rule_set_347" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_login_events_lastlog", + "value": "audit_rules_usergroup_modification_shadow", "remarks": "rule_set_348" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Attempts to Alter Logon and Logout Events - lastlog", + "value": "Record Events that Modify User/Group Information - /etc/shadow", "remarks": "rule_set_348" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_rename", + "value": "audit_rules_usergroup_modification_opasswd", "remarks": "rule_set_349" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects File Deletion Events by User - rename", + "value": "Record Events that Modify User/Group Information - /etc/security/opasswd", "remarks": "rule_set_349" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_renameat", + "value": "audit_rules_dac_modification_chmod", "remarks": "rule_set_350" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects File Deletion Events by User - renameat", + "value": "Record Events that Modify the System's Discretionary Access Controls - chmod", "remarks": "rule_set_350" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_renameat2", + "value": "audit_rules_dac_modification_fchmod", "remarks": "rule_set_351" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects File Deletion Events by User - renameat2", + "value": "Record Events that Modify the System's Discretionary Access Controls - fchmod", "remarks": "rule_set_351" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_unlink", + "value": "audit_rules_dac_modification_fchmodat", "remarks": "rule_set_352" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects File Deletion Events by User - unlink", + "value": "Record Events that Modify the System's Discretionary Access Controls - fchmodat", "remarks": "rule_set_352" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_unlinkat", + "value": "audit_rules_dac_modification_fchmodat2", "remarks": "rule_set_353" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects File Deletion Events by User - unlinkat", + "value": "Record Events that Modify the System's Discretionary Access Controls - fchmodat2", "remarks": "rule_set_353" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_mac_modification_etc_selinux", + "value": "audit_rules_dac_modification_chown", "remarks": "rule_set_354" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Mandatory Access Controls (/etc/selinux)", + "value": "Record Events that Modify the System's Discretionary Access Controls - chown", "remarks": "rule_set_354" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_mac_modification_usr_share", + "value": "audit_rules_dac_modification_fchown", "remarks": "rule_set_355" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Mandatory Access Controls in usr/share", + "value": "Record Events that Modify the System's Discretionary Access Controls - fchown", "remarks": "rule_set_355" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_execution_chcon", + "value": "audit_rules_dac_modification_fchownat", "remarks": "rule_set_356" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Any Attempts to Run chcon", + "value": "Record Events that Modify the System's Discretionary Access Controls - fchownat", "remarks": "rule_set_356" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_execution_setfacl", + "value": "audit_rules_dac_modification_lchown", "remarks": "rule_set_357" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Any Attempts to Run setfacl", + "value": "Record Events that Modify the System's Discretionary Access Controls - lchown", "remarks": "rule_set_357" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_execution_chacl", + "value": "audit_rules_dac_modification_fremovexattr", "remarks": "rule_set_358" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Any Attempts to Run chacl", + "value": "Record Events that Modify the System's Discretionary Access Controls - fremovexattr", "remarks": "rule_set_358" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_privileged_commands_usermod", + "value": "audit_rules_dac_modification_fsetxattr", "remarks": "rule_set_359" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on the Use of Privileged Commands - usermod", + "value": "Record Events that Modify the System's Discretionary Access Controls - fsetxattr", "remarks": "rule_set_359" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_delete", + "value": "audit_rules_dac_modification_lremovexattr", "remarks": "rule_set_360" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on Kernel Module Unloading - delete_module", + "value": "Record Events that Modify the System's Discretionary Access Controls - lremovexattr", "remarks": "rule_set_360" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_finit", + "value": "audit_rules_dac_modification_lsetxattr", "remarks": "rule_set_361" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on Kernel Module Loading and Unloading - finit_module", + "value": "Record Events that Modify the System's Discretionary Access Controls - lsetxattr", "remarks": "rule_set_361" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_init", + "value": "audit_rules_dac_modification_removexattr", "remarks": "rule_set_362" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on Kernel Module Loading - init_module", + "value": "Record Events that Modify the System's Discretionary Access Controls - removexattr", "remarks": "rule_set_362" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_query", + "value": "audit_rules_dac_modification_setxattr", "remarks": "rule_set_363" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on Kernel Module Loading and Unloading - query_module", + "value": "Record Events that Modify the System's Discretionary Access Controls - setxattr", "remarks": "rule_set_363" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_privileged_commands_kmod", + "value": "audit_rules_media_export", "remarks": "rule_set_364" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on the Use of Privileged Commands - kmod", + "value": "Ensure auditd Collects Information on Exporting to Media (successful)", "remarks": "rule_set_364" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_immutable", + "value": "audit_rules_session_events_utmp", "remarks": "rule_set_365" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Make the auditd Configuration Immutable", + "value": "Record Attempts to Alter Process and Session Initiation Information utmp", "remarks": "rule_set_365" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "directory_permissions_var_log_audit", + "value": "audit_rules_session_events_btmp", "remarks": "rule_set_366" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "System Audit Logs Must Have Mode 0750 or Less Permissive", + "value": "Record Attempts to Alter Process and Session Initiation Information btmp", "remarks": "rule_set_366" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_var_log_audit", + "value": "audit_rules_session_events_wtmp", "remarks": "rule_set_367" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "System Audit Logs Must Have Mode 0640 or Less Permissive", + "value": "Record Attempts to Alter Process and Session Initiation Information wtmp", "remarks": "rule_set_367" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_var_log_audit_stig", + "value": "audit_rules_login_events_faillock", "remarks": "rule_set_368" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "System Audit Logs Must Be Owned By Root", + "value": "Record Attempts to Alter Logon and Logout Events - faillock", "remarks": "rule_set_368" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_group_ownership_var_log_audit", + "value": "audit_rules_login_events_lastlog", "remarks": "rule_set_369" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "System Audit Logs Must Be Group Owned By Root", + "value": "Record Attempts to Alter Logon and Logout Events - lastlog", "remarks": "rule_set_369" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_audit_configuration", + "value": "audit_rules_file_deletion_events_unlink", "remarks": "rule_set_370" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Audit Configuration Files Permissions are 640 or More Restrictive", + "value": "Ensure auditd Collects File Deletion Events by User - unlink", "remarks": "rule_set_370" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_audit_configuration", + "value": "audit_rules_file_deletion_events_unlinkat", "remarks": "rule_set_371" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Audit Configuration Files Must Be Owned By Root", + "value": "Ensure auditd Collects File Deletion Events by User - unlinkat", "remarks": "rule_set_371" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_audit_configuration", + "value": "audit_rules_file_deletion_events_rename", "remarks": "rule_set_372" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Audit Configuration Files Must Be Owned By Group root", + "value": "Ensure auditd Collects File Deletion Events by User - rename", "remarks": "rule_set_372" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_audit_binaries", + "value": "audit_rules_file_deletion_events_renameat", "remarks": "rule_set_373" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify that audit tools Have Mode 0755 or less", + "value": "Ensure auditd Collects File Deletion Events by User - renameat", "remarks": "rule_set_373" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_audit_binaries", + "value": "audit_rules_file_deletion_events_renameat2", "remarks": "rule_set_374" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify that audit tools are owned by root", + "value": "Ensure auditd Collects File Deletion Events by User - renameat2", "remarks": "rule_set_374" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_audit_binaries", + "value": "audit_rules_mac_modification_etc_selinux", "remarks": "rule_set_375" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify that audit tools are owned by group root", + "value": "Record Events that Modify the System's Mandatory Access Controls (/etc/selinux)", "remarks": "rule_set_375" - } - ], - "control-implementations": [ + }, { - "uuid": "c259fd0a-4905-4f04-ac0a-8d6a9a5e56f4", - "source": "trestle://profiles/rhel10-cis_rhel10-l2_server/profile.json", - "description": "REPLACE_ME", - "props": [ - { - "name": "Framework_Short_Name", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal", - "value": "cis" - } - ], - "set-parameters": [ - { - "param-id": "cis_banner_text", - "values": [ - "cis" - ] - }, - { - "param-id": "inactivity_timeout_value", - "values": [ - "15_minutes" - ] - }, - { - "param-id": "login_banner_text", - "values": [ - "cis_banners" - ] - }, - { - "param-id": "sshd_idle_timeout_value", - "values": [ - "5_minutes" - ] - }, - { - "param-id": "sshd_max_auth_tries_value", - "values": [ - "4" - ] - }, - { - "param-id": "sshd_strong_kex", - "values": [ - "cis_rhel8" - ] - }, - { - "param-id": "sshd_strong_macs", - "values": [ - "cis_rhel8" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_all_accept_redirects_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_all_accept_source_route_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_all_log_martians_value", - "values": [ - "enabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_all_rp_filter_value", - "values": [ - "enabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_all_secure_redirects_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_default_accept_redirects_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_default_accept_source_route_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_default_log_martians_value", - "values": [ - "enabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_default_rp_filter_value", - "values": [ - "enabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_default_secure_redirects_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts_value", - "values": [ - "enabled" - ] - }, + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_mac_modification_usr_share", + "remarks": "rule_set_376" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Record Events that Modify the System's Mandatory Access Controls in usr/share", + "remarks": "rule_set_376" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_execution_chcon", + "remarks": "rule_set_377" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Record Any Attempts to Run chcon", + "remarks": "rule_set_377" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_execution_setfacl", + "remarks": "rule_set_378" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Record Any Attempts to Run setfacl", + "remarks": "rule_set_378" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_execution_chacl", + "remarks": "rule_set_379" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Record Any Attempts to Run chacl", + "remarks": "rule_set_379" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_privileged_commands_usermod", + "remarks": "rule_set_380" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure auditd Collects Information on the Use of Privileged Commands - usermod", + "remarks": "rule_set_380" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_privileged_commands_kmod", + "remarks": "rule_set_381" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure auditd Collects Information on the Use of Privileged Commands - kmod", + "remarks": "rule_set_381" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_kernel_module_loading_init", + "remarks": "rule_set_382" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure auditd Collects Information on Kernel Module Loading - init_module", + "remarks": "rule_set_382" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_kernel_module_loading_finit", + "remarks": "rule_set_383" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure auditd Collects Information on Kernel Module Loading and Unloading - finit_module", + "remarks": "rule_set_383" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_kernel_module_loading_delete", + "remarks": "rule_set_384" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure auditd Collects Information on Kernel Module Unloading - delete_module", + "remarks": "rule_set_384" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_kernel_module_loading_create", + "remarks": "rule_set_385" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure auditd Collects Information on Kernel Module Unloading - create_module", + "remarks": "rule_set_385" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_kernel_module_loading_query", + "remarks": "rule_set_386" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure auditd Collects Information on Kernel Module Loading and Unloading - query_module", + "remarks": "rule_set_386" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_immutable", + "remarks": "rule_set_387" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Make the auditd Configuration Immutable", + "remarks": "rule_set_387" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "directory_permissions_var_log_audit", + "remarks": "rule_set_388" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "System Audit Logs Must Have Mode 0750 or Less Permissive", + "remarks": "rule_set_388" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_var_log_audit", + "remarks": "rule_set_389" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "System Audit Logs Must Have Mode 0640 or Less Permissive", + "remarks": "rule_set_389" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_ownership_var_log_audit_stig", + "remarks": "rule_set_390" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "System Audit Logs Must Be Owned By Root", + "remarks": "rule_set_390" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_group_ownership_var_log_audit", + "remarks": "rule_set_391" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "System Audit Logs Must Be Group Owned By Root", + "remarks": "rule_set_391" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_audit_configuration", + "remarks": "rule_set_392" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Audit Configuration Files Permissions are 640 or More Restrictive", + "remarks": "rule_set_392" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_ownership_audit_configuration", + "remarks": "rule_set_393" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Audit Configuration Files Must Be Owned By Root", + "remarks": "rule_set_393" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_groupownership_audit_configuration", + "remarks": "rule_set_394" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Audit Configuration Files Must Be Owned By Group root", + "remarks": "rule_set_394" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_audit_binaries", + "remarks": "rule_set_395" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify that audit tools Have Mode 0755 or less", + "remarks": "rule_set_395" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_ownership_audit_binaries", + "remarks": "rule_set_396" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify that audit tools are owned by root", + "remarks": "rule_set_396" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_groupownership_audit_binaries", + "remarks": "rule_set_397" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify that audit tools are owned by group root", + "remarks": "rule_set_397" + } + ], + "control-implementations": [ + { + "uuid": "a617d26f-8d7a-4082-b30a-a717e8193807", + "source": "trestle://profiles/rhel10-cis_rhel10-l2_server/profile.json", + "description": "REPLACE_ME", + "props": [ { - "param-id": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses_value", + "name": "Framework_Short_Name", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal", + "value": "cis" + } + ], + "set-parameters": [ + { + "param-id": "cis_banner_text", "values": [ - "enabled" + "cis" ] }, { - "param-id": "sysctl_net_ipv4_tcp_syncookies_value", + "param-id": "inactivity_timeout_value", "values": [ - "enabled" + "15_minutes" ] }, { - "param-id": "sysctl_net_ipv6_conf_all_accept_ra_value", + "param-id": "login_banner_text", "values": [ - "disabled" + "cis_banners" ] }, { - "param-id": "sysctl_net_ipv6_conf_all_accept_redirects_value", + "param-id": "sshd_idle_timeout_value", "values": [ - "disabled" + "5_minutes" ] }, { - "param-id": "sysctl_net_ipv6_conf_all_accept_source_route_value", + "param-id": "sshd_max_auth_tries_value", "values": [ - "disabled" + "4" ] }, { - "param-id": "sysctl_net_ipv6_conf_all_forwarding_value", + "param-id": "sshd_strong_kex", "values": [ - "disabled" + "cis_rhel10" + ] + }, + { + "param-id": "sshd_strong_macs", + "values": [ + "cis_rhel10" + ] + }, + { + "param-id": "sysctl_net_ipv4_conf_all_accept_redirects_value", + "values": [ + "disabled" + ] + }, + { + "param-id": "sysctl_net_ipv4_conf_all_accept_source_route_value", + "values": [ + "disabled" + ] + }, + { + "param-id": "sysctl_net_ipv4_conf_all_log_martians_value", + "values": [ + "enabled" + ] + }, + { + "param-id": "sysctl_net_ipv4_conf_all_rp_filter_value", + "values": [ + "enabled" + ] + }, + { + "param-id": "sysctl_net_ipv4_conf_all_secure_redirects_value", + "values": [ + "disabled" + ] + }, + { + "param-id": "sysctl_net_ipv4_conf_default_accept_redirects_value", + "values": [ + "disabled" + ] + }, + { + "param-id": "sysctl_net_ipv4_conf_default_accept_source_route_value", + "values": [ + "disabled" + ] + }, + { + "param-id": "sysctl_net_ipv4_conf_default_log_martians_value", + "values": [ + "enabled" + ] + }, + { + "param-id": "sysctl_net_ipv4_conf_default_rp_filter_value", + "values": [ + "enabled" + ] + }, + { + "param-id": "sysctl_net_ipv4_conf_default_secure_redirects_value", + "values": [ + "disabled" + ] + }, + { + "param-id": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts_value", + "values": [ + "enabled" + ] + }, + { + "param-id": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses_value", + "values": [ + "enabled" + ] + }, + { + "param-id": "sysctl_net_ipv4_tcp_syncookies_value", + "values": [ + "enabled" + ] + }, + { + "param-id": "sysctl_net_ipv6_conf_all_accept_ra_value", + "values": [ + "disabled" + ] + }, + { + "param-id": "sysctl_net_ipv6_conf_all_accept_redirects_value", + "values": [ + "disabled" + ] + }, + { + "param-id": "sysctl_net_ipv6_conf_all_accept_source_route_value", + "values": [ + "disabled" + ] + }, + { + "param-id": "sysctl_net_ipv6_conf_all_forwarding_value", + "values": [ + "disabled" ] }, { @@ -5872,6 +6154,12 @@ "disabled" ] }, + { + "param-id": "sysctl_net_ipv6_conf_default_forwarding_value", + "values": [ + "disabled" + ] + }, { "param-id": "var_account_disable_post_pw_expiration", "values": [ @@ -5935,19 +6223,19 @@ { "param-id": "var_auditd_admin_space_left_action", "values": [ - "cis_rhel8" + "cis_rhel10" ] }, { "param-id": "var_auditd_disk_error_action", "values": [ - "cis_rhel8" + "cis_rhel10" ] }, { "param-id": "var_auditd_disk_full_action", "values": [ - "cis_rhel8" + "cis_rhel10" ] }, { @@ -5965,7 +6253,7 @@ { "param-id": "var_auditd_space_left_action", "values": [ - "cis_rhel8" + "cis_rhel10" ] }, { @@ -6103,7 +6391,7 @@ ], "implemented-requirements": [ { - "uuid": "64ff28c8-91e9-4fca-b9b0-274301eab58b", + "uuid": "d3de6c65-f54f-4371-828c-ee5eba735e5c", "control-id": "cis_rhel10_1-1.1.6", "description": "REPLACE_ME", "props": [ @@ -6115,14 +6403,31 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_squashfs_disabled" + "value": "kernel_module_overlayfs_disabled" } ] }, { - "uuid": "b2c14feb-6ade-45b5-b1d1-9e6b78d5098f", + "uuid": "7fd48a6e-3362-4f83-a824-84a5fcd65cdc", "control-id": "cis_rhel10_1-1.1.7", "description": "REPLACE_ME", + "props": [ + { + "name": "implementation-status", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "kernel_module_squashfs_disabled" + } + ] + }, + { + "uuid": "875dee25-21b6-4c87-8205-09de9351d606", + "control-id": "cis_rhel10_1-1.1.8", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -6137,7 +6442,7 @@ ] }, { - "uuid": "47a0b036-f808-4dc8-866c-cdf1f7e2ed2c", + "uuid": "f4e53825-2d72-48d7-8e27-6ff077dc9bda", "control-id": "cis_rhel10_1-1.2.3.1", "description": "REPLACE_ME", "props": [ @@ -6154,7 +6459,7 @@ ] }, { - "uuid": "648edbbe-492c-4613-85e0-18c1209abcd7", + "uuid": "3a6c5fb3-db16-41e2-ac33-d5d134d96beb", "control-id": "cis_rhel10_1-1.2.4.1", "description": "REPLACE_ME", "props": [ @@ -6171,7 +6476,7 @@ ] }, { - "uuid": "5bf726e8-4202-496a-9a0e-a12412092093", + "uuid": "dacdc6be-b550-4db2-8e4a-a13f624ec848", "control-id": "cis_rhel10_1-1.2.5.1", "description": "REPLACE_ME", "props": [ @@ -6188,7 +6493,7 @@ ] }, { - "uuid": "dfbefe07-c1aa-4021-a861-529587b17912", + "uuid": "ad6cf678-4007-4997-9086-1dcac9f2716b", "control-id": "cis_rhel10_1-1.2.6.1", "description": "REPLACE_ME", "props": [ @@ -6205,7 +6510,7 @@ ] }, { - "uuid": "4a917af2-898e-4207-b075-84844f697218", + "uuid": "83e969e2-2469-4387-a464-1e904a8f52db", "control-id": "cis_rhel10_1-1.2.7.1", "description": "REPLACE_ME", "props": [ @@ -6222,7 +6527,7 @@ ] }, { - "uuid": "d3ebda2d-c6d8-46d0-b337-0e5f24d5459c", + "uuid": "a2f13482-ecc7-4333-b365-86a586296273", "control-id": "cis_rhel10_1-2.1.3", "description": "REPLACE_ME", "props": [ @@ -6235,7 +6540,7 @@ ] }, { - "uuid": "464fa186-bd61-4eb0-aeae-5676b25213a0", + "uuid": "be544abd-a448-492c-b7c5-9ac362d330d4", "control-id": "cis_rhel10_1-3.1.5", "description": "REPLACE_ME", "props": [ @@ -6252,7 +6557,7 @@ ] }, { - "uuid": "c20eac83-eb3d-4968-8e88-879afb380780", + "uuid": "fbaee157-aebf-421c-b8b5-1335411d4d5e", "control-id": "cis_rhel10_1-3.1.6", "description": "REPLACE_ME", "props": [ @@ -6265,8 +6570,8 @@ ] }, { - "uuid": "08180a66-26b1-42f8-a209-46c352babf1f", - "control-id": "cis_rhel10_1-8.1", + "uuid": "077212d4-7894-41dd-a4df-8653aa93199f", + "control-id": "cis_rhel10_1-5.3", "description": "REPLACE_ME", "props": [ { @@ -6277,35 +6582,26 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_gdm_removed" + "value": "sysctl_fs_protected_symlinks" } ] }, { - "uuid": "6253507b-8734-4e1f-ab1a-936593ffbdee", - "control-id": "cis_rhel10_2-1.20", - "description": "Review the availability of xorg-x11-server-common package when the product is out.\nThe rule also configures correct run level to prevent unbootable system.", + "uuid": "8d093963-f65d-499b-a8b8-c700d62fb461", + "control-id": "cis_rhel10_1-8.6", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_gdm_removed" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "xwindows_runlevel_target" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "385d3b7c-69f8-4219-892f-cbea2ac2d702", - "control-id": "cis_rhel10_2-2.2", + "uuid": "a13d4854-1aad-4248-bff8-ed95deb0533b", + "control-id": "cis_rhel10_2-1.3", "description": "REPLACE_ME", "props": [ { @@ -6316,14 +6612,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_openldap-clients_removed" + "value": "service_cockpit_disabled" } ] }, { - "uuid": "4b4ad9fd-4c3b-4569-975f-89417c2aa530", - "control-id": "cis_rhel10_3-2.2", - "description": "REPLACE_ME", + "uuid": "6a979001-7f93-49a4-b260-e5159e387b73", + "control-id": "cis_rhel10_2-1.20", + "description": "Review the availability of xorg-x11-server-common package when the product is out.\nThe rule also configures correct run level to prevent unbootable system.", "props": [ { "name": "implementation-status", @@ -6333,13 +6629,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_tipc_disabled" + "value": "package_gdm_removed" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "xwindows_runlevel_target" } ] }, { - "uuid": "261acb45-3cef-4616-89e5-aaaca029b3b4", - "control-id": "cis_rhel10_3-2.4", + "uuid": "fefa2bc0-f3f0-463e-8508-5f3bd43e9d8e", + "control-id": "cis_rhel10_2-2.2", "description": "REPLACE_ME", "props": [ { @@ -6350,26 +6651,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_sctp_disabled" - } - ] - }, - { - "uuid": "3c795b8f-b4d0-4a00-9fb0-3bea449021f4", - "control-id": "cis_rhel10_5-1.10", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "New templated rule is necessary for \"disableforwarding\" option." + "value": "package_openldap-clients_removed" } ] }, { - "uuid": "b90c6594-b91b-4c82-bace-ad9f7042a085", - "control-id": "cis_rhel10_5-1.11", + "uuid": "6455d544-ad26-4286-b3dd-81b9902b1bfa", + "control-id": "cis_rhel10_5-1.8", "description": "REPLACE_ME", "props": [ { @@ -6380,13 +6668,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_gssapi_auth" + "value": "sshd_disable_forwarding" } ] }, { - "uuid": "0f1045d5-c0cf-4e13-8068-ddb612b04a32", - "control-id": "cis_rhel10_5-2.4", + "uuid": "8ebd258b-9da1-4fc3-bec9-d37b902a33b0", + "control-id": "cis_rhel10_5-1.9", "description": "REPLACE_ME", "props": [ { @@ -6397,13 +6685,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_require_authentication" + "value": "sshd_disable_gssapi_auth" } ] }, { - "uuid": "8802cbe5-d3f7-49bc-a0ba-78318a15de3e", - "control-id": "cis_rhel10_5-3.3.1.3", + "uuid": "a496992f-cfbe-4201-9873-94c35403a6a4", + "control-id": "cis_rhel10_5-2.4", "description": "REPLACE_ME", "props": [ { @@ -6414,12 +6702,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_deny_root" + "value": "sudo_require_authentication" } ] }, { - "uuid": "5bfedf7d-b696-4c0f-bd4d-8c275bb30392", + "uuid": "cbd51f3e-6eb4-40d8-9c54-e790f9991cbb", "control-id": "cis_rhel10_5-4.1.2", "description": "REPLACE_ME", "props": [ @@ -6441,20 +6729,24 @@ ] }, { - "uuid": "ca68dd61-7f3b-4577-b818-4c26006141c8", + "uuid": "da6774d6-f446-44c2-a05a-e422f31d45b4", "control-id": "cis_rhel10_5-4.3.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary to create a new rule to check and remove nologin from /etc/shells.\nThe no_tmux_in_shells rule can be used as referece." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "no_nologin_in_shells" } ] }, { - "uuid": "8c0d1c1f-ecae-45fc-b5b6-96bd563a2ea6", + "uuid": "e7a0c208-a09b-40df-adb6-b610e554767c", "control-id": "cis_rhel10_6-3.1.1", "description": "REPLACE_ME", "props": [ @@ -6476,7 +6768,7 @@ ] }, { - "uuid": "aa16cc8b-6671-4de7-bb94-b5fc76597399", + "uuid": "a722eb4b-1c96-421c-8197-894cbace3060", "control-id": "cis_rhel10_6-3.1.2", "description": "REPLACE_ME", "props": [ @@ -6493,7 +6785,7 @@ ] }, { - "uuid": "42b26039-fdc3-4639-96d6-67ddca1256f5", + "uuid": "e5925f8f-9f1b-480a-9833-c3f6f775f6f6", "control-id": "cis_rhel10_6-3.1.3", "description": "REPLACE_ME", "props": [ @@ -6510,7 +6802,7 @@ ] }, { - "uuid": "d34f3bc6-e137-47e6-8c08-b273e15f1f4d", + "uuid": "321402f4-fee9-4f28-9746-b133b4e70afa", "control-id": "cis_rhel10_6-3.1.4", "description": "REPLACE_ME", "props": [ @@ -6527,7 +6819,7 @@ ] }, { - "uuid": "2f3d933c-2fd8-47e2-a784-b5eabf3b1488", + "uuid": "0dafac6b-76a3-4e15-9ad5-ce0997984dd8", "control-id": "cis_rhel10_6-3.2.1", "description": "REPLACE_ME", "props": [ @@ -6544,7 +6836,7 @@ ] }, { - "uuid": "a86f85c6-ae54-4524-a06a-e4aad669741b", + "uuid": "d8a63285-693c-4265-8055-116b8c7aa18e", "control-id": "cis_rhel10_6-3.2.2", "description": "REPLACE_ME", "props": [ @@ -6561,7 +6853,7 @@ ] }, { - "uuid": "be62d0cb-22b1-4291-9c69-81f9668ad1ca", + "uuid": "4a6d2dab-0db7-428a-904a-d6d4733b34fc", "control-id": "cis_rhel10_6-3.2.3", "description": "REPLACE_ME", "props": [ @@ -6583,7 +6875,7 @@ ] }, { - "uuid": "e188fbd1-cdaf-4cfb-9b4a-b1ad395cfe69", + "uuid": "25575b56-a87d-4e53-9a66-f99892df1506", "control-id": "cis_rhel10_6-3.2.4", "description": "REPLACE_ME", "props": [ @@ -6610,7 +6902,7 @@ ] }, { - "uuid": "9e1bc5d2-bded-4a6b-a271-6ba46e75613f", + "uuid": "4c4912e3-b6b7-4487-8e00-5fe9c48ae9f7", "control-id": "cis_rhel10_6-3.3.1", "description": "REPLACE_ME", "props": [ @@ -6627,7 +6919,7 @@ ] }, { - "uuid": "4d7b6996-78fd-4d1a-8837-5288a685e3a9", + "uuid": "2a207553-46d7-474d-9631-f854f7248e34", "control-id": "cis_rhel10_6-3.3.2", "description": "REPLACE_ME", "props": [ @@ -6644,7 +6936,7 @@ ] }, { - "uuid": "10d249d6-bf12-4905-b8b1-dd00939196bd", + "uuid": "569a60d1-d877-4a9c-bd43-f10ad8711e1b", "control-id": "cis_rhel10_6-3.3.3", "description": "REPLACE_ME", "props": [ @@ -6661,7 +6953,7 @@ ] }, { - "uuid": "c33b9de2-1255-4c10-9b40-8e8d4fad064d", + "uuid": "ac5b9a8a-2105-4cab-8818-e58d07a2609d", "control-id": "cis_rhel10_6-3.3.4", "description": "REPLACE_ME", "props": [ @@ -6693,19 +6985,55 @@ ] }, { - "uuid": "5a956772-659f-4196-9d21-81b2bca995aa", + "uuid": "28f52ae6-e87f-4e90-b621-4578c75be4a4", "control-id": "cis_rhel10_6-3.3.5", - "description": "These rules are not covering \"/etc/hostname\" and \"/etc/NetworkManager/\".", + "description": "This requirement is covered by 6.3.3.6.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "implemented" + } + ] + }, + { + "uuid": "aeb5a279-8135-4cb2-b716-9959855406a0", + "control-id": "cis_rhel10_6-3.3.6", + "description": "REPLACE_ME", + "props": [ + { + "name": "implementation-status", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_networkconfig_modification" + } + ] + }, + { + "uuid": "bbb3fe63-07e3-4acd-8af4-46ffef8e9cc7", + "control-id": "cis_rhel10_6-3.3.7", + "description": "This requirement is partially covered by 6.3.3.6.", + "props": [ + { + "name": "implementation-status", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "implemented" + } + ] + }, + { + "uuid": "9f985e10-e5e4-469b-a1b7-7c4af5918a8c", + "control-id": "cis_rhel10_6-3.3.8", + "description": "This requirement is partially covered by 6.3.3.6.", + "props": [ + { + "name": "implementation-status", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "implemented" }, { "name": "Rule_Id", @@ -6715,8 +7043,20 @@ ] }, { - "uuid": "a58767f8-7482-445b-945d-650ec8a34db8", - "control-id": "cis_rhel10_6-3.3.6", + "uuid": "908274b7-e0a9-4737-b344-2fdf99eb157f", + "control-id": "cis_rhel10_6-3.3.9", + "description": "This requirement is covered by 6.3.3.6.", + "props": [ + { + "name": "implementation-status", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "implemented" + } + ] + }, + { + "uuid": "456abe25-816d-4b47-b121-6c00aa31ab43", + "control-id": "cis_rhel10_6-3.3.10", "description": "REPLACE_ME", "props": [ { @@ -6732,8 +7072,8 @@ ] }, { - "uuid": "55a5611f-72b6-4fcc-a13d-668be79d817b", - "control-id": "cis_rhel10_6-3.3.7", + "uuid": "cdc357a1-ba4a-4b8d-9acf-2d903716003e", + "control-id": "cis_rhel10_6-3.3.11", "description": "REPLACE_ME", "props": [ { @@ -6769,45 +7109,42 @@ ] }, { - "uuid": "8ddb4466-c4e7-430a-afb0-2e7305f69058", - "control-id": "cis_rhel10_6-3.3.8", - "description": "Missing rules to check \"/etc/nsswitch.conf\", \"/etc/pam.conf\" and \"/etc/pam.d\"", + "uuid": "4b9a61e0-c664-44ca-82ab-44a179cf63a3", + "control-id": "cis_rhel10_6-3.3.12", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_usergroup_modification_group" - }, + } + ] + }, + { + "uuid": "3554aecb-cf71-447d-9abb-0450575cfdd2", + "control-id": "cis_rhel10_6-3.3.13", + "description": "REPLACE_ME", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_gshadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_opasswd" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_usergroup_modification_passwd" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_shadow" } ] }, { - "uuid": "1f26708d-f3b5-437c-b189-a7265c010b47", - "control-id": "cis_rhel10_6-3.3.9", + "uuid": "b1041e93-8530-4e91-930c-8a7fb7017111", + "control-id": "cis_rhel10_6-3.3.14", "description": "REPLACE_ME", "props": [ { @@ -6818,78 +7155,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_chmod" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_chown" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchmod" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchmodat" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchmodat2" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchown" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchownat" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fremovexattr" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fsetxattr" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_lchown" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_lremovexattr" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_lsetxattr" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_removexattr" + "value": "audit_rules_usergroup_modification_gshadow" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_setxattr" + "value": "audit_rules_usergroup_modification_shadow" } ] }, { - "uuid": "a317cad4-3a8e-46bc-b394-2f2132cdae83", - "control-id": "cis_rhel10_6-3.3.10", + "uuid": "54ff4043-ee38-4109-824a-8b9eaf1346e8", + "control-id": "cis_rhel10_6-3.3.15", "description": "REPLACE_ME", "props": [ { @@ -6900,62 +7177,39 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_media_export" + "value": "audit_rules_usergroup_modification_opasswd" } ] }, { - "uuid": "87e4fd2b-170c-4426-bf43-fcfa5b4d0d63", - "control-id": "cis_rhel10_6-3.3.11", + "uuid": "fafdf43e-08ac-4ea2-aba4-6f2b4435ada8", + "control-id": "cis_rhel10_6-3.3.16", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_session_events_utmp" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_session_events_btmp" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_session_events_wtmp" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "25731d29-d4b8-494d-bf29-83d8a7ddbe22", - "control-id": "cis_rhel10_6-3.3.12", + "uuid": "d2e79189-37cd-4442-ad2f-342d3863d900", + "control-id": "cis_rhel10_6-3.3.17", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_login_events_faillock" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_login_events_lastlog" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "64be7ad0-6a75-4caa-8cbb-9b6196557439", - "control-id": "cis_rhel10_6-3.3.13", + "uuid": "45ae2d82-14f7-498d-9491-b9616d5251ef", + "control-id": "cis_rhel10_6-3.3.18", "description": "REPLACE_ME", "props": [ { @@ -6966,33 +7220,28 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_rename" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_renameat" + "value": "audit_rules_dac_modification_chmod" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_renameat2" + "value": "audit_rules_dac_modification_fchmod" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_unlink" + "value": "audit_rules_dac_modification_fchmodat" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_unlinkat" + "value": "audit_rules_dac_modification_fchmodat2" } ] }, { - "uuid": "287e098d-d4f3-4e85-bc38-c0371c2a747b", - "control-id": "cis_rhel10_6-3.3.14", + "uuid": "5a728930-b51c-4802-889c-10564aed41c8", + "control-id": "cis_rhel10_6-3.3.19", "description": "REPLACE_ME", "props": [ { @@ -7003,69 +7252,28 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_mac_modification_etc_selinux" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_mac_modification_usr_share" - } - ] - }, - { - "uuid": "091af50b-7c82-4317-8475-f45a878c05b3", - "control-id": "cis_rhel10_6-3.3.15", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "audit_rules_dac_modification_chown" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_execution_chcon" - } - ] - }, - { - "uuid": "06091fa2-7547-4051-ac43-fbe82c88eaa2", - "control-id": "cis_rhel10_6-3.3.16", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "audit_rules_dac_modification_fchown" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_execution_setfacl" - } - ] - }, - { - "uuid": "874fe4c5-94c4-434b-8373-2fa25f9b14f0", - "control-id": "cis_rhel10_6-3.3.17", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "audit_rules_dac_modification_fchownat" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_execution_chacl" + "value": "audit_rules_dac_modification_lchown" } ] }, { - "uuid": "cd1e6098-4067-4727-9b5c-e1c83a7b870b", - "control-id": "cis_rhel10_6-3.3.18", + "uuid": "c66e2d8b-f76a-4b6f-bde0-81350d25fa52", + "control-id": "cis_rhel10_6-3.3.20", "description": "REPLACE_ME", "props": [ { @@ -7076,50 +7284,38 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_privileged_commands_usermod" - } - ] - }, - { - "uuid": "c5979d40-20ce-41ac-b183-49967aac1550", - "control-id": "cis_rhel10_6-3.3.19", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "audit_rules_dac_modification_fremovexattr" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_delete" + "value": "audit_rules_dac_modification_fsetxattr" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_finit" + "value": "audit_rules_dac_modification_lremovexattr" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_init" + "value": "audit_rules_dac_modification_lsetxattr" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_query" + "value": "audit_rules_dac_modification_removexattr" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_privileged_commands_kmod" + "value": "audit_rules_dac_modification_setxattr" } ] }, { - "uuid": "cf7b2394-88a6-4a60-88c9-9143ba1e57bb", - "control-id": "cis_rhel10_6-3.3.20", + "uuid": "ee0b4305-d3a2-471b-b966-f17ded6574fc", + "control-id": "cis_rhel10_6-3.3.21", "description": "REPLACE_ME", "props": [ { @@ -7130,25 +7326,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_immutable" - } - ] - }, - { - "uuid": "32bb2536-37b3-49f3-9792-de9ad4e04576", - "control-id": "cis_rhel10_6-3.3.21", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "audit_rules_media_export" } ] }, { - "uuid": "a642d522-ecd6-4af7-9807-2b69ca092928", + "uuid": "9a70e04a-1fb7-4bea-a48e-ee82fdc5a40c", "control-id": "cis_rhel10_6-3.4.1", "description": "REPLACE_ME", "props": [ @@ -7165,7 +7348,7 @@ ] }, { - "uuid": "4e85cc9d-b33d-4d01-8318-f5f049dc009a", + "uuid": "5018be94-bccc-463b-9393-b52bb35c2d45", "control-id": "cis_rhel10_6-3.4.2", "description": "REPLACE_ME", "props": [ @@ -7182,7 +7365,7 @@ ] }, { - "uuid": "f1d0f8a8-0038-41be-b05c-3b8cdd6409a2", + "uuid": "c8c9f07d-2499-4b27-a459-4447c6e1d037", "control-id": "cis_rhel10_6-3.4.3", "description": "REPLACE_ME", "props": [ @@ -7199,7 +7382,7 @@ ] }, { - "uuid": "e045bf11-c2a7-4fe3-9693-d4946ed0d27c", + "uuid": "d05c5e8e-105f-4b4d-bc80-a7eb5b25e5ed", "control-id": "cis_rhel10_6-3.4.4", "description": "REPLACE_ME", "props": [ @@ -7216,7 +7399,7 @@ ] }, { - "uuid": "a348d974-3b7e-4d83-b571-b13f1f857f47", + "uuid": "40deaa11-a317-41bb-9401-b4943e03421b", "control-id": "cis_rhel10_6-3.4.5", "description": "REPLACE_ME", "props": [ @@ -7233,7 +7416,7 @@ ] }, { - "uuid": "91cb2ca1-8754-46f0-89af-15e622303541", + "uuid": "83177a3f-7d3c-4d6c-a0b8-c2fe621b710a", "control-id": "cis_rhel10_6-3.4.6", "description": "REPLACE_ME", "props": [ @@ -7250,7 +7433,7 @@ ] }, { - "uuid": "c0a56e89-51fc-4902-9861-663235021410", + "uuid": "f79b8ebc-5e9c-4e7b-aa00-92d32667e065", "control-id": "cis_rhel10_6-3.4.7", "description": "REPLACE_ME", "props": [ @@ -7267,7 +7450,7 @@ ] }, { - "uuid": "11b5e5f1-83fd-4674-8818-759150a1b1cf", + "uuid": "dfacbaf9-f96d-4bbf-ae72-e48ff9cba7eb", "control-id": "cis_rhel10_6-3.4.8", "description": "REPLACE_ME", "props": [ @@ -7284,7 +7467,7 @@ ] }, { - "uuid": "2ca30aaa-b21d-4b9b-800a-d5c4f724cc39", + "uuid": "93c51af1-b111-471c-ac26-bf642ef5dd47", "control-id": "cis_rhel10_6-3.4.9", "description": "REPLACE_ME", "props": [ @@ -7301,7 +7484,7 @@ ] }, { - "uuid": "b175731a-06dc-4fa3-ac67-1f1eecf6a504", + "uuid": "d0e03593-534c-42dc-b2f2-f79608cfd725", "control-id": "cis_rhel10_6-3.4.10", "description": "REPLACE_ME", "props": [ @@ -7318,20 +7501,7 @@ ] }, { - "uuid": "90c4af75-4c9b-46bc-9fa4-ce8717462baa", - "control-id": "cis_rhel10_7-1.14", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } - ] - }, - { - "uuid": "2e1ebf8c-04f3-49ee-ab02-fa5c09809fbc", + "uuid": "d1a95900-9526-4ace-bfdd-584da8ad1d60", "control-id": "reload_dconf_db", "description": "This is a helper rule to reload Dconf database correctly.", "props": [ @@ -7348,8 +7518,8 @@ ] }, { - "uuid": "1ba89124-1782-4939-aa55-1341e66507a7", - "control-id": "cis_rhel10_1-1.1.8", + "uuid": "47dd7a4f-947e-4f25-a2e1-2461d17094ae", + "control-id": "cis_rhel10_1-1.1.9", "description": "REPLACE_ME", "props": [ { @@ -7360,25 +7530,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_usb-storage_disabled" - } - ] - }, - { - "uuid": "33123b5c-ff5e-4cb7-bcf7-fc79a1d39de9", - "control-id": "cis_rhel10_1-1.1.9", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "kernel_module_firewire-core_disabled" } ] }, { - "uuid": "2edc30a4-8bf3-4cbd-b9a0-3fafa6b8649d", + "uuid": "52a2f4d5-ca61-43ec-8593-773890a18a40", "control-id": "cis_rhel10_1-1.2.1.1", "description": "REPLACE_ME", "props": [ @@ -7395,7 +7552,7 @@ ] }, { - "uuid": "7aee0972-8bd8-479f-a477-2e40af9a249c", + "uuid": "12a20402-3d9f-4e52-9e59-6a994e656beb", "control-id": "cis_rhel10_1-1.2.1.2", "description": "REPLACE_ME", "props": [ @@ -7412,7 +7569,7 @@ ] }, { - "uuid": "af9faae8-ba71-4486-ac9e-24742ababac8", + "uuid": "0ed2619d-e2d6-4ae9-8604-e519a0c9f70d", "control-id": "cis_rhel10_1-1.2.1.3", "description": "REPLACE_ME", "props": [ @@ -7429,7 +7586,7 @@ ] }, { - "uuid": "f4b95de9-e6b7-4675-a2f7-494950c8eb48", + "uuid": "c04d8074-e3ed-43c8-9eeb-7f0787d55e8c", "control-id": "cis_rhel10_1-1.2.1.4", "description": "REPLACE_ME", "props": [ @@ -7446,7 +7603,7 @@ ] }, { - "uuid": "4657620f-5e22-491e-bc7c-884785e19d48", + "uuid": "cdf0a338-7a7e-44df-8908-80900399e04c", "control-id": "cis_rhel10_1-1.2.2.1", "description": "REPLACE_ME", "props": [ @@ -7463,7 +7620,7 @@ ] }, { - "uuid": "9f949712-2ffb-4bcb-9391-802792b32e80", + "uuid": "2b01736e-0d7b-4774-b107-0d8250fc844e", "control-id": "cis_rhel10_1-1.2.2.2", "description": "REPLACE_ME", "props": [ @@ -7480,7 +7637,7 @@ ] }, { - "uuid": "9b48b6a7-6854-40c2-9739-5129d1144c5e", + "uuid": "027ad00c-9ce4-4f15-9c28-34b2c6b42180", "control-id": "cis_rhel10_1-1.2.2.3", "description": "REPLACE_ME", "props": [ @@ -7497,7 +7654,7 @@ ] }, { - "uuid": "2f1736d9-49d1-4204-901a-1e3f483fba6a", + "uuid": "970bc9c1-027c-4c8f-88ee-dbbb83ee86ab", "control-id": "cis_rhel10_1-1.2.2.4", "description": "REPLACE_ME", "props": [ @@ -7514,7 +7671,7 @@ ] }, { - "uuid": "9897c751-2f84-4e5e-a171-73f8e3c1573d", + "uuid": "c70b6087-25e7-41a6-a726-32c5ba9c9a16", "control-id": "cis_rhel10_1-1.2.3.2", "description": "REPLACE_ME", "props": [ @@ -7531,7 +7688,7 @@ ] }, { - "uuid": "9d62500b-477d-4487-8ae3-d1f5608b1581", + "uuid": "74960b3e-9b9e-40d3-bca6-309ca65c4c6f", "control-id": "cis_rhel10_1-1.2.3.3", "description": "REPLACE_ME", "props": [ @@ -7548,7 +7705,7 @@ ] }, { - "uuid": "bcd18350-51ba-4e23-b17d-58ffe0c4b3ef", + "uuid": "574e158c-c07b-4f69-9f7d-332af05cb63f", "control-id": "cis_rhel10_1-1.2.4.2", "description": "REPLACE_ME", "props": [ @@ -7565,7 +7722,7 @@ ] }, { - "uuid": "161d4559-d71d-47ea-83e1-7c352b904d99", + "uuid": "593c17bd-739d-4f57-8af8-d7659ef62bba", "control-id": "cis_rhel10_1-1.2.4.3", "description": "REPLACE_ME", "props": [ @@ -7582,7 +7739,7 @@ ] }, { - "uuid": "c07d485b-8e06-46fa-a00e-f1ab04996f84", + "uuid": "af3368ee-6b55-4759-98eb-0e1e23b511ea", "control-id": "cis_rhel10_1-1.2.5.2", "description": "REPLACE_ME", "props": [ @@ -7599,7 +7756,7 @@ ] }, { - "uuid": "1de7363c-b72e-4b6e-a8c7-c533715e8610", + "uuid": "569c2177-16f4-4980-9d08-641a8b749525", "control-id": "cis_rhel10_1-1.2.5.3", "description": "REPLACE_ME", "props": [ @@ -7616,7 +7773,7 @@ ] }, { - "uuid": "be99d399-35e3-4b45-bf9f-218f873c890b", + "uuid": "07f1739e-7c9a-4552-932d-a2bc74b2d462", "control-id": "cis_rhel10_1-1.2.5.4", "description": "REPLACE_ME", "props": [ @@ -7633,7 +7790,7 @@ ] }, { - "uuid": "1e382e5e-c657-43a2-b75a-36c43ce70dbc", + "uuid": "b1fa83ed-3b20-4e7c-a14e-9e1ab34e46ff", "control-id": "cis_rhel10_1-1.2.6.2", "description": "REPLACE_ME", "props": [ @@ -7650,7 +7807,7 @@ ] }, { - "uuid": "85da890e-84bd-4ec4-b58e-694f92af0615", + "uuid": "9d0ead29-c27a-4e99-9e1d-57df151ddd33", "control-id": "cis_rhel10_1-1.2.6.3", "description": "REPLACE_ME", "props": [ @@ -7667,7 +7824,7 @@ ] }, { - "uuid": "2853a0d9-ccc5-4c6f-b548-05deb427ece4", + "uuid": "e6b3269d-745e-460d-ae93-7325bf5743b5", "control-id": "cis_rhel10_1-1.2.6.4", "description": "REPLACE_ME", "props": [ @@ -7684,7 +7841,7 @@ ] }, { - "uuid": "00959d7f-1bcd-4b7c-b74f-2bc7efec56d4", + "uuid": "b8271b17-89c5-412c-890d-b74ce4fc245c", "control-id": "cis_rhel10_1-1.2.7.2", "description": "REPLACE_ME", "props": [ @@ -7701,7 +7858,7 @@ ] }, { - "uuid": "126c5a4c-3886-4392-b448-4ab0c6b12963", + "uuid": "e4275935-f1df-4a77-b278-6b83169581e2", "control-id": "cis_rhel10_1-1.2.7.3", "description": "REPLACE_ME", "props": [ @@ -7718,7 +7875,7 @@ ] }, { - "uuid": "ed3dfbcc-cd56-43b6-b0d1-4b60469e0d10", + "uuid": "4a61f01a-7206-4fc5-b4fa-641d70b6ecf1", "control-id": "cis_rhel10_1-1.2.7.4", "description": "REPLACE_ME", "props": [ @@ -7735,7 +7892,7 @@ ] }, { - "uuid": "dd644932-ef98-4513-8f56-94c81883dac4", + "uuid": "cfcc54a4-e92b-4c01-a2fd-09f4eeab7826", "control-id": "cis_rhel10_1-2.1.1", "description": "REPLACE_ME", "props": [ @@ -7748,7 +7905,7 @@ ] }, { - "uuid": "6a16c817-2b5c-4773-a3d8-2dd65695fb4a", + "uuid": "80daef0a-89cb-433f-b90a-07a238a9e711", "control-id": "cis_rhel10_1-2.1.2", "description": "REPLACE_ME", "props": [ @@ -7765,7 +7922,7 @@ ] }, { - "uuid": "384dcaaf-429b-4c3d-8729-f597f7671e12", + "uuid": "5b19f7b5-66c9-4e9b-b094-a3d857a8bc50", "control-id": "cis_rhel10_1-2.1.4", "description": "REPLACE_ME", "props": [ @@ -7778,7 +7935,7 @@ ] }, { - "uuid": "b7775ea6-8b8d-47c9-9666-441e7af8d9b3", + "uuid": "85c4583e-c0a9-4186-b47d-3ea665ad713f", "control-id": "cis_rhel10_1-2.2.1", "description": "REPLACE_ME", "props": [ @@ -7791,7 +7948,7 @@ ] }, { - "uuid": "96b4efac-d8ac-4b69-a8cf-3d26020a70b5", + "uuid": "fc688afd-4831-4531-805a-ad3e607ad61a", "control-id": "cis_rhel10_1-3.1.1", "description": "REPLACE_ME", "props": [ @@ -7808,7 +7965,7 @@ ] }, { - "uuid": "1eface02-27bf-429c-aa0d-3388477daca8", + "uuid": "23af863d-3ce9-4cd4-a2f1-5ae1303694d7", "control-id": "cis_rhel10_1-3.1.2", "description": "REPLACE_ME", "props": [ @@ -7825,7 +7982,7 @@ ] }, { - "uuid": "264e7855-c4d8-420f-b216-292168deb4a4", + "uuid": "a92a8266-ae3b-49aa-97cc-ab4594f25cc4", "control-id": "cis_rhel10_1-3.1.3", "description": "REPLACE_ME", "props": [ @@ -7842,7 +7999,7 @@ ] }, { - "uuid": "1618f180-f855-45bb-bce0-ad7240699e43", + "uuid": "c20b3f50-c61e-48a3-96a2-0d5dd4fa910e", "control-id": "cis_rhel10_1-3.1.4", "description": "REPLACE_ME", "props": [ @@ -7859,7 +8016,7 @@ ] }, { - "uuid": "34ae9a6d-0ec0-457c-b464-3c220af5cc46", + "uuid": "849bc19f-64eb-4690-86f2-a90acc0db40f", "control-id": "cis_rhel10_1-3.1.7", "description": "REPLACE_ME", "props": [ @@ -7876,7 +8033,7 @@ ] }, { - "uuid": "5192c59d-0b34-4625-8f67-91cc5d525923", + "uuid": "2195c8be-5472-4b00-9b10-af255060c584", "control-id": "cis_rhel10_1-3.1.8", "description": "REPLACE_ME", "props": [ @@ -7893,7 +8050,7 @@ ] }, { - "uuid": "ddf23022-e7a7-43ac-82f6-4715eed5aae5", + "uuid": "ea06342d-9a78-4b54-ac0e-5345bb7ee7fd", "control-id": "cis_rhel10_1-4.1", "description": "There is no automated remediation for this rule and this is intentional.\nMore details in the rule description.", "props": [ @@ -7910,7 +8067,7 @@ ] }, { - "uuid": "b1db337a-992b-4615-b41a-f176025028d7", + "uuid": "952376b2-0ba2-4a72-90a9-f2df5e0cadcc", "control-id": "cis_rhel10_1-4.2", "description": "REPLACE_ME", "props": [ @@ -7953,25 +8110,8 @@ ] }, { - "uuid": "dbc42b58-d241-4179-bf7b-5260d2b4c3ef", + "uuid": "41900acb-8eff-418d-b383-a76ae4337426", "control-id": "cis_rhel10_1-5.1", - "description": "Address Space Layout Randomization (ASLR)", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_kernel_randomize_va_space" - } - ] - }, - { - "uuid": "d772479f-e9ae-4a1c-9078-a51ed8207a97", - "control-id": "cis_rhel10_1-5.2", "description": "REPLACE_ME", "props": [ { @@ -7982,13 +8122,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_kernel_yama_ptrace_scope" + "value": "disable_users_coredumps" } ] }, { - "uuid": "d033cc28-2195-49ab-8362-fe87a2dae469", - "control-id": "cis_rhel10_1-5.3", + "uuid": "98586595-5a9c-4c68-9bcf-dd2f1186dd1e", + "control-id": "cis_rhel10_1-5.2", "description": "REPLACE_ME", "props": [ { @@ -7999,12 +8139,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_backtraces" + "value": "sysctl_fs_protected_hardlinks" } ] }, { - "uuid": "4d24e0e1-fbbf-46de-b4c1-ad8f4323c702", + "uuid": "ba3cf485-38be-4303-9954-ff6e8da62a9e", "control-id": "cis_rhel10_1-5.4", "description": "REPLACE_ME", "props": [ @@ -8016,12 +8156,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_storage" + "value": "sysctl_fs_suid_dumpable" } ] }, { - "uuid": "9a492f1d-a2bb-4362-af8e-b9a4efbb30f5", + "uuid": "28a34fbf-c788-489a-8cf7-1a65828bdaec", "control-id": "cis_rhel10_1-6.1", "description": "REPLACE_ME", "props": [ @@ -8038,37 +8178,21 @@ ] }, { - "uuid": "5914c960-2fd5-41b2-9564-7da9aad3871b", + "uuid": "3143e598-4ddc-4b9c-9e7a-37d9db17554c", "control-id": "cis_rhel10_1-6.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_ssh_crypto_policy" + "value": "alternative", + "remarks": "It is necessary a new rule to ensure a module disabling sha1 in\n/etc/crypto-policies/policies/modules/ so it can be used by update-crypto-policies command." } ] }, { - "uuid": "27209fd9-3081-457f-88e8-d39886d46243", + "uuid": "c6822304-84ba-4055-b8a7-f5dde58619a7", "control-id": "cis_rhel10_1-6.3", - "description": "This requirement is already satisfied by 1.6.1.", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - } - ] - }, - { - "uuid": "9f5675c3-b22d-4ce3-8b64-d8ca9636c018", - "control-id": "cis_rhel10_1-6.4", "description": "REPLACE_ME", "props": [ { @@ -8080,8 +8204,8 @@ ] }, { - "uuid": "578e9b8b-8b77-4390-ae0b-e3730d779594", - "control-id": "cis_rhel10_1-6.5", + "uuid": "0c9150e0-1de3-4c9c-b0e2-eb25ec477a17", + "control-id": "cis_rhel10_1-6.4", "description": "REPLACE_ME", "props": [ { @@ -8093,34 +8217,8 @@ ] }, { - "uuid": "8ede8f48-5686-4f69-b494-d65854f876bb", - "control-id": "cis_rhel10_1-6.6", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } - ] - }, - { - "uuid": "606c9f5c-22e4-414d-bb76-045cda7a927d", - "control-id": "cis_rhel10_1-6.7", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } - ] - }, - { - "uuid": "bbbca5f9-c336-4174-8c22-2d2f260ff3a2", - "control-id": "cis_rhel10_1-7.1", + "uuid": "9fd24ec4-f0e5-45d8-b310-affa3ca3bcda", + "control-id": "cis_rhel10_1-7.1", "description": "REPLACE_ME", "props": [ { @@ -8136,7 +8234,7 @@ ] }, { - "uuid": "5f5c8f09-f862-4e2b-9811-624390f7323b", + "uuid": "3ee36f1f-c355-424d-bd9d-06d9774a1900", "control-id": "cis_rhel10_1-7.2", "description": "REPLACE_ME", "props": [ @@ -8153,7 +8251,7 @@ ] }, { - "uuid": "374d5199-2e84-484a-9106-c0024ee7921e", + "uuid": "54f3b045-45db-46a9-8a29-30ac7bde0ead", "control-id": "cis_rhel10_1-7.3", "description": "REPLACE_ME", "props": [ @@ -8170,7 +8268,7 @@ ] }, { - "uuid": "fc1e252a-1aca-4c4e-8eb7-57ad41505c13", + "uuid": "6f120290-6ff1-4edb-a90f-d39d88c421cb", "control-id": "cis_rhel10_1-7.4", "description": "REPLACE_ME", "props": [ @@ -8197,7 +8295,7 @@ ] }, { - "uuid": "2cc81f50-d470-484c-80f0-0afb69683944", + "uuid": "f556a932-d591-4b63-800f-c2bb71967646", "control-id": "cis_rhel10_1-7.5", "description": "REPLACE_ME", "props": [ @@ -8224,7 +8322,7 @@ ] }, { - "uuid": "1edf8b70-47be-4a5c-97f7-91cda70c3c74", + "uuid": "6267f979-f7e0-400f-8285-8e5266e64ed0", "control-id": "cis_rhel10_1-7.6", "description": "REPLACE_ME", "props": [ @@ -8251,8 +8349,8 @@ ] }, { - "uuid": "90e3b35c-aaa8-4679-ad7d-061965ca3f16", - "control-id": "cis_rhel10_1-8.2", + "uuid": "4036fb02-b766-4806-ab26-011ca4ee91b4", + "control-id": "cis_rhel10_1-8.1", "description": "REPLACE_ME", "props": [ { @@ -8273,8 +8371,8 @@ ] }, { - "uuid": "f86ea8fb-0054-4d89-8d80-a450f2af1715", - "control-id": "cis_rhel10_1-8.3", + "uuid": "3fba4969-20de-4ff3-a7c9-2e996896568e", + "control-id": "cis_rhel10_1-8.2", "description": "REPLACE_ME", "props": [ { @@ -8290,8 +8388,8 @@ ] }, { - "uuid": "ab53efff-766a-49bd-89c4-fa3589a2f921", - "control-id": "cis_rhel10_1-8.4", + "uuid": "fa09e944-29cf-4d7c-8b49-d2f949255446", + "control-id": "cis_rhel10_1-8.3", "description": "REPLACE_ME", "props": [ { @@ -8308,18 +8406,6 @@ "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_screensaver_lock_delay" - } - ] - }, - { - "uuid": "59ad8ca6-727b-45b9-bcd2-622e2e2f2066", - "control-id": "cis_rhel10_1-8.5", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" }, { "name": "Rule_Id", @@ -8334,30 +8420,8 @@ ] }, { - "uuid": "feeaece1-e035-470d-9a80-7339ba0c474a", - "control-id": "cis_rhel10_1-8.6", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_automount" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_automount_open" - } - ] - }, - { - "uuid": "d0d41240-c44d-44c4-96b3-11f3abe56c07", - "control-id": "cis_rhel10_1-8.7", + "uuid": "4443ca56-b824-4dbc-92eb-3ef101066844", + "control-id": "cis_rhel10_1-8.4", "description": "REPLACE_ME", "props": [ { @@ -8378,25 +8442,8 @@ ] }, { - "uuid": "e1ca9f1a-a62d-4dc8-bd0f-3d7448324c6f", - "control-id": "cis_rhel10_1-8.8", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_autorun" - } - ] - }, - { - "uuid": "2b79370f-adb1-4df9-bdcc-280a57348bac", - "control-id": "cis_rhel10_1-8.9", + "uuid": "7d404073-cce9-4bfb-b3e9-2071b742964b", + "control-id": "cis_rhel10_1-8.5", "description": "REPLACE_ME", "props": [ { @@ -8412,19 +8459,7 @@ ] }, { - "uuid": "2936fa14-2754-4f2b-972b-3a0022d1475d", - "control-id": "cis_rhel10_1-8.10", - "description": "This was inherited from the RHEL 9 profile.\nHowever, it was reported that XDMCP is no\nlonger in RHEL 10.", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - } - ] - }, - { - "uuid": "0b26b82f-e997-4ab0-bb66-917bb481bc03", + "uuid": "eea5d43f-2e96-4514-99c6-a7a97d66329d", "control-id": "cis_rhel10_2-1.1", "description": "REPLACE_ME", "props": [ @@ -8441,7 +8476,7 @@ ] }, { - "uuid": "f8b25410-8c6d-46d9-b5f5-0a18d64505e1", + "uuid": "2ce36326-0720-4586-8bc2-c1a4d9b62f2f", "control-id": "cis_rhel10_2-1.2", "description": "REPLACE_ME", "props": [ @@ -8458,24 +8493,7 @@ ] }, { - "uuid": "8cf51b4a-f238-4395-9034-c51f4e8380f9", - "control-id": "cis_rhel10_2-1.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_kea_removed" - } - ] - }, - { - "uuid": "a10fc256-cef7-4d3e-9cbe-c2326cac8b9b", + "uuid": "a7080500-921a-4a24-97e1-19c4c2806231", "control-id": "cis_rhel10_2-1.4", "description": "REPLACE_ME", "props": [ @@ -8487,12 +8505,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_bind_removed" + "value": "package_kea_removed" } ] }, { - "uuid": "9f4c0996-96c3-4e23-b569-ef88793d51c1", + "uuid": "d314939a-0eaf-4d7a-af47-1ebdd715f31b", "control-id": "cis_rhel10_2-1.5", "description": "REPLACE_ME", "props": [ @@ -8504,12 +8522,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_dnsmasq_removed" + "value": "package_bind_removed" } ] }, { - "uuid": "b100632d-482e-4fe1-ae7b-cbac311ad463", + "uuid": "1a60f84c-9906-4de5-b778-4bbe2fbcbed5", "control-id": "cis_rhel10_2-1.6", "description": "REPLACE_ME", "props": [ @@ -8521,12 +8539,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_samba_removed" + "value": "package_dnsmasq_removed" } ] }, { - "uuid": "f3f35242-9a60-48b6-85c1-d7d22e463e80", + "uuid": "ea592b55-5617-417a-b6f6-219db1a3b315", "control-id": "cis_rhel10_2-1.7", "description": "REPLACE_ME", "props": [ @@ -8543,7 +8561,7 @@ ] }, { - "uuid": "16716411-0062-4e69-86a5-9c6348f1d44e", + "uuid": "9f817275-28a9-4d99-98a2-81bcdbc489aa", "control-id": "cis_rhel10_2-1.8", "description": "REPLACE_ME", "props": [ @@ -8565,7 +8583,7 @@ ] }, { - "uuid": "aeb270d7-b23b-4ab9-9ac0-9e079253f8dc", + "uuid": "ebda6481-9b7d-45f9-952a-4f8469075022", "control-id": "cis_rhel10_2-1.9", "description": "Many of the libvirt packages used by Enterprise Linux virtualization are dependent on the\nnfs-utils package.", "props": [ @@ -8582,7 +8600,7 @@ ] }, { - "uuid": "678d91c3-2c6a-464f-8138-244f73ba597c", + "uuid": "028892f7-ad4a-4a33-8be3-281e1b42bb7a", "control-id": "cis_rhel10_2-1.10", "description": "REPLACE_ME", "props": [ @@ -8590,13 +8608,18 @@ "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "service_cups_disabled" } ] }, { - "uuid": "ddfdd535-8018-4100-af87-6b5c1fdf70f7", + "uuid": "99fe412f-d9ea-4df0-8530-7b2bd49461b6", "control-id": "cis_rhel10_2-1.11", - "description": "REPLACE_ME", + "description": "Many of the libvirt packages used by Enterprise Linux virtualization, and the nfs-utils\npackage used for The Network File System (NFS), are dependent on the rpcbind package.", "props": [ { "name": "implementation-status", @@ -8606,14 +8629,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_cups_disabled" + "value": "service_rpcbind_disabled" } ] }, { - "uuid": "9e7fd199-0b67-4811-a8de-b8a254c6215c", + "uuid": "d7b3fec1-98cb-4b2f-9e44-9a63a5e5cb47", "control-id": "cis_rhel10_2-1.12", - "description": "Many of the libvirt packages used by Enterprise Linux virtualization, and the nfs-utils\npackage used for The Network File System (NFS), are dependent on the rpcbind package.", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -8623,12 +8646,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_rpcbind_disabled" + "value": "package_rsync_removed" } ] }, { - "uuid": "b7dc95e6-9ff6-4f4f-9630-0c8b13f7aa1d", + "uuid": "154fc9fd-c0df-46e2-8793-b3db05f37cc4", "control-id": "cis_rhel10_2-1.13", "description": "REPLACE_ME", "props": [ @@ -8640,12 +8663,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_rsync_removed" + "value": "package_samba_removed" } ] }, { - "uuid": "a119d6ce-e353-4459-82ee-77b9e852a033", + "uuid": "d5b9b581-e5be-486a-84ce-66780e289281", "control-id": "cis_rhel10_2-1.14", "description": "REPLACE_ME", "props": [ @@ -8662,7 +8685,7 @@ ] }, { - "uuid": "e65f2c95-fc20-4390-9ef5-eb058d78d51e", + "uuid": "ef3c388b-415b-48a9-be19-ce6f0507efb7", "control-id": "cis_rhel10_2-1.15", "description": "REPLACE_ME", "props": [ @@ -8679,7 +8702,7 @@ ] }, { - "uuid": "e6f5ceb4-0f1a-4fc2-9015-573ad8af9c52", + "uuid": "ac389967-9d67-4e3d-a205-f4e7e71299a0", "control-id": "cis_rhel10_2-1.16", "description": "REPLACE_ME", "props": [ @@ -8696,7 +8719,7 @@ ] }, { - "uuid": "6da6b5e4-462f-42b0-8c3c-6691ae7222e3", + "uuid": "80811822-828d-4fab-b885-a8779d015d99", "control-id": "cis_rhel10_2-1.17", "description": "REPLACE_ME", "props": [ @@ -8713,7 +8736,7 @@ ] }, { - "uuid": "5ea51d2d-7684-4318-9c90-c658e79d8245", + "uuid": "82a34fd4-bc6b-4c90-999b-44e8a63a0188", "control-id": "cis_rhel10_2-1.18", "description": "REPLACE_ME", "props": [ @@ -8735,7 +8758,7 @@ ] }, { - "uuid": "ba96f5a0-5592-4f61-bc4c-3c88efc97ffd", + "uuid": "9938aef7-3980-4768-8d39-2c2244d0c6b9", "control-id": "cis_rhel10_2-1.21", "description": "The rule has_nonlocal_mta currently checks for services listening only on port 25,\nbut the policy checks also for ports 465 and 587", "props": [ @@ -8757,7 +8780,7 @@ ] }, { - "uuid": "2b84f0b0-068f-46da-8a7d-3d88fc19b997", + "uuid": "762cf626-ae16-4cba-84c6-5115faeec98f", "control-id": "cis_rhel10_2-1.22", "description": "REPLACE_ME", "props": [ @@ -8770,7 +8793,7 @@ ] }, { - "uuid": "bc94bc48-53f4-40ab-b8a1-b4a56ad64829", + "uuid": "2dd5e752-85c1-49c6-a4f9-72b2c7fda69d", "control-id": "cis_rhel10_2-2.1", "description": "REPLACE_ME", "props": [ @@ -8787,21 +8810,9 @@ ] }, { - "uuid": "0a1eeeb8-e11b-4c75-b505-cc2ff013754d", + "uuid": "b1e3437a-7f00-4c23-8310-8d0523961970", "control-id": "cis_rhel10_2-2.3", "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - } - ] - }, - { - "uuid": "b2cdab7e-7725-44d1-813b-9a7d5865afef", - "control-id": "cis_rhel10_2-2.4", - "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -8816,8 +8827,8 @@ ] }, { - "uuid": "8f35bec8-6efd-4ea3-af3d-30c675fb0cee", - "control-id": "cis_rhel10_2-2.5", + "uuid": "76bcaaa4-5034-46e2-b939-88926ff401de", + "control-id": "cis_rhel10_2-2.4", "description": "REPLACE_ME", "props": [ { @@ -8833,7 +8844,7 @@ ] }, { - "uuid": "79d4c352-2ba7-4c01-a08f-1551cd3e36a8", + "uuid": "023f41f3-8f4a-4500-ae37-b0121a70d0e5", "control-id": "cis_rhel10_2-3.1", "description": "REPLACE_ME", "props": [ @@ -8845,7 +8856,7 @@ ] }, { - "uuid": "652def9d-fd67-4a63-9af0-cb515c4bbf82", + "uuid": "da360ed3-c7db-49c3-9a32-7d3be6492011", "control-id": "cis_rhel10_2-3.2", "description": "REPLACE_ME", "props": [ @@ -8862,7 +8873,7 @@ ] }, { - "uuid": "4abdc415-d5a7-47bf-95bf-188d12e64d89", + "uuid": "a400b6a4-9491-40aa-a6ba-4639b83827b4", "control-id": "cis_rhel10_2-3.3", "description": "REPLACE_ME", "props": [ @@ -8879,7 +8890,7 @@ ] }, { - "uuid": "889e34e6-0c60-4219-813a-4906d78f117a", + "uuid": "d4ef69bc-95fb-48e5-8a20-bbebfd3726cc", "control-id": "cis_rhel10_2-4.1.1", "description": "REPLACE_ME", "props": [ @@ -8901,7 +8912,7 @@ ] }, { - "uuid": "cbbf011a-9da4-4dbd-b336-580c187683c6", + "uuid": "1f7c5603-bcfc-4774-9954-1f077d61a830", "control-id": "cis_rhel10_2-4.1.2", "description": "REPLACE_ME", "props": [ @@ -8928,7 +8939,7 @@ ] }, { - "uuid": "0bd9fe56-e0a4-47e0-adb2-2c13463acedf", + "uuid": "a4d61120-4505-43ab-9e22-e786e645d8a3", "control-id": "cis_rhel10_2-4.1.3", "description": "REPLACE_ME", "props": [ @@ -8955,7 +8966,7 @@ ] }, { - "uuid": "195faec8-9139-4be4-8853-6a78a219ba44", + "uuid": "52e128a7-b6bb-40f2-ae3d-9056a292e5c0", "control-id": "cis_rhel10_2-4.1.4", "description": "REPLACE_ME", "props": [ @@ -8982,7 +8993,7 @@ ] }, { - "uuid": "ddbcb775-d105-44c2-aba7-264057f6e018", + "uuid": "c285019c-572d-4763-981e-f8e2ea8058ef", "control-id": "cis_rhel10_2-4.1.5", "description": "REPLACE_ME", "props": [ @@ -9009,7 +9020,7 @@ ] }, { - "uuid": "134d24e4-fb00-4ae5-b328-d8bebaf07002", + "uuid": "ce59c166-6e60-46a7-b413-b44e1a8bfa60", "control-id": "cis_rhel10_2-4.1.6", "description": "REPLACE_ME", "props": [ @@ -9036,34 +9047,20 @@ ] }, { - "uuid": "32b033f7-969a-4d95-bb85-a274d269f797", + "uuid": "e15c67f5-d897-42d4-891d-bc338a5064c1", "control-id": "cis_rhel10_2-4.1.7", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_d" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_d" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_d" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "2886e3e7-5e80-49d6-9087-cfb4e6750619", + "uuid": "fe77c6e4-c264-403e-b04f-086dace75380", "control-id": "cis_rhel10_2-4.1.8", "description": "REPLACE_ME", "props": [ @@ -9075,32 +9072,22 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_cron_deny_not_exist" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_cron_allow_exists" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_allow" + "value": "file_groupowner_cron_d" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_allow" + "value": "file_owner_cron_d" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_allow" + "value": "file_permissions_cron_d" } ] }, { - "uuid": "f2b4524e-7759-47df-910e-5ab08a7430c1", + "uuid": "6dc38bc9-b5ff-4318-ba45-ba283923a546", "control-id": "cis_rhel10_2-4.2.1", "description": "It is necessary to create a rule to ensure the existence of at.allow.\nfile_cron_allow_exists can be used as reference for a new templated rule.", "props": [ @@ -9132,7 +9119,7 @@ ] }, { - "uuid": "be44ed24-7703-4254-8f07-37be2103ca64", + "uuid": "4a48baa6-6064-41cf-a476-9e4191050240", "control-id": "cis_rhel10_3-1.1", "description": "REPLACE_ME", "props": [ @@ -9145,7 +9132,7 @@ ] }, { - "uuid": "b86ef8da-d2f9-460a-9e28-9d0822d5098b", + "uuid": "90f77e54-7718-4438-8135-9f9a22a6a176", "control-id": "cis_rhel10_3-1.2", "description": "REPLACE_ME", "props": [ @@ -9162,7 +9149,7 @@ ] }, { - "uuid": "80f6bcdb-abe7-474e-a77e-7220610b8f3c", + "uuid": "197ae66c-37da-4b30-ab06-ae371fa3ace8", "control-id": "cis_rhel10_3-1.3", "description": "REPLACE_ME", "props": [ @@ -9179,8 +9166,8 @@ ] }, { - "uuid": "578b2dc0-c5a6-4491-a6b4-3ad802f27b17", - "control-id": "cis_rhel10_3-3.1", + "uuid": "7894928f-73fe-4b09-9e21-6087924cf4d7", + "control-id": "cis_rhel10_3-2.2", "description": "REPLACE_ME", "props": [ { @@ -9191,18 +9178,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_ip_forward" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_forwarding" + "value": "kernel_module_can_disabled" } ] }, { - "uuid": "1674cd96-8090-4f44-8093-3a6caa9b1395", - "control-id": "cis_rhel10_3-3.2", + "uuid": "c315e4b3-4f06-4bf9-b646-d92d3a5b0641", + "control-id": "cis_rhel10_3-2.4", "description": "REPLACE_ME", "props": [ { @@ -9213,18 +9195,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_send_redirects" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_send_redirects" + "value": "kernel_module_tipc_disabled" } ] }, { - "uuid": "dc3b1fdb-57ac-4cb1-a1bf-15ccec3dd3f4", - "control-id": "cis_rhel10_3-3.3", + "uuid": "951f6d7e-b8c0-478a-b12d-509cfa53d510", + "control-id": "cis_rhel10_4-1.1", "description": "REPLACE_ME", "props": [ { @@ -9235,30 +9212,26 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses" + "value": "package_firewalld_installed" } ] }, { - "uuid": "ccce3e98-6c03-46af-9e75-ea8415d0d1fe", - "control-id": "cis_rhel10_3-3.4", + "uuid": "5e072944-8a43-4da4-a543-8ceb56781d11", + "control-id": "cis_rhel10_4-1.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "a132cc64-1cfb-44bb-9a78-f027846a4b95", - "control-id": "cis_rhel10_3-3.5", + "uuid": "c9582f25-9f95-49a4-baaf-1a6ead9d125d", + "control-id": "cis_rhel10_5-1.1", "description": "REPLACE_ME", "props": [ { @@ -9269,28 +9242,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_accept_redirects" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_accept_redirects" + "value": "file_groupowner_sshd_config" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_redirects" + "value": "file_owner_sshd_config" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_redirects" + "value": "file_permissions_sshd_config" } ] }, { - "uuid": "995cce77-7302-489d-9ba6-11978e2681aa", - "control-id": "cis_rhel10_3-3.6", + "uuid": "0d95f1bb-d293-4a3f-9a56-23c710c5f425", + "control-id": "cis_rhel10_5-1.2", "description": "REPLACE_ME", "props": [ { @@ -9301,18 +9269,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_secure_redirects" + "value": "file_groupownership_sshd_private_key" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_ownership_sshd_private_key" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_secure_redirects" + "value": "file_permissions_sshd_private_key" } ] }, { - "uuid": "3e71c13c-3afd-4147-805f-f38b14dbdfc1", - "control-id": "cis_rhel10_3-3.7", + "uuid": "ee27d19e-0585-4fe5-982f-714613e35758", + "control-id": "cis_rhel10_5-1.3", "description": "REPLACE_ME", "props": [ { @@ -9323,18 +9296,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_rp_filter" + "value": "file_groupownership_sshd_pub_key" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_ownership_sshd_pub_key" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_rp_filter" + "value": "file_permissions_sshd_pub_key" } ] }, { - "uuid": "53ae6687-5bc9-473c-941b-3eba1a2cd2f9", - "control-id": "cis_rhel10_3-3.8", + "uuid": "adebc462-f5c4-4ecc-82e4-6d634d10f4fb", + "control-id": "cis_rhel10_5-1.4", "description": "REPLACE_ME", "props": [ { @@ -9345,29 +9323,43 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_accept_source_route" - }, + "value": "sshd_limit_user_access" + } + ] + }, + { + "uuid": "03854c13-0a41-478c-a98e-755056bda186", + "control-id": "cis_rhel10_5-1.5", + "description": "REPLACE_ME", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_accept_source_route" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_source_route" - }, + "value": "sshd_enable_warning_banner_net" + } + ] + }, + { + "uuid": "2e9a9aaa-4a4e-4f3f-8ff3-0f48cbca4450", + "control-id": "cis_rhel10_5-1.6", + "description": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation.", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_source_route" + "value": "implemented" } ] }, { - "uuid": "75d75a43-5927-476a-8cbc-c5bf1787f92f", - "control-id": "cis_rhel10_3-3.9", - "description": "REPLACE_ME", + "uuid": "9a711e5f-7927-46d9-bb73-fcef2838b7f9", + "control-id": "cis_rhel10_5-1.7", + "description": "The requirement gives an example of 45 seconds, but is flexible about the values. It is only\nnecessary to ensure there is a timeout configured in alignment to the site policy.", "props": [ { "name": "implementation-status", @@ -9377,18 +9369,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_log_martians" + "value": "sshd_set_idle_timeout" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_log_martians" + "value": "sshd_set_keepalive" } ] }, { - "uuid": "496bd9c7-f9dc-475e-b9cd-b815c73a768d", - "control-id": "cis_rhel10_3-3.10", + "uuid": "6c344109-c642-421e-9317-e26f7e8fbe9b", + "control-id": "cis_rhel10_5-1.10", "description": "REPLACE_ME", "props": [ { @@ -9399,13 +9391,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_tcp_syncookies" + "value": "disable_host_auth" } ] }, { - "uuid": "acf53e0c-fd2d-4253-a7c8-7c6504770543", - "control-id": "cis_rhel10_3-3.11", + "uuid": "f7ce8d2c-92f3-4f88-8165-a73ea393dfd3", + "control-id": "cis_rhel10_5-1.11", "description": "REPLACE_ME", "props": [ { @@ -9416,35 +9408,31 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_ra" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_ra" + "value": "sshd_disable_rhosts" } ] }, { - "uuid": "0cb36bec-8c81-415b-ab38-52bc0bc18c84", - "control-id": "cis_rhel10_4-1.1", + "uuid": "d125a072-9c9d-406d-9508-4d9e2915d36f", + "control-id": "cis_rhel10_5-1.12", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "alternative", + "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_nftables_installed" + "value": "sshd_use_strong_kex" } ] }, { - "uuid": "ff71a21e-8904-4a3d-9627-90d45042e898", - "control-id": "cis_rhel10_4-1.2", + "uuid": "79e984a0-ddb1-46ce-981e-813795573a46", + "control-id": "cis_rhel10_5-1.13", "description": "REPLACE_ME", "props": [ { @@ -9455,36 +9443,48 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_firewalld_enabled" - }, + "value": "sshd_set_login_grace_time" + } + ] + }, + { + "uuid": "54fce50b-3da7-41e6-91ad-ecbc6385ed23", + "control-id": "cis_rhel10_5-1.14", + "description": "The CIS benchmark is not opinionated about which loglevel is selected here. Here, this\nprofile uses VERBOSE by default, as it allows for the capture of login and logout activity\nas well as key fingerprints.", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_firewalld_installed" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_nftables_disabled" + "value": "sshd_set_loglevel_verbose" } ] }, { - "uuid": "f5264f9a-06ee-4a51-a6ff-b535e47932cd", - "control-id": "cis_rhel10_4-2.1", + "uuid": "73c02c54-3193-4a2b-b53d-6ef5cc082f3b", + "control-id": "cis_rhel10_5-1.15", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "alternative", - "remarks": "REPLACE_ME" + "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_use_strong_macs" } ] }, { - "uuid": "cf807c4c-3cb6-4324-9b31-68e5045ab479", - "control-id": "cis_rhel10_4-2.2", + "uuid": "9fc062ac-34a3-454d-973f-a0232bfa2444", + "control-id": "cis_rhel10_5-1.16", "description": "REPLACE_ME", "props": [ { @@ -9495,67 +9495,64 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "firewalld_loopback_traffic_trusted" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "firewalld_loopback_traffic_restricted" + "value": "sshd_set_max_auth_tries" } ] }, { - "uuid": "a1e2f11e-89ed-406e-8f90-70dca5cbae79", - "control-id": "cis_rhel10_4-3.1", - "description": "RHEL systems use firewalld for firewall management. Although nftables is the default\nback-end for firewalld, it is not recommended to use nftables directly when firewalld\nis in use. When using firewalld the base chains are installed by default.", + "uuid": "2db7c923-8587-49d1-b21e-418b961ecb76", + "control-id": "cis_rhel10_5-1.17", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - } - ] - }, - { - "uuid": "cb930b13-afc0-4585-b335-dc313b77a8fe", - "control-id": "cis_rhel10_4-3.2", - "description": "REPLACE_ME", - "props": [ + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "sshd_set_maxstartups" } ] }, { - "uuid": "6b09bb3f-c351-41b5-a1dc-a0b8950d1e8b", - "control-id": "cis_rhel10_4-3.3", - "description": "RHEL systems use firewalld for firewall management. Although nftables is the default\nback-end for firewalld, it is not recommended to use nftables directly when firewalld\nis in use.", + "uuid": "6ad0d7b3-f1b2-411d-b47b-ba66d817933b", + "control-id": "cis_rhel10_5-1.18", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_set_max_sessions" } ] }, { - "uuid": "f8853849-21e4-4941-ac62-30bb81da3d7e", - "control-id": "cis_rhel10_4-3.4", - "description": "RHEL systems use firewalld for firewall management. Although nftables is the default\nback-end for firewalld, it is not recommended to use nftables directly when firewalld\nis in use.", + "uuid": "0b804beb-435b-498e-acbe-d920a03e5605", + "control-id": "cis_rhel10_5-1.19", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_disable_empty_passwords" } ] }, { - "uuid": "8ba40f50-5db2-4e6f-8d29-cf415e481a68", - "control-id": "cis_rhel10_5-1.1", + "uuid": "312026c2-a8c9-49af-b9ba-70b5342fa916", + "control-id": "cis_rhel10_5-1.20", "description": "REPLACE_ME", "props": [ { @@ -9566,23 +9563,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_sshd_config" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_sshd_config" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_config" + "value": "sshd_disable_root_login" } ] }, { - "uuid": "75964724-952b-4924-a5e2-6513cb1458df", - "control-id": "cis_rhel10_5-1.2", + "uuid": "015733e5-a4a7-4445-b7ce-2bb28791990f", + "control-id": "cis_rhel10_5-1.21", "description": "REPLACE_ME", "props": [ { @@ -9593,23 +9580,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_private_key" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_private_key" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_sshd_private_key" + "value": "sshd_do_not_permit_user_env" } ] }, { - "uuid": "9b47b25a-d361-46e0-9552-6b54f402df09", - "control-id": "cis_rhel10_5-1.3", + "uuid": "158468b3-19e1-4dbc-86b1-47ab817b6c20", + "control-id": "cis_rhel10_5-1.22", "description": "REPLACE_ME", "props": [ { @@ -9620,72 +9597,64 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_pub_key" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_pub_key" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_sshd_pub_key" + "value": "sshd_enable_pam" } ] }, { - "uuid": "24a27abf-34be-4a33-8d9b-73bd46e6e841", - "control-id": "cis_rhel10_5-1.4", + "uuid": "90a3189a-9346-4980-8c3d-4c8da27d03cc", + "control-id": "cis_rhel10_5-2.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "package_sudo_installed" } ] }, { - "uuid": "d0b55296-6b54-422a-9bb9-221f828887db", - "control-id": "cis_rhel10_5-1.5", + "uuid": "3f3cb226-ad3f-4112-b56c-05fa6695ed9e", + "control-id": "cis_rhel10_5-2.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_kex" + "value": "sudo_add_use_pty" } ] }, { - "uuid": "c31146b8-e56b-44b5-a324-08293b7c0d23", - "control-id": "cis_rhel10_5-1.6", + "uuid": "e661f775-5cc1-4059-bce7-97b80e1b37eb", + "control-id": "cis_rhel10_5-2.3", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_macs" + "value": "sudo_custom_logfile" } ] }, { - "uuid": "bbb0a88b-1e29-47ec-8ca1-7578b1f92e62", - "control-id": "cis_rhel10_5-1.7", + "uuid": "6bee05da-bdbe-46fd-bc25-ec4e2be57175", + "control-id": "cis_rhel10_5-2.5", "description": "REPLACE_ME", "props": [ { @@ -9696,13 +9665,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_limit_user_access" + "value": "sudo_require_authentication" } ] }, { - "uuid": "eb94ee61-b661-4a18-9f09-26c6f09230ea", - "control-id": "cis_rhel10_5-1.8", + "uuid": "84ac8e31-19ac-4bfd-9e69-ee284feb51c0", + "control-id": "cis_rhel10_5-2.6", "description": "REPLACE_ME", "props": [ { @@ -9713,14 +9682,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_enable_warning_banner_net" + "value": "sudo_require_reauthentication" } ] }, { - "uuid": "62a2c654-2524-470e-a66d-2adf36db4e34", - "control-id": "cis_rhel10_5-1.9", - "description": "The requirement gives an example of 45 seconds, but is flexible about the values. It is only\nnecessary to ensure there is a timeout configured in alignment to the site policy.", + "uuid": "c28bc3d8-a6d1-47d3-a8c9-60c3850d7adc", + "control-id": "cis_rhel10_5-2.7", + "description": "Members of \"wheel\" or GID 0 groups are checked by default if the group option is not set for\npam_wheel.so module. The recommendation states the group should be empty to reinforce the\nuse of \"sudo\" for privileged access. Therefore, members of these groups should be manually\nchecked or a different group should be informed.", "props": [ { "name": "implementation-status", @@ -9730,36 +9699,31 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_idle_timeout" + "value": "use_pam_wheel_group_for_su" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_keepalive" + "value": "ensure_pam_wheel_group_empty" } ] }, { - "uuid": "6f3ba72e-b2aa-4c10-8117-6b5b72751762", - "control-id": "cis_rhel10_5-1.12", - "description": "REPLACE_ME", + "uuid": "0b5e6005-57a6-4c1e-999a-dc05525b2e89", + "control-id": "cis_rhel10_5-3.1.1", + "description": "This requirement is hard to be automated without any specific requirement. The policy even\nstates that provided commands are examples, other custom settings might be in place and the\nsettings might be different depending on site policies. The other rules will already make\nsure there is a correct autheselect profile regardless of the existing settings. It is\nnecessary to better discuss with CIS Community.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "disable_host_auth" + "value": "partial" } ] }, { - "uuid": "b800a09c-e876-4a88-8e2c-7e180fa5c2c8", - "control-id": "cis_rhel10_5-1.13", - "description": "REPLACE_ME", + "uuid": "dbd5104f-dcd9-488e-b101-0379225efa61", + "control-id": "cis_rhel10_5-3.1.2", + "description": "This requirement is also indirectly satisfied by the requirement 5.3.2.1.", "props": [ { "name": "implementation-status", @@ -9769,31 +9733,19 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_rhosts" - } - ] - }, - { - "uuid": "7cc3cca2-9afc-4c04-9502-8cf537355690", - "control-id": "cis_rhel10_5-1.14", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "account_password_pam_faillock_password_auth" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_login_grace_time" + "value": "account_password_pam_faillock_system_auth" } ] }, { - "uuid": "a8d40478-cf32-43c7-9b67-a22bd3da203f", - "control-id": "cis_rhel10_5-1.15", - "description": "The CIS benchmark is not opinionated about which loglevel is selected here. Here, this\nprofile uses VERBOSE by default, as it allows for the capture of login and logout activity\nas well as key fingerprints.", + "uuid": "c114feca-2f89-4bf9-9229-52be9be574ee", + "control-id": "cis_rhel10_5-3.1.3", + "description": "This requirement is also indirectly satisfied by the requirement 5.3.2.2.", "props": [ { "name": "implementation-status", @@ -9803,13 +9755,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_loglevel_verbose" + "value": "package_pam_pwquality_installed" } ] }, { - "uuid": "dee5fee6-017e-4573-bfa8-8250168e1ca0", - "control-id": "cis_rhel10_5-1.16", + "uuid": "9eb49696-e1e2-4d1b-906f-5a6368044273", + "control-id": "cis_rhel10_5-4.1.1", "description": "REPLACE_ME", "props": [ { @@ -9820,13 +9772,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_max_auth_tries" + "value": "accounts_maximum_age_login_defs" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_password_set_max_life_existing" } ] }, { - "uuid": "d7af1922-6333-4845-a42e-5dc7e4aeaace", - "control-id": "cis_rhel10_5-1.17", + "uuid": "e316b2e0-357a-4d43-8dc3-a80774ff2ac6", + "control-id": "cis_rhel10_5-4.1.3", "description": "REPLACE_ME", "props": [ { @@ -9837,14 +9794,19 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_maxstartups" + "value": "accounts_password_warn_age_login_defs" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_password_set_warn_age_existing" } ] }, { - "uuid": "bfc0409c-6ec1-4f4c-a436-f49884cd5f66", - "control-id": "cis_rhel10_5-1.18", - "description": "REPLACE_ME", + "uuid": "5f340b41-4be0-4749-8267-433d1c838268", + "control-id": "cis_rhel10_5-4.1.4", + "description": "There's a \"new\" set of options in /etc/login.defs file to define the number of iterations\nperformed during the hashing process.", "props": [ { "name": "implementation-status", @@ -9854,13 +9816,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_max_sessions" + "value": "set_password_hashing_algorithm_libuserconf" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "set_password_hashing_algorithm_logindefs" } ] }, { - "uuid": "a84897e4-0f56-4185-9e47-3f6ddbbf94c4", - "control-id": "cis_rhel10_5-1.19", + "uuid": "1a8069fd-294d-47d9-afec-394c55de8116", + "control-id": "cis_rhel10_5-4.1.5", "description": "REPLACE_ME", "props": [ { @@ -9871,13 +9838,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_empty_passwords" + "value": "account_disable_post_pw_expiration" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_set_post_pw_existing" } ] }, { - "uuid": "dacdff0d-cf4c-4f2d-8698-736e4d9a7cf8", - "control-id": "cis_rhel10_5-1.20", + "uuid": "40a70c15-32c8-4830-bdd3-2560bb9c378c", + "control-id": "cis_rhel10_5-4.1.6", "description": "REPLACE_ME", "props": [ { @@ -9888,13 +9860,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_root_login" + "value": "accounts_password_last_change_is_in_past" } ] }, { - "uuid": "3864b775-d4d5-4520-816d-463162c687d9", - "control-id": "cis_rhel10_5-1.21", + "uuid": "7540c943-02ad-421a-8be4-ae2327dbbc83", + "control-id": "cis_rhel10_5-4.2.1", "description": "REPLACE_ME", "props": [ { @@ -9905,30 +9877,30 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_do_not_permit_user_env" + "value": "accounts_no_uid_except_zero" } ] }, { - "uuid": "49b866e4-a115-4a6c-b5f3-27709162d6d7", - "control-id": "cis_rhel10_5-1.22", - "description": "REPLACE_ME", + "uuid": "f8136fc1-c505-4c20-b973-5e0ce33630c3", + "control-id": "cis_rhel10_5-4.2.2", + "description": "The rule confirms the primary group for root, but doesn't check if any other user are also\nusing GID 0. New rule is necessary.\nThere is assessment but no automated remediation for this rule and this sounds reasonable.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "partial" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_enable_pam" + "value": "accounts_root_gid_zero" } ] }, { - "uuid": "39460094-7b35-468c-844d-785ec8855b01", - "control-id": "cis_rhel10_5-2.1", + "uuid": "286c5141-98db-4cfd-abd1-71955556a586", + "control-id": "cis_rhel10_5-4.2.3", "description": "REPLACE_ME", "props": [ { @@ -9939,13 +9911,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_sudo_installed" + "value": "groups_no_zero_gid_except_root" } ] }, { - "uuid": "c914fd09-3246-468f-b7a9-2e055b8cba16", - "control-id": "cis_rhel10_5-2.2", + "uuid": "4a39ba1b-ffbb-47b1-b5cd-cbb450ded4b5", + "control-id": "cis_rhel10_5-4.2.4", "description": "REPLACE_ME", "props": [ { @@ -9956,13 +9928,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_add_use_pty" + "value": "ensure_root_password_configured" } ] }, { - "uuid": "80b57ede-bc5e-460e-88b1-54edbbc9dbe5", - "control-id": "cis_rhel10_5-2.3", + "uuid": "ff3cd0b1-186f-42ec-9bc0-71772d8f5ac1", + "control-id": "cis_rhel10_5-4.2.5", "description": "REPLACE_ME", "props": [ { @@ -9973,13 +9945,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_custom_logfile" + "value": "accounts_root_path_dirs_no_write" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "root_path_no_dot" } ] }, { - "uuid": "8a32154a-bb6c-4461-971e-877814dc00a4", - "control-id": "cis_rhel10_5-2.5", + "uuid": "ec9d0ff8-dc7a-4b8e-97b8-ec3ba2817855", + "control-id": "cis_rhel10_5-4.2.6", "description": "REPLACE_ME", "props": [ { @@ -9990,13 +9967,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_require_reauthentication" + "value": "accounts_umask_root" } ] }, { - "uuid": "389b97f1-7a9a-4b76-a4dc-b409bfc11c94", - "control-id": "cis_rhel10_5-2.6", + "uuid": "08d428f3-1982-4156-96bf-a5f3a75d1b21", + "control-id": "cis_rhel10_5-4.2.7", "description": "REPLACE_ME", "props": [ { @@ -10007,92 +9984,131 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_require_reauthentication" + "value": "no_password_auth_for_systemaccounts" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "no_shelllogin_for_systemaccounts" } ] }, { - "uuid": "ffbbd0c7-08bf-4444-85e0-13062c4f8592", - "control-id": "cis_rhel10_5-2.7", - "description": "Members of \"wheel\" or GID 0 groups are checked by default if the group option is not set for\npam_wheel.so module. The recommendation states the group should be empty to reinforce the\nuse of \"sudo\" for privileged access. Therefore, members of these groups should be manually\nchecked or a different group should be informed.", + "uuid": "bebd04f5-8603-4ea2-9d4d-2276492d2077", + "control-id": "cis_rhel10_5-4.2.8", + "description": "New rule is necessary.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - }, + } + ] + }, + { + "uuid": "768c37b1-64ef-459b-ba59-b81fa50323e2", + "control-id": "cis_rhel10_5-4.3.2", + "description": "REPLACE_ME", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "use_pam_wheel_group_for_su" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_pam_wheel_group_empty" + "value": "accounts_tmout" } ] }, { - "uuid": "1e58592f-a7ca-4c18-b015-8d199a635a76", - "control-id": "cis_rhel10_5-3.1.1", + "uuid": "bd717485-405d-4904-8884-7e510b8fc12a", + "control-id": "cis_rhel10_5-4.3.3", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary a new rule to ensure PAM package is updated." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_umask_etc_bashrc" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_umask_etc_login_defs" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_umask_etc_profile" } ] }, { - "uuid": "db4c6542-21f1-4b78-a760-e42911459ed2", - "control-id": "cis_rhel10_5-3.1.2", + "uuid": "5bcd29f9-49ec-4804-ba5f-2c254a3814ad", + "control-id": "cis_rhel10_6-1.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary a new rule to ensure authselect package is updated." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "package_aide_installed" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "aide_build_database" } ] }, { - "uuid": "b5781df1-5471-4f8a-991b-dd4dec275504", - "control-id": "cis_rhel10_5-3.1.3", + "uuid": "8fc4c04f-9501-40a3-b5f3-b9c300e87415", + "control-id": "cis_rhel10_6-1.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary a new rule to ensure libpwquality package is updated." + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_pam_pwquality_installed" + "value": "aide_periodic_cron_checking" } ] }, { - "uuid": "8589a5fc-d431-4c3c-a081-fd5dd7d30fd4", - "control-id": "cis_rhel10_5-3.2.1", - "description": "This requirement is hard to be automated without any specific requirement. The policy even\nstates that provided commands are examples, other custom settings might be in place and the\nsettings might be different depending on site policies. The other rules will already make\nsure there is a correct autheselect profile regardless of the existing settings. It is\nnecessary to better discuss with CIS Community.", + "uuid": "3719aa39-6150-4fe6-91ca-5a4af0a8e6bf", + "control-id": "cis_rhel10_6-1.3", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "aide_check_audit_tools" } ] }, { - "uuid": "c69fbc35-7aa4-4cb6-ad29-112da4295e4a", - "control-id": "cis_rhel10_5-3.2.2", - "description": "This requirement is also indirectly satisfied by the requirement 5.3.3.1.", + "uuid": "26c8d6ff-da3f-476e-b1b0-fb7669f47ee1", + "control-id": "cis_rhel10_6-2.1.1", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -10102,72 +10118,66 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_password_auth" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_system_auth" + "value": "service_systemd-journald_enabled" } ] }, { - "uuid": "104d8f08-0cf8-4517-a70e-63cdc49598e6", - "control-id": "cis_rhel10_5-3.2.3", - "description": "This requirement is also indirectly satisfied by the requirement 5.3.3.2.", + "uuid": "22025fc2-b9c9-4357-96a6-a7faedcba5b2", + "control-id": "cis_rhel10_6-2.1.2", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "21e428e5-e8de-40a2-a271-305932bcee49", - "control-id": "cis_rhel10_5-3.2.4", - "description": "The module is properly enabled by the rules mentioned in related_rules.\nRequirements in 5.3.3.3 use these rules.", + "uuid": "6b317638-40b9-4f9a-bd50-223d7f604fb9", + "control-id": "cis_rhel10_6-2.1.3", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "7996dff0-b0db-4a1a-9967-efe241383753", - "control-id": "cis_rhel10_5-3.2.5", - "description": "This module is always present by default. It is necessary to investigate if a new rule to\ncheck its existence needs to be created. But so far the rule no_empty_passwords, used in\n5.3.3.4 can ensure this requirement is attended.", + "uuid": "8064dc99-0da8-4e27-8131-021de8112011", + "control-id": "cis_rhel10_6-2.1.4", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "alternative", + "remarks": "It is necessary to create a new rule to check the status of journald and rsyslog.\nIt would also be necessary a new rule to disable or remove rsyslog." } ] }, { - "uuid": "44420b5d-130c-4014-8508-5a301af31133", - "control-id": "cis_rhel10_5-3.3.1.1", + "uuid": "8d35117a-e1ae-4460-a7e9-766a92ab077c", + "control-id": "cis_rhel10_6-2.2.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_deny" + "value": "alternative", + "remarks": "This rule conflicts with 6.2.3.3. More investigation is needed to properly solve this." } ] }, { - "uuid": "e3fa8d30-f4b2-48f6-b00a-5c42a5b5cc3a", - "control-id": "cis_rhel10_5-3.3.1.2", - "description": "The policy also accepts value 0, which means the locked accounts should be manually unlocked\nby an administrator. However, it also mentions that using value 0 can facilitate a DoS\nattack to legitimate users.", + "uuid": "692b1a72-6367-4134-9515-fb9c40ef40a2", + "control-id": "cis_rhel10_6-2.2.3", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -10177,13 +10187,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_unlock_time" + "value": "journald_compress" } ] }, { - "uuid": "de2396dd-252b-41d4-96ed-56633c08070a", - "control-id": "cis_rhel10_5-3.3.2.1", + "uuid": "b14666a5-011e-4e16-9c37-d247d3cd6aac", + "control-id": "cis_rhel10_6-2.2.4", "description": "REPLACE_ME", "props": [ { @@ -10194,13 +10204,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_difok" + "value": "journald_storage" } ] }, { - "uuid": "2c23213b-8f33-41af-8f60-4455a5af774f", - "control-id": "cis_rhel10_5-3.3.2.2", + "uuid": "f9bce2ac-b116-4f3c-80d1-91c22d16a671", + "control-id": "cis_rhel10_6-2.2.1.1", "description": "REPLACE_ME", "props": [ { @@ -10211,30 +10221,39 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_minlen" + "value": "package_systemd-journal-remote_installed" } ] }, { - "uuid": "444705fa-9b99-47fb-b075-eadb595dca43", - "control-id": "cis_rhel10_5-3.3.2.3", - "description": "This requirement is expected to be manual. However, in previous versions of the policy\nit was already automated the configuration of \"minclass\" option. This posture was kept for\nRHEL 9 in this new version. Rules related to other options are informed in related_rules.\nIn short, minclass=4 alone can achieve the same result achieved by the combination of the\nother 4 options mentioned in the policy.", + "uuid": "d772106c-e69a-49a6-8530-4dedb5da8cef", + "control-id": "cis_rhel10_6-2.2.1.2", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, + "value": "alternative", + "remarks": "REPLACE_ME" + } + ] + }, + { + "uuid": "5420580d-398a-40cb-b4dd-41959b432ff7", + "control-id": "cis_rhel10_6-2.2.1.3", + "description": "REPLACE_ME", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_minclass" + "value": "alternative", + "remarks": "New templated rule is necessary." } ] }, { - "uuid": "3cce73b0-149f-404f-afa1-de1198205a78", - "control-id": "cis_rhel10_5-3.3.2.4", + "uuid": "d61830fa-bad4-4d4f-a44a-ed2e6d8eddb4", + "control-id": "cis_rhel10_6-2.2.1.4", "description": "REPLACE_ME", "props": [ { @@ -10245,138 +10264,113 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_maxrepeat" + "value": "socket_systemd-journal-remote_disabled" } ] }, { - "uuid": "c35109de-4d4a-4562-b07f-cb18a00e6185", - "control-id": "cis_rhel10_5-3.3.2.5", + "uuid": "934dc6f1-467d-4409-832d-98bd69d7da14", + "control-id": "cis_rhel10_6-2.3.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "planned", - "remarks": "A new templated rule and variable are necessary for the maxsequence option." + "value": "implemented" } ] }, { - "uuid": "22c8f01f-288a-435f-bbb5-0701cde3dad4", - "control-id": "cis_rhel10_5-3.3.2.6", + "uuid": "cf56b2c3-e86d-436d-9064-e9318d8934a1", + "control-id": "cis_rhel10_6-2.3.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_dictcheck" } ] }, { - "uuid": "39d6cee7-65de-408d-b05f-3aba9414388d", - "control-id": "cis_rhel10_5-3.3.2.7", + "uuid": "31e106c4-c9da-43d3-b06b-a5187e2f2dba", + "control-id": "cis_rhel10_6-2.3.3", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_enforce_root" } ] }, { - "uuid": "be8d586b-f1dd-458c-8605-07694df6e358", - "control-id": "cis_rhel10_5-3.3.3.1", - "description": "Although mentioned in the section 5.3.3.3, there is no explicit requirement to configure\nretry option of pam_pwhistory. If come in the future, the rule accounts_password_pam_retry\ncan be used.", + "uuid": "fa71cde7-54b7-4374-8ee9-d6c01ae4fc27", + "control-id": "cis_rhel10_6-2.3.4", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_pwhistory_remember_password_auth" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_pwhistory_remember_system_auth" } ] }, { - "uuid": "e29946b1-6361-4ec0-aed3-33727a4b5804", - "control-id": "cis_rhel10_5-3.3.3.2", + "uuid": "36a96c4f-f14b-45c9-8205-c60c6bca0f2e", + "control-id": "cis_rhel10_6-2.3.5", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "planned", - "remarks": "A new rule needs to be created to check and remediate the enforce_for_root option in\n/etc/security/pwhistory.conf. accounts_password_pam_enforce_root can be used as reference." + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "67420319-6bc9-419f-afbe-6ba4e32c66d4", - "control-id": "cis_rhel10_5-3.3.3.3", - "description": "In RHEL 9 pam_pwhistory is enabled via authselect feature, as required in 5.3.2.4. The\nfeature automatically set \"use_authok\" option. In any case, we don't have a rule to check\nthis option specifically.", + "uuid": "be1b305d-67ba-48a8-9255-41a06df55cf8", + "control-id": "cis_rhel10_6-2.3.6", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "eb687438-fa29-4e37-bf74-5e22ad18e033", - "control-id": "cis_rhel10_5-3.3.4.1", - "description": "The rule more specifically used in this requirement also satify the requirement 5.3.2.5.", + "uuid": "e9dc44ee-9cd3-41e6-9b0b-be7102173684", + "control-id": "cis_rhel10_6-2.3.7", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_empty_passwords" } ] }, { - "uuid": "67bf61b7-3267-4c10-b611-1b0e040239ca", - "control-id": "cis_rhel10_5-3.3.4.2", + "uuid": "f32156cd-b7c8-4111-ae31-7886014567f8", + "control-id": "cis_rhel10_6-2.3.8", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "alternative", - "remarks": "Usage of pam_unix.so module together with \"remember\" option is deprecated and is not\nrecommened by this policy. Instead, it should be used remember option of pam_pwhistory\nmodule, as required in 5.3.3.3.1. See here for more details about pam_unix.so:\nhttps://bugzilla.redhat.com/show_bug.cgi?id=1778929\nA new rule needs to be created to remove the remember option from pam_unix module." + "remarks": "REPLACE_ME" } ] }, { - "uuid": "038efc0b-00e8-4784-afc9-04ddabfe1b4e", - "control-id": "cis_rhel10_5-3.3.4.3", - "description": "Changes in logindefs mentioned in this requirement are more specifically covered by 5.4.1.4", + "uuid": "9de3583b-ef22-418c-8866-ba135274c394", + "control-id": "cis_rhel10_6-2.4.1", + "description": "It is not harmful to run these rules even if rsyslog is not installed or active.", "props": [ { "name": "implementation-status", @@ -10386,30 +10380,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_systemauth" + "value": "rsyslog_files_groupownership" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_passwordauth" - } - ] - }, - { - "uuid": "7cb856d3-7c1a-4241-9be4-db3d8d614eaa", - "control-id": "cis_rhel10_5-3.3.4.4", - "description": "In RHEL 9 pam_unix is enabled by default in all authselect profiles already with the\nuse_authtok option set. In any case, we don't have a rule to check this option specifically,\nlike in 5.3.3.3.3.", - "props": [ + "value": "rsyslog_files_ownership" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "rsyslog_files_permissions" } ] }, { - "uuid": "3a88d4e5-5656-49d6-9a8b-b1ce6087bc61", - "control-id": "cis_rhel10_5-4.1.1", + "uuid": "949d25d8-c6cb-4415-a143-219ef2cc3aa0", + "control-id": "cis_rhel10_7-1.1", "description": "REPLACE_ME", "props": [ { @@ -10420,18 +10407,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_maximum_age_login_defs" + "value": "file_groupowner_etc_passwd" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_set_max_life_existing" + "value": "file_owner_etc_passwd" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_etc_passwd" } ] }, { - "uuid": "eefa30c0-5438-4205-ad0e-a095cc86492b", - "control-id": "cis_rhel10_5-4.1.3", + "uuid": "c8f5783a-4615-4c90-8967-373e1a201fa5", + "control-id": "cis_rhel10_7-1.2", "description": "REPLACE_ME", "props": [ { @@ -10442,19 +10434,24 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_warn_age_login_defs" + "value": "file_groupowner_backup_etc_passwd" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_set_warn_age_existing" + "value": "file_owner_backup_etc_passwd" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_backup_etc_passwd" } ] }, { - "uuid": "38ea09cb-0c71-4fae-b1f8-2149deef4044", - "control-id": "cis_rhel10_5-4.1.4", - "description": "There's a \"new\" set of options in /etc/login.defs file to define the number of iterations\nperformed during the hashing process.", + "uuid": "9656bf67-a4f6-4c1f-94bc-8ed46e55b3c4", + "control-id": "cis_rhel10_7-1.3", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -10464,18 +10461,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_libuserconf" + "value": "file_groupowner_etc_group" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_logindefs" + "value": "file_owner_etc_group" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_etc_group" } ] }, { - "uuid": "2ebf6759-246e-4f6a-92b7-65babb50a354", - "control-id": "cis_rhel10_5-4.1.5", + "uuid": "fc5a7462-92f4-4152-a8a4-6edaadd9c9b1", + "control-id": "cis_rhel10_7-1.4", "description": "REPLACE_ME", "props": [ { @@ -10486,18 +10488,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_disable_post_pw_expiration" + "value": "file_groupowner_backup_etc_group" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_set_post_pw_existing" + "value": "file_owner_backup_etc_group" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_backup_etc_group" } ] }, { - "uuid": "f9a62947-00c1-4d0e-8198-1402daad1ba6", - "control-id": "cis_rhel10_5-4.1.6", + "uuid": "d944666a-413b-430f-8a4d-5b8ab2759705", + "control-id": "cis_rhel10_7-1.5", "description": "REPLACE_ME", "props": [ { @@ -10508,13 +10515,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_last_change_is_in_past" + "value": "file_owner_etc_shadow" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_groupowner_etc_shadow" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_etc_shadow" } ] }, { - "uuid": "6c0fe2df-9b28-45fe-819b-9f38c823f616", - "control-id": "cis_rhel10_5-4.2.1", + "uuid": "36530f85-84f1-428a-b8fe-e6dd93932a90", + "control-id": "cis_rhel10_7-1.6", "description": "REPLACE_ME", "props": [ { @@ -10525,43 +10542,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_no_uid_except_zero" - } - ] - }, - { - "uuid": "adf1a72c-f0a6-4c23-8b20-f923db08b5ae", - "control-id": "cis_rhel10_5-4.2.2", - "description": "The rule confirms the primary group for root, but doesn't check if any other user are also\nusing GID 0. New rule is necessary.\nThere is assessment but no automated remediation for this rule and this sounds reasonable.", - "props": [ + "value": "file_groupowner_backup_etc_shadow" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "file_owner_backup_etc_shadow" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_root_gid_zero" + "value": "file_permissions_backup_etc_shadow" } ] }, { - "uuid": "f5724f50-0618-421b-b515-fca1d3e782c7", - "control-id": "cis_rhel10_5-4.2.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "New rule is necessary." - } - ] - }, - { - "uuid": "8b8f6069-3ce4-49a8-ac8a-ba2b59950538", - "control-id": "cis_rhel10_5-4.2.4", + "uuid": "a77a2b13-597d-4963-b11d-8c4562c9cc21", + "control-id": "cis_rhel10_7-1.7", "description": "REPLACE_ME", "props": [ { @@ -10572,48 +10569,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_root_password_configured" - } - ] - }, - { - "uuid": "a8c74f1e-a833-4cd2-a203-3d254962442e", - "control-id": "cis_rhel10_5-4.2.5", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "file_groupowner_etc_gshadow" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_root_path_dirs_no_write" + "value": "file_owner_etc_gshadow" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "root_path_no_dot" - } - ] - }, - { - "uuid": "283f1f33-cb64-41f5-a15f-1e4cc1e3ba37", - "control-id": "cis_rhel10_5-4.2.6", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "There is no rule to ensure umask in /root/.bash_profile and /root/.bashrc. A new rule have\nto be created. It can be based on accounts_umask_interactive_users." + "value": "file_permissions_etc_gshadow" } ] }, { - "uuid": "5be48de7-c484-4415-8069-853adb6a812d", - "control-id": "cis_rhel10_5-4.2.7", + "uuid": "dba5c38d-593c-45c6-b1ee-a1283dda53dc", + "control-id": "cis_rhel10_7-1.8", "description": "REPLACE_ME", "props": [ { @@ -10624,48 +10596,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_password_auth_for_systemaccounts" + "value": "file_groupowner_backup_etc_gshadow" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_shelllogin_for_systemaccounts" - } - ] - }, - { - "uuid": "b206650e-4ac6-4008-83c1-e7ef41b0992e", - "control-id": "cis_rhel10_5-4.2.8", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "New rule is necessary." - } - ] - }, - { - "uuid": "aa6b9f2b-2b42-4141-88b1-448cbe05b47e", - "control-id": "cis_rhel10_5-4.3.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "file_owner_backup_etc_gshadow" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_tmout" + "value": "file_permissions_backup_etc_gshadow" } ] }, { - "uuid": "6f9bf8d9-3b3a-423e-b453-13fd647ab0fa", - "control-id": "cis_rhel10_5-4.3.3", + "uuid": "3b7eda61-86fe-442a-ad88-27665803e2df", + "control-id": "cis_rhel10_7-1.9", "description": "REPLACE_ME", "props": [ { @@ -10676,23 +10623,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_umask_etc_bashrc" + "value": "file_groupowner_etc_shells" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_umask_etc_login_defs" + "value": "file_owner_etc_shells" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_umask_etc_profile" + "value": "file_permissions_etc_shells" } ] }, { - "uuid": "6d6bfea7-ddac-459a-8525-68ff972e10cf", - "control-id": "cis_rhel10_6-1.1", + "uuid": "be1f57dc-a927-4cc0-86d3-9ddf66102c88", + "control-id": "cis_rhel10_7-1.10", "description": "REPLACE_ME", "props": [ { @@ -10703,18 +10650,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_aide_installed" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "aide_build_database" + "value": "file_etc_security_opasswd" } ] }, { - "uuid": "3db80080-7bad-43d8-a6ae-302749082864", - "control-id": "cis_rhel10_6-1.2", + "uuid": "18b2e81a-eeca-4d2c-986d-45d611ad2b39", + "control-id": "cis_rhel10_7-1.11", "description": "REPLACE_ME", "props": [ { @@ -10725,60 +10667,40 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "aide_periodic_cron_checking" - } - ] - }, - { - "uuid": "47e61248-1abb-4f3f-bcde-fcf637b8636f", - "control-id": "cis_rhel10_6-1.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "file_permissions_unauthorized_world_writable" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "aide_check_audit_tools" + "value": "dir_perms_world_writable_sticky_bits" } ] }, { - "uuid": "d59dc231-5a92-42c3-902f-677cd98ccd2b", - "control-id": "cis_rhel10_6-2.1.1", + "uuid": "b185034c-0fea-4e0a-835c-ccbb2c3ab81d", + "control-id": "cis_rhel10_7-1.12", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "partial" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_systemd-journald_enabled" - } - ] - }, - { - "uuid": "49dfee8a-a222-4a00-9a28-99b469fbbd22", - "control-id": "cis_rhel10_6-2.1.2", - "description": "REPLACE_ME", - "props": [ + "value": "no_files_unowned_by_user" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "file_permissions_ungroupowned" } ] }, { - "uuid": "84a2e6ff-64ed-415b-a866-ec6b682692d7", - "control-id": "cis_rhel10_6-2.1.3", + "uuid": "ea8690fe-cb66-4644-9ec4-ab340b698e0b", + "control-id": "cis_rhel10_7-1.13", "description": "REPLACE_ME", "props": [ { @@ -10790,21 +10712,8 @@ ] }, { - "uuid": "691c5361-7581-4eca-afa2-dfc79adff0d7", - "control-id": "cis_rhel10_6-2.1.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary to create a new rule to check the status of journald and rsyslog.\nIt would also be necessary a new rule to disable or remove rsyslog." - } - ] - }, - { - "uuid": "fb458389-8da9-47b3-b70a-9fb95b8c54c5", - "control-id": "cis_rhel10_6-2.2.1.1", + "uuid": "c550b8d9-8238-47c6-a196-a3703132b354", + "control-id": "cis_rhel10_7-2.1", "description": "REPLACE_ME", "props": [ { @@ -10815,39 +10724,30 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_systemd-journal-remote_installed" + "value": "accounts_password_all_shadowed" } ] }, { - "uuid": "b9c7d584-80d5-4dff-9fe5-77ef5d582ab5", - "control-id": "cis_rhel10_6-2.2.1.2", + "uuid": "cbebe4e0-dfc2-49b6-8f69-d909f9bda634", + "control-id": "cis_rhel10_7-2.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } - ] - }, - { - "uuid": "700e56b5-5649-460d-a621-8ad8572b09a5", - "control-id": "cis_rhel10_6-2.2.1.3", - "description": "REPLACE_ME", - "props": [ + "value": "implemented" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "New templated rule is necessary." + "value": "no_empty_passwords_etc_shadow" } ] }, { - "uuid": "4c027c04-2387-48a1-a444-d90aac550aa5", - "control-id": "cis_rhel10_6-2.2.1.4", + "uuid": "871b87a4-21e2-45ac-9022-ce0915071c90", + "control-id": "cis_rhel10_7-2.3", "description": "REPLACE_ME", "props": [ { @@ -10858,26 +10758,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "socket_systemd-journal-remote_disabled" - } - ] - }, - { - "uuid": "5a59bc96-2875-40c4-8f76-7345bae19262", - "control-id": "cis_rhel10_6-2.2.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "This rule conflicts with 6.2.3.3. More investigation is needed to properly solve this." + "value": "gid_passwd_group_same" } ] }, { - "uuid": "b830f208-eb80-4ed6-b14e-909f86d0c262", - "control-id": "cis_rhel10_6-2.2.3", + "uuid": "486f0a0a-efab-4366-bddb-52d90c1b53d3", + "control-id": "cis_rhel10_7-2.4", "description": "REPLACE_ME", "props": [ { @@ -10888,13 +10775,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_compress" + "value": "account_unique_id" } ] }, { - "uuid": "b1996953-1f0b-4274-9485-10c57644073e", - "control-id": "cis_rhel10_6-2.2.4", + "uuid": "50272a83-7870-497a-be06-a34c4dafc029", + "control-id": "cis_rhel10_7-2.5", "description": "REPLACE_ME", "props": [ { @@ -10905,608 +10792,80 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_storage" + "value": "group_unique_id" } ] }, { - "uuid": "97ec1689-17fb-478c-975e-416367b6697d", - "control-id": "cis_rhel10_6-2.3.1", + "uuid": "0fd0fb47-bdce-49de-8c24-ad853f0a5af1", + "control-id": "cis_rhel10_7-2.6", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - } - ] - }, - { - "uuid": "f4c581e9-a7b5-4235-90b6-9f16cf7e1aee", - "control-id": "cis_rhel10_6-2.3.2", - "description": "REPLACE_ME", - "props": [ + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "account_unique_name" } ] }, { - "uuid": "14f276c7-459a-4e7a-a803-a692430263d6", - "control-id": "cis_rhel10_6-2.3.3", + "uuid": "074f28e0-8808-49ff-9638-ab389decfc2c", + "control-id": "cis_rhel10_7-2.7", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - } - ] - }, - { - "uuid": "b2f9c5ad-7caa-465f-95b8-f5a62c3b9d93", - "control-id": "cis_rhel10_6-2.3.4", - "description": "REPLACE_ME", - "props": [ + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "group_unique_name" } ] }, { - "uuid": "c0ff8ca1-6865-4259-b5c3-9502d0a80911", - "control-id": "cis_rhel10_6-2.3.5", + "uuid": "4683832b-2154-42bc-9c2c-68838f6e5a43", + "control-id": "cis_rhel10_7-2.8", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } - ] - }, - { - "uuid": "3abda98b-7607-4283-8ca9-5ef0796e4fdf", - "control-id": "cis_rhel10_6-2.3.6", - "description": "REPLACE_ME", - "props": [ + "value": "implemented" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } - ] - }, - { - "uuid": "0c4a751b-e059-4873-a9bf-7677a8f53d2c", - "control-id": "cis_rhel10_6-2.3.7", - "description": "REPLACE_ME", - "props": [ + "value": "accounts_user_interactive_home_directory_exists" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - } - ] - }, - { - "uuid": "4e30bf47-c201-4465-b2fe-3735813ba180", - "control-id": "cis_rhel10_6-2.3.8", - "description": "REPLACE_ME", - "props": [ + "value": "file_ownership_home_directories" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "file_permissions_home_directories" } ] }, { - "uuid": "a0099883-6b89-4dc2-81f0-0514278ce852", - "control-id": "cis_rhel10_6-2.4.1", - "description": "It is not harmful to run these rules even if rsyslog is not installed or active.", + "uuid": "bcd235b5-4b93-442f-831b-ae2740fc5c47", + "control-id": "cis_rhel10_7-2.9", + "description": "Missing a rule to check that .bash_history is mode 0600 or more restrictive.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "rsyslog_files_groupownership" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "rsyslog_files_ownership" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "rsyslog_files_permissions" - } - ] - }, - { - "uuid": "c022c8bc-5a37-4a1d-98ce-7c09df0f3e53", - "control-id": "cis_rhel10_7-1.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_passwd" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_passwd" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_passwd" - } - ] - }, - { - "uuid": "ceb4d7c2-87f4-4655-9572-f60bfb7f5d33", - "control-id": "cis_rhel10_7-1.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_passwd" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_passwd" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_passwd" - } - ] - }, - { - "uuid": "b6d24314-2f9d-4dcc-b687-9e71506b2d3e", - "control-id": "cis_rhel10_7-1.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_group" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_group" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_group" - } - ] - }, - { - "uuid": "27d15f5b-901a-4071-b545-0cbca4780510", - "control-id": "cis_rhel10_7-1.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_group" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_group" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_group" - } - ] - }, - { - "uuid": "12a5489e-c318-4787-9c31-d7016c817a20", - "control-id": "cis_rhel10_7-1.5", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_shadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_shadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_shadow" - } - ] - }, - { - "uuid": "b83d9442-252c-400b-8283-0e14a1985ea6", - "control-id": "cis_rhel10_7-1.6", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_shadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_shadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_shadow" - } - ] - }, - { - "uuid": "7f31a48f-669f-452c-9887-875815d7d3d1", - "control-id": "cis_rhel10_7-1.7", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_gshadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_gshadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_gshadow" - } - ] - }, - { - "uuid": "f1214815-60d9-4e32-be54-ab95ec2425b4", - "control-id": "cis_rhel10_7-1.8", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_gshadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_gshadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_gshadow" - } - ] - }, - { - "uuid": "82f215bd-34de-4ed8-b461-0258d72ff93b", - "control-id": "cis_rhel10_7-1.9", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_shells" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_shells" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_shells" - } - ] - }, - { - "uuid": "6d9906d7-7c7b-45a9-9289-9acb0e2d26c4", - "control-id": "cis_rhel10_7-1.10", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_etc_security_opasswd" - } - ] - }, - { - "uuid": "e63a4635-8f21-4d72-b334-b7865f44ef6a", - "control-id": "cis_rhel10_7-1.11", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_unauthorized_world_writable" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dir_perms_world_writable_sticky_bits" - } - ] - }, - { - "uuid": "b813258e-fd26-49f9-861a-cb00c8c9b90f", - "control-id": "cis_rhel10_7-1.12", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_files_unowned_by_user" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_ungroupowned" - } - ] - }, - { - "uuid": "9881288f-8088-4ee1-a296-8a0b8dff3a66", - "control-id": "cis_rhel10_7-1.13", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } - ] - }, - { - "uuid": "5119819a-035c-4d16-9baa-7f854311d159", - "control-id": "cis_rhel10_7-2.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_all_shadowed" - } - ] - }, - { - "uuid": "e2e26d89-da16-4228-8610-f254fbead94f", - "control-id": "cis_rhel10_7-2.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_empty_passwords_etc_shadow" - } - ] - }, - { - "uuid": "a3b40667-299b-4a27-af4c-6eb1616ecfb2", - "control-id": "cis_rhel10_7-2.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "gid_passwd_group_same" - } - ] - }, - { - "uuid": "6973aff0-d88b-40ff-927e-4af2b393dfcf", - "control-id": "cis_rhel10_7-2.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_unique_id" - } - ] - }, - { - "uuid": "5cab33eb-b688-4ef9-850a-76ef77aa0c57", - "control-id": "cis_rhel10_7-2.5", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "group_unique_id" - } - ] - }, - { - "uuid": "706e2aa0-ee74-4b8f-a979-3c0f586e95bb", - "control-id": "cis_rhel10_7-2.6", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_unique_name" - } - ] - }, - { - "uuid": "748ba949-7d06-448f-b17d-ebe42784b206", - "control-id": "cis_rhel10_7-2.7", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "group_unique_name" - } - ] - }, - { - "uuid": "9820bef3-c0b3-471a-985e-a8dffe48f1bd", - "control-id": "cis_rhel10_7-2.8", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_user_interactive_home_directory_exists" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_home_directories" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_home_directories" - } - ] - }, - { - "uuid": "b85c9730-e0dc-450a-b227-c3d562ef9910", - "control-id": "cis_rhel10_7-2.9", - "description": "Missing a rule to check that .bash_history is mode 0600 or more restrictive.", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "partial" }, { "name": "Rule_Id", @@ -11679,7 +11038,7 @@ { "name": "Parameter_Value_Alternatives_5", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", + "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel10': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", "remarks": "rule_set_000" }, { @@ -11697,7 +11056,7 @@ { "name": "Parameter_Value_Alternatives_6", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", + "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel10': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", "remarks": "rule_set_000" }, { @@ -12063,683 +11422,701 @@ { "name": "Parameter_Id_27", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_account_disable_post_pw_expiration", + "value": "sysctl_net_ipv6_conf_default_forwarding_value", "remarks": "rule_set_000" }, { "name": "Parameter_Description_27", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The number of days to wait after a password expires, until the account will be permanently disabled.", + "value": "Toggle IPv6 default Forwarding", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_27", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'0': '0', 180: 180, 30: 30, 35: 35, 40: 40, 45: 45, 60: 60, 90: 90, 'default': 35}", + "value": "{'default': '0', 'disabled': '0', 'enabled': 1}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_28", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_maximum_age_login_defs", + "value": "var_account_disable_post_pw_expiration", "remarks": "rule_set_000" }, { "name": "Parameter_Description_28", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Maximum age of password in days", + "value": "The number of days to wait after a password expires, until the account will be permanently disabled.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_28", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{365: 365, 120: 120, 180: 180, 90: 90, 60: 60, 45: 45, 'default': 60}", + "value": "{'0': '0', 180: 180, 30: 30, 35: 35, 40: 40, 45: 45, 60: 60, 90: 90, 'default': 35}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_29", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_minimum_age_login_defs", + "value": "var_accounts_maximum_age_login_defs", "remarks": "rule_set_000" }, { "name": "Parameter_Description_29", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Minimum age of password in days", + "value": "Maximum age of password in days", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_29", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'0': '0', 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 'default': 7}", + "value": "{365: 365, 120: 120, 180: 180, 90: 90, 60: 60, 45: 45, 'default': 60}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_30", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_password_warn_age_login_defs", + "value": "var_accounts_minimum_age_login_defs", "remarks": "rule_set_000" }, { "name": "Parameter_Description_30", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The number of days' warning given before a password expires.", + "value": "Minimum age of password in days", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_30", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'0': '0', 14: 14, 10: 10, 7: 7, 'default': 7}", + "value": "{'0': '0', 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 'default': 7}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_31", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_passwords_pam_faillock_deny", + "value": "var_accounts_password_warn_age_login_defs", "remarks": "rule_set_000" }, { "name": "Parameter_Description_31", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Number of failed login attempts before account lockout", + "value": "The number of days' warning given before a password expires.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_31", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{10: 10, 3: 3, 4: 4, 5: 5, 6: 6, 8: 8, 'default': 3}", + "value": "{'0': '0', 14: 14, 10: 10, 7: 7, 'default': 7}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_32", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_passwords_pam_faillock_dir", + "value": "var_accounts_passwords_pam_faillock_deny", "remarks": "rule_set_000" }, { "name": "Parameter_Description_32", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The directory where the user files with the failure records are kept", + "value": "Number of failed login attempts before account lockout", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_32", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'ol8': '/var/log/faillock', 'default': '/var/log/faillock', 'run': '/var/run/faillock'}", + "value": "{10: 10, 3: 3, 4: 4, 5: 5, 6: 6, 8: 8, 'default': 3}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_33", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_passwords_pam_faillock_unlock_time", + "value": "var_accounts_passwords_pam_faillock_dir", "remarks": "rule_set_000" }, { "name": "Parameter_Description_33", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Seconds before automatic unlocking or permanently locking after excessive failed logins", + "value": "The directory where the user files with the failure records are kept", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_33", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{1800: 1800, 3600: 3600, 600: 600, 604800: 604800, 86400: 86400, 900: 900, 300: 300, 'default': 0, 'never': 0}", + "value": "{'ol8': '/var/log/faillock', 'default': '/var/log/faillock', 'run': '/var/run/faillock'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_34", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_tmout", + "value": "var_accounts_passwords_pam_faillock_unlock_time", "remarks": "rule_set_000" }, { "name": "Parameter_Description_34", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "In an interactive shell, the value is interpreted as the number of seconds to wait for input after issuing the primary prompt. Bash terminates after waiting for that number of seconds if input does not arrive.", + "value": "Seconds before automatic unlocking or permanently locking after excessive failed logins", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_34", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'30_min': 1800, '10_min': 600, '15_min': 900, '5_min': 300, 'default': 600}", + "value": "{1800: 1800, 3600: 3600, 600: 600, 604800: 604800, 86400: 86400, 900: 900, 300: 300, 'default': 0, 'never': 0}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_35", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_user_umask", + "value": "var_accounts_tmout", "remarks": "rule_set_000" }, { "name": "Parameter_Description_35", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enter default user umask", + "value": "In an interactive shell, the value is interpreted as the number of seconds to wait for input after issuing the primary prompt. Bash terminates after waiting for that number of seconds if input does not arrive.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_35", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'007': '007', '022': '022', '027': '027', '077': '077', 'default': '027'}", + "value": "{'30_min': 1800, '10_min': 600, '15_min': 900, '5_min': 300, 'default': 600}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_36", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_auditd_action_mail_acct", + "value": "var_accounts_user_umask", "remarks": "rule_set_000" }, { "name": "Parameter_Description_36", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The setting for action_mail_acct in /etc/audit/auditd.conf", + "value": "Enter default user umask", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_36", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'admin': 'admin', 'default': 'root', 'root': 'root'}", + "value": "{'007': '007', '022': '022', '027': '027', '077': '077', 'default': '027'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_auditd_admin_space_left_action", + "value": "var_auditd_action_mail_acct", "remarks": "rule_set_000" }, { "name": "Parameter_Description_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The setting for admin_space_left_action in /etc/audit/auditd.conf", + "value": "The setting for action_mail_acct in /etc/audit/auditd.conf", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt'}", + "value": "{'admin': 'admin', 'default': 'root', 'root': 'root'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_auditd_disk_error_action", + "value": "var_auditd_admin_space_left_action", "remarks": "rule_set_000" }, { "name": "Parameter_Description_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "'The setting for disk_error_action in /etc/audit/auditd.conf, if multiple values are allowed write them separated by pipes as in \"syslog|single|halt\", for remediations the first value will be taken'", + "value": "The setting for admin_space_left_action in /etc/audit/auditd.conf", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", + "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt', 'cis_rhel10': 'single|halt'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_auditd_disk_full_action", + "value": "var_auditd_disk_error_action", "remarks": "rule_set_000" }, { "name": "Parameter_Description_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "'The setting for disk_full_action in /etc/audit/auditd.conf, if multiple values are allowed write them separated by pipes as in \"syslog|single|halt\", for remediations the first value will be taken'", + "value": "'The setting for disk_error_action in /etc/audit/auditd.conf, if multiple values are allowed write them separated by pipes as in \"syslog|single|halt\", for remediations the first value will be taken'", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_rhel10': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_40", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_auditd_max_log_file", + "value": "var_auditd_disk_full_action", "remarks": "rule_set_000" }, { "name": "Parameter_Description_40", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The setting for max_log_file in /etc/audit/auditd.conf", + "value": "'The setting for disk_full_action in /etc/audit/auditd.conf, if multiple values are allowed write them separated by pipes as in \"syslog|single|halt\", for remediations the first value will be taken'", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_40", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{1: 1, 10: 10, 20: 20, 5: 5, 6: 6, 'default': 6}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_rhel10': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_41", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_auditd_max_log_file_action", + "value": "var_auditd_max_log_file", "remarks": "rule_set_000" }, { "name": "Parameter_Description_41", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The setting for max_log_file_action in /etc/audit/auditd.conf. The following options are available:
ignore - audit daemon does nothing.
syslog - audit daemon will issue a warning to syslog.
suspend - audit daemon will stop writing records to the disk.
rotate - audit daemon will rotate logs in the same convention used by logrotate.
keep_logs - similar to rotate but prevents audit logs to be overwritten. May trigger space_left_action if volume is full.", + "value": "The setting for max_log_file in /etc/audit/auditd.conf", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_41", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'rotate', 'keep_logs': 'keep_logs', 'rotate': 'rotate', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore'}", + "value": "{1: 1, 10: 10, 20: 20, 5: 5, 6: 6, 'default': 6}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_42", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_auditd_space_left_action", + "value": "var_auditd_max_log_file_action", "remarks": "rule_set_000" }, { "name": "Parameter_Description_42", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The setting for space_left_action in /etc/audit/auditd.conf", + "value": "The setting for max_log_file_action in /etc/audit/auditd.conf. The following options are available:
ignore - audit daemon does nothing.
syslog - audit daemon will issue a warning to syslog.
suspend - audit daemon will stop writing records to the disk.
rotate - audit daemon will rotate logs in the same convention used by logrotate.
keep_logs - similar to rotate but prevents audit logs to be overwritten. May trigger space_left_action if volume is full.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_42", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt'}", + "value": "{'default': 'rotate', 'keep_logs': 'keep_logs', 'rotate': 'rotate', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_43", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_authselect_profile", + "value": "var_auditd_space_left_action", "remarks": "rule_set_000" }, { "name": "Parameter_Description_43", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the authselect profile to select", + "value": "The setting for space_left_action in /etc/audit/auditd.conf", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_43", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'local': 'local', 'default': 'minimal', 'minimal': 'minimal', 'sssd': 'sssd'}", + "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt', 'cis_rhel10': 'email|exec|single|halt'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_44", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_multiple_time_servers", + "value": "var_authselect_profile", "remarks": "rule_set_000" }, { "name": "Parameter_Description_44", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The list of vendor-approved time servers", + "value": "Specify the authselect profile to select", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_44", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'generic': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'stig': '0.us.pool.ntp.mil', 'fedora': '0.fedora.pool.ntp.org,1.fedora.pool.ntp.org,2.fedora.pool.ntp.org,3.fedora.pool.ntp.org', 'rhel': '0.rhel.pool.ntp.org,1.rhel.pool.ntp.org,2.rhel.pool.ntp.org,3.rhel.pool.ntp.org', 'ol': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'suse': '0.suse.pool.ntp.org,1.suse.pool.ntp.org,2.suse.pool.ntp.org,3.suse.pool.ntp.org', 'alinux': '0.ntp.cloud.aliyuncs.com,1.ntp.aliyun.com,2.ntp1.aliyun.com,3.ntp1.cloud.aliyuncs.com', 'amazon': '0.rhel.pool.ntp.org,1.rhel.pool.ntp.org,2.rhel.pool.ntp.org,3.rhel.pool.ntp.org', 'ubuntu': '0.ubuntu.pool.ntp.org,1.ubuntu.pool.ntp.org,2.ubuntu.pool.ntp.org,3.ubuntu.pool.ntp.org', 'almalinux': '0.almalinux.pool.ntp.org,1.almalinux.pool.ntp.org,2.almalinux.pool.ntp.org,3.almalinux.pool.ntp.org', 'debian': '0.debian.pool.ntp.org,1.debian.pool.ntp.org,2.debian.pool.ntp.org,3.debian.pool.ntp.org', 'nist': 'time.nist.gov,time-a-g.nist.gov,time-b-g.nist.gov,time-c-g.nist.gov'}", + "value": "{'local': 'local', 'default': 'minimal', 'minimal': 'minimal', 'sssd': 'sssd'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_45", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_pam_wheel_group_for_su", + "value": "var_multiple_time_servers", "remarks": "rule_set_000" }, { "name": "Parameter_Description_45", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "pam_wheel module has a parameter called group, which controls which groups can access the su command. This variable holds the valid value for the parameter.", + "value": "The list of vendor-approved time servers", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_45", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'sugroup', 'cis': 'sugroup'}", + "value": "{'default': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'generic': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'stig': '0.us.pool.ntp.mil', 'fedora': '0.fedora.pool.ntp.org,1.fedora.pool.ntp.org,2.fedora.pool.ntp.org,3.fedora.pool.ntp.org', 'rhel': '0.rhel.pool.ntp.org,1.rhel.pool.ntp.org,2.rhel.pool.ntp.org,3.rhel.pool.ntp.org', 'ol': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'suse': '0.suse.pool.ntp.org,1.suse.pool.ntp.org,2.suse.pool.ntp.org,3.suse.pool.ntp.org', 'alinux': '0.ntp.cloud.aliyuncs.com,1.ntp.aliyun.com,2.ntp1.aliyun.com,3.ntp1.cloud.aliyuncs.com', 'amazon': '0.rhel.pool.ntp.org,1.rhel.pool.ntp.org,2.rhel.pool.ntp.org,3.rhel.pool.ntp.org', 'ubuntu': '0.ubuntu.pool.ntp.org,1.ubuntu.pool.ntp.org,2.ubuntu.pool.ntp.org,3.ubuntu.pool.ntp.org', 'almalinux': '0.almalinux.pool.ntp.org,1.almalinux.pool.ntp.org,2.almalinux.pool.ntp.org,3.almalinux.pool.ntp.org', 'debian': '0.debian.pool.ntp.org,1.debian.pool.ntp.org,2.debian.pool.ntp.org,3.debian.pool.ntp.org', 'nist': 'time.nist.gov,time-a-g.nist.gov,time-b-g.nist.gov,time-c-g.nist.gov'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_46", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_hashing_algorithm", + "value": "var_pam_wheel_group_for_su", "remarks": "rule_set_000" }, { "name": "Parameter_Description_46", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the system default encryption algorithm for encrypting passwords. Defines the value set as ENCRYPT_METHOD in /etc/login.defs.", + "value": "pam_wheel module has a parameter called group, which controls which groups can access the su command. This variable holds the valid value for the parameter.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_46", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'SHA512', 'SHA512': 'SHA512', 'SHA256': 'SHA256', 'yescrypt': 'YESCRYPT', 'cis_ubuntu2404': 'SHA512|YESCRYPT'}", + "value": "{'default': 'sugroup', 'cis': 'sugroup'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_47", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_hashing_algorithm_pam", + "value": "var_password_hashing_algorithm", "remarks": "rule_set_000" }, { "name": "Parameter_Description_47", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the system default encryption algorithm for encrypting passwords. Defines the hashing algorithm to be used in pam_unix.so.", + "value": "Specify the system default encryption algorithm for encrypting passwords. Defines the value set as ENCRYPT_METHOD in /etc/login.defs.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_47", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'sha512', 'sha512': 'sha512', 'yescrypt': 'yescrypt'}", + "value": "{'default': 'SHA512', 'SHA512': 'SHA512', 'SHA256': 'SHA256', 'yescrypt': 'YESCRYPT', 'cis_ubuntu2404': 'SHA512|YESCRYPT'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_48", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_dictcheck", + "value": "var_password_hashing_algorithm_pam", "remarks": "rule_set_000" }, { "name": "Parameter_Description_48", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Prevent the use of dictionary words for passwords.", + "value": "Specify the system default encryption algorithm for encrypting passwords. Defines the hashing algorithm to be used in pam_unix.so.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_48", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{1: 1, 'default': 1}", + "value": "{'default': 'sha512', 'sha512': 'sha512', 'yescrypt': 'yescrypt'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_49", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_difok", + "value": "var_password_pam_dictcheck", "remarks": "rule_set_000" }, { "name": "Parameter_Description_49", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Minimum number of characters not present in old password", + "value": "Prevent the use of dictionary words for passwords.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_49", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{15: 15, 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 8: 8, 'default': 8}", + "value": "{1: 1, 'default': 1}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_50", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_maxrepeat", + "value": "var_password_pam_difok", "remarks": "rule_set_000" }, { "name": "Parameter_Description_50", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Maximum Number of Consecutive Repeating Characters in a Password", + "value": "Minimum number of characters not present in old password", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_50", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{1: 1, 2: 2, 3: 3, 'default': 3}", + "value": "{15: 15, 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 8: 8, 'default': 8}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_51", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_minclass", + "value": "var_password_pam_maxrepeat", "remarks": "rule_set_000" }, { "name": "Parameter_Description_51", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Maximum Number of Consecutive Repeating Characters in a Password", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Value_Alternatives_51", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "{1: 1, 2: 2, 3: 3, 'default': 3}", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Id_52", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "var_password_pam_minclass", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Description_52", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Minimum number of categories of characters that must exist in a password", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_51", + "name": "Parameter_Value_Alternatives_52", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{1: 1, 2: 2, 3: 3, 4: 4, 'default': 3}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_52", + "name": "Parameter_Id_53", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_password_pam_minlen", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_52", + "name": "Parameter_Description_53", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Minimum number of characters in password", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_52", + "name": "Parameter_Value_Alternatives_53", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{10: 10, 12: 12, 14: 14, 15: 15, 17: 17, 18: 18, 20: 20, 6: 6, 7: 7, 8: 8, 'default': 15}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_53", + "name": "Parameter_Id_54", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_password_pam_remember", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_53", + "name": "Parameter_Description_54", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Prevent password re-use using password history lookup", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_53", + "name": "Parameter_Value_Alternatives_54", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'0': '0', 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 8: 8, 9: 9, 24: 24, 'default': 5}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_54", + "name": "Parameter_Id_55", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_password_pam_remember_control_flag", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_54", + "name": "Parameter_Description_55", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "'Specify the control flag required for password remember requirement. If multiple values are allowed write them separated by commas as in \"required,requisite\", for remediations the first value will be taken'", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_54", + "name": "Parameter_Value_Alternatives_55", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'required': 'required', 'optional': 'optional', 'requisite': 'requisite', 'sufficient': 'sufficient', 'binding': 'binding', 'ol8': 'required,requisite', 'requisite_or_required': 'requisite,required', 'default': 'requisite'}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_55", + "name": "Parameter_Id_56", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_postfix_inet_interfaces", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_55", + "name": "Parameter_Description_56", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "The setting for inet_interfaces in /etc/postfix/main.cf", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_55", + "name": "Parameter_Value_Alternatives_56", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'loopback-only': 'loopback-only', 'default': 'loopback-only', 'localhost': 'localhost'}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_56", + "name": "Parameter_Id_57", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_screensaver_lock_delay", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_56", + "name": "Parameter_Description_57", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Choose allowed duration (in seconds) after a screensaver becomes active before displaying an authentication prompt", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_56", + "name": "Parameter_Value_Alternatives_57", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'10_seconds': 10, '5_seconds': 5, 'default': '0', 'immediate': '0'}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_57", + "name": "Parameter_Id_58", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_selinux_policy_name", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_57", + "name": "Parameter_Description_58", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Type of policy in use. Possible values are:
targeted - Only targeted network daemons are protected.
strict - Full SELinux protection.
mls - Multiple levels of security", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_57", + "name": "Parameter_Value_Alternatives_58", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'default': 'targeted', 'mls': 'mls', 'targeted': 'targeted'}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_58", + "name": "Parameter_Id_59", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_selinux_state", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_58", + "name": "Parameter_Description_59", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "enforcing - SELinux security policy is enforced.
permissive - SELinux prints warnings instead of enforcing.
disabled - SELinux is fully disabled.", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_58", + "name": "Parameter_Value_Alternatives_59", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'default': 'enforcing', 'disabled': 'disabled', 'enforcing': 'enforcing', 'permissive': 'permissive'}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_59", + "name": "Parameter_Id_60", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_sshd_max_sessions", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_59", + "name": "Parameter_Description_60", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Specify the maximum number of open sessions permitted.", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_59", + "name": "Parameter_Value_Alternatives_60", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{10: 10, 4: 4, 3: 3, 2: 2, 1: 1, 0: 0, 'default': 10}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_60", + "name": "Parameter_Id_61", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_sshd_set_keepalive", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_60", + "name": "Parameter_Description_61", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Specify the maximum number of idle message counts before session is terminated.", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_60", + "name": "Parameter_Value_Alternatives_61", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{10: 10, 3: 3, 5: 5, 0: 0, 1: 1, 'default': 0}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_61", + "name": "Parameter_Id_62", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_sshd_set_login_grace_time", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_61", + "name": "Parameter_Description_62", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure parameters for how long the servers stays connected before the user has successfully logged in", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_61", + "name": "Parameter_Value_Alternatives_62", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'default': 60, 60: 60}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_62", + "name": "Parameter_Id_63", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_sshd_set_maxstartups", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_62", + "name": "Parameter_Description_63", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure parameters for maximum concurrent unauthenticated connections to the SSH daemon.", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_62", + "name": "Parameter_Value_Alternatives_63", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'default': '10:30:100', '10:30:60': '10:30:60'}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_63", + "name": "Parameter_Id_64", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_system_crypto_policy", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_63", + "name": "Parameter_Description_64", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Specify the crypto policy for the system.", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_63", + "name": "Parameter_Value_Alternatives_64", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { - "name": "Parameter_Id_64", + "name": "Parameter_Id_65", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "var_user_initialization_files_regex", "remarks": "rule_set_000" }, { - "name": "Parameter_Description_64", + "name": "Parameter_Description_65", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "'A regular expression describing a list of file names for files that are sourced at login time for interactive users'", "remarks": "rule_set_000" }, { - "name": "Parameter_Value_Alternatives_64", + "name": "Parameter_Value_Alternatives_65", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'default': '^(\\\\.bashrc|\\\\.zshrc|\\\\.cshrc|\\\\.profile|\\\\.bash_login|\\\\.bash_profile)$', 'all_dotfiles': '^\\\\.[\\\\w\\\\- ]+$'}", "remarks": "rule_set_000" @@ -12747,9007 +12124,9535 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_usb-storage_disabled", + "value": "kernel_module_cramfs_disabled", "remarks": "rule_set_001" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Modprobe Loading of USB Storage Driver", + "value": "Disable Mounting of cramfs", "remarks": "rule_set_001" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_usb-storage_disabled", + "value": "kernel_module_cramfs_disabled", "remarks": "rule_set_001" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Modprobe Loading of USB Storage Driver", + "value": "Disable Mounting of cramfs", "remarks": "rule_set_001" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_tmp", + "value": "kernel_module_freevxfs_disabled", "remarks": "rule_set_002" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /tmp Located On Separate Partition", + "value": "Disable Mounting of freevxfs", "remarks": "rule_set_002" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_tmp", + "value": "kernel_module_freevxfs_disabled", "remarks": "rule_set_002" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /tmp Located On Separate Partition", + "value": "Disable Mounting of freevxfs", "remarks": "rule_set_002" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_nodev", + "value": "kernel_module_hfs_disabled", "remarks": "rule_set_003" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /tmp", + "value": "Disable Mounting of hfs", "remarks": "rule_set_003" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_nodev", + "value": "kernel_module_hfs_disabled", "remarks": "rule_set_003" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /tmp", + "value": "Disable Mounting of hfs", "remarks": "rule_set_003" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_nosuid", + "value": "kernel_module_hfsplus_disabled", "remarks": "rule_set_004" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /tmp", + "value": "Disable Mounting of hfsplus", "remarks": "rule_set_004" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_nosuid", + "value": "kernel_module_hfsplus_disabled", "remarks": "rule_set_004" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /tmp", + "value": "Disable Mounting of hfsplus", "remarks": "rule_set_004" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_noexec", + "value": "kernel_module_jffs2_disabled", "remarks": "rule_set_005" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /tmp", + "value": "Disable Mounting of jffs2", "remarks": "rule_set_005" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_noexec", + "value": "kernel_module_jffs2_disabled", "remarks": "rule_set_005" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /tmp", + "value": "Disable Mounting of jffs2", "remarks": "rule_set_005" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_dev_shm", + "value": "kernel_module_firewire-core_disabled", "remarks": "rule_set_006" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /dev/shm is configured", + "value": "Disable IEEE 1394 (FireWire) Support", "remarks": "rule_set_006" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_dev_shm", + "value": "kernel_module_firewire-core_disabled", "remarks": "rule_set_006" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /dev/shm is configured", + "value": "Disable IEEE 1394 (FireWire) Support", "remarks": "rule_set_006" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_nodev", + "value": "kernel_module_usb-storage_disabled", "remarks": "rule_set_007" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /dev/shm", + "value": "Disable Modprobe Loading of USB Storage Driver", "remarks": "rule_set_007" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_nodev", + "value": "kernel_module_usb-storage_disabled", "remarks": "rule_set_007" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /dev/shm", + "value": "Disable Modprobe Loading of USB Storage Driver", "remarks": "rule_set_007" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_nosuid", + "value": "partition_for_tmp", "remarks": "rule_set_008" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /dev/shm", + "value": "Ensure /tmp Located On Separate Partition", + "remarks": "rule_set_008" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "partition_for_tmp", + "remarks": "rule_set_008" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure /tmp Located On Separate Partition", "remarks": "rule_set_008" }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "mount_option_tmp_nodev", + "remarks": "rule_set_009" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Add nodev Option to /tmp", + "remarks": "rule_set_009" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "mount_option_tmp_nodev", + "remarks": "rule_set_009" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Add nodev Option to /tmp", + "remarks": "rule_set_009" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "mount_option_tmp_nosuid", + "remarks": "rule_set_010" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Add nosuid Option to /tmp", + "remarks": "rule_set_010" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "mount_option_tmp_nosuid", + "remarks": "rule_set_010" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Add nosuid Option to /tmp", + "remarks": "rule_set_010" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "mount_option_tmp_noexec", + "remarks": "rule_set_011" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Add noexec Option to /tmp", + "remarks": "rule_set_011" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "mount_option_tmp_noexec", + "remarks": "rule_set_011" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Add noexec Option to /tmp", + "remarks": "rule_set_011" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "partition_for_dev_shm", + "remarks": "rule_set_012" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure /dev/shm is configured", + "remarks": "rule_set_012" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "partition_for_dev_shm", + "remarks": "rule_set_012" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure /dev/shm is configured", + "remarks": "rule_set_012" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "mount_option_dev_shm_nodev", + "remarks": "rule_set_013" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Add nodev Option to /dev/shm", + "remarks": "rule_set_013" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "mount_option_dev_shm_nodev", + "remarks": "rule_set_013" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Add nodev Option to /dev/shm", + "remarks": "rule_set_013" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "mount_option_dev_shm_nosuid", + "remarks": "rule_set_014" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Add nosuid Option to /dev/shm", + "remarks": "rule_set_014" + }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_dev_shm_nosuid", - "remarks": "rule_set_008" + "remarks": "rule_set_014" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nosuid Option to /dev/shm", - "remarks": "rule_set_008" + "remarks": "rule_set_014" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_dev_shm_noexec", - "remarks": "rule_set_009" + "remarks": "rule_set_015" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add noexec Option to /dev/shm", - "remarks": "rule_set_009" + "remarks": "rule_set_015" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_dev_shm_noexec", - "remarks": "rule_set_009" + "remarks": "rule_set_015" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add noexec Option to /dev/shm", - "remarks": "rule_set_009" + "remarks": "rule_set_015" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_home_nodev", - "remarks": "rule_set_010" + "remarks": "rule_set_016" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nodev Option to /home", - "remarks": "rule_set_010" + "remarks": "rule_set_016" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_home_nodev", - "remarks": "rule_set_010" + "remarks": "rule_set_016" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nodev Option to /home", - "remarks": "rule_set_010" + "remarks": "rule_set_016" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_home_nosuid", - "remarks": "rule_set_011" + "remarks": "rule_set_017" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nosuid Option to /home", - "remarks": "rule_set_011" + "remarks": "rule_set_017" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_home_nosuid", - "remarks": "rule_set_011" + "remarks": "rule_set_017" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nosuid Option to /home", - "remarks": "rule_set_011" + "remarks": "rule_set_017" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_nodev", - "remarks": "rule_set_012" + "remarks": "rule_set_018" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nodev Option to /var", - "remarks": "rule_set_012" + "remarks": "rule_set_018" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_nodev", - "remarks": "rule_set_012" + "remarks": "rule_set_018" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nodev Option to /var", - "remarks": "rule_set_012" + "remarks": "rule_set_018" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_nosuid", - "remarks": "rule_set_013" + "remarks": "rule_set_019" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nosuid Option to /var", - "remarks": "rule_set_013" + "remarks": "rule_set_019" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_nosuid", - "remarks": "rule_set_013" + "remarks": "rule_set_019" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nosuid Option to /var", - "remarks": "rule_set_013" + "remarks": "rule_set_019" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_tmp_nodev", - "remarks": "rule_set_014" + "remarks": "rule_set_020" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nodev Option to /var/tmp", - "remarks": "rule_set_014" + "remarks": "rule_set_020" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_tmp_nodev", - "remarks": "rule_set_014" + "remarks": "rule_set_020" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nodev Option to /var/tmp", - "remarks": "rule_set_014" + "remarks": "rule_set_020" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_tmp_nosuid", - "remarks": "rule_set_015" + "remarks": "rule_set_021" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nosuid Option to /var/tmp", - "remarks": "rule_set_015" + "remarks": "rule_set_021" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_tmp_nosuid", - "remarks": "rule_set_015" + "remarks": "rule_set_021" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nosuid Option to /var/tmp", - "remarks": "rule_set_015" + "remarks": "rule_set_021" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_tmp_noexec", - "remarks": "rule_set_016" + "remarks": "rule_set_022" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add noexec Option to /var/tmp", - "remarks": "rule_set_016" + "remarks": "rule_set_022" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_tmp_noexec", - "remarks": "rule_set_016" + "remarks": "rule_set_022" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add noexec Option to /var/tmp", - "remarks": "rule_set_016" + "remarks": "rule_set_022" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_nodev", - "remarks": "rule_set_017" + "remarks": "rule_set_023" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nodev Option to /var/log", - "remarks": "rule_set_017" + "remarks": "rule_set_023" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_nodev", - "remarks": "rule_set_017" + "remarks": "rule_set_023" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nodev Option to /var/log", - "remarks": "rule_set_017" + "remarks": "rule_set_023" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_nosuid", - "remarks": "rule_set_018" + "remarks": "rule_set_024" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nosuid Option to /var/log", - "remarks": "rule_set_018" + "remarks": "rule_set_024" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_nosuid", - "remarks": "rule_set_018" + "remarks": "rule_set_024" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nosuid Option to /var/log", - "remarks": "rule_set_018" + "remarks": "rule_set_024" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_noexec", - "remarks": "rule_set_019" + "remarks": "rule_set_025" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add noexec Option to /var/log", - "remarks": "rule_set_019" + "remarks": "rule_set_025" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_noexec", - "remarks": "rule_set_019" + "remarks": "rule_set_025" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add noexec Option to /var/log", - "remarks": "rule_set_019" + "remarks": "rule_set_025" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_audit_nodev", - "remarks": "rule_set_020" + "remarks": "rule_set_026" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nodev Option to /var/log/audit", - "remarks": "rule_set_020" + "remarks": "rule_set_026" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_audit_nodev", - "remarks": "rule_set_020" + "remarks": "rule_set_026" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nodev Option to /var/log/audit", - "remarks": "rule_set_020" + "remarks": "rule_set_026" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_audit_nosuid", - "remarks": "rule_set_021" + "remarks": "rule_set_027" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nosuid Option to /var/log/audit", - "remarks": "rule_set_021" + "remarks": "rule_set_027" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_audit_nosuid", - "remarks": "rule_set_021" + "remarks": "rule_set_027" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add nosuid Option to /var/log/audit", - "remarks": "rule_set_021" + "remarks": "rule_set_027" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_audit_noexec", - "remarks": "rule_set_022" + "remarks": "rule_set_028" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add noexec Option to /var/log/audit", - "remarks": "rule_set_022" + "remarks": "rule_set_028" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "mount_option_var_log_audit_noexec", - "remarks": "rule_set_022" + "remarks": "rule_set_028" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Add noexec Option to /var/log/audit", - "remarks": "rule_set_022" + "remarks": "rule_set_028" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "ensure_gpgcheck_globally_activated", - "remarks": "rule_set_023" + "remarks": "rule_set_029" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure gpgcheck Enabled In Main dnf Configuration", - "remarks": "rule_set_023" + "remarks": "rule_set_029" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "ensure_gpgcheck_globally_activated", - "remarks": "rule_set_023" + "remarks": "rule_set_029" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure gpgcheck Enabled In Main dnf Configuration", - "remarks": "rule_set_023" + "remarks": "rule_set_029" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_libselinux_installed", - "remarks": "rule_set_024" + "remarks": "rule_set_030" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Install libselinux Package", - "remarks": "rule_set_024" + "remarks": "rule_set_030" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_libselinux_installed", - "remarks": "rule_set_024" + "remarks": "rule_set_030" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Install libselinux Package", - "remarks": "rule_set_024" + "remarks": "rule_set_030" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "grub2_enable_selinux", - "remarks": "rule_set_025" + "remarks": "rule_set_031" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure SELinux Not Disabled in /etc/default/grub", - "remarks": "rule_set_025" + "remarks": "rule_set_031" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "grub2_enable_selinux", - "remarks": "rule_set_025" + "remarks": "rule_set_031" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure SELinux Not Disabled in /etc/default/grub", - "remarks": "rule_set_025" + "remarks": "rule_set_031" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "selinux_policytype", - "remarks": "rule_set_026" + "remarks": "rule_set_032" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure SELinux Policy", - "remarks": "rule_set_026" + "remarks": "rule_set_032" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "selinux_policytype", - "remarks": "rule_set_026" + "remarks": "rule_set_032" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure SELinux Policy", - "remarks": "rule_set_026" + "remarks": "rule_set_032" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "selinux_not_disabled", - "remarks": "rule_set_027" + "remarks": "rule_set_033" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure SELinux is Not Disabled", - "remarks": "rule_set_027" + "remarks": "rule_set_033" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "selinux_not_disabled", - "remarks": "rule_set_027" + "remarks": "rule_set_033" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure SELinux is Not Disabled", - "remarks": "rule_set_027" + "remarks": "rule_set_033" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_mcstrans_removed", - "remarks": "rule_set_028" + "remarks": "rule_set_034" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall mcstrans Package", - "remarks": "rule_set_028" + "remarks": "rule_set_034" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "package_mcstrans_removed", + "remarks": "rule_set_034" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Uninstall mcstrans Package", + "remarks": "rule_set_034" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "package_setroubleshoot_removed", + "remarks": "rule_set_035" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Uninstall setroubleshoot Package", + "remarks": "rule_set_035" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "package_setroubleshoot_removed", + "remarks": "rule_set_035" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Uninstall setroubleshoot Package", + "remarks": "rule_set_035" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "grub2_password", + "remarks": "rule_set_036" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Set Boot Loader Password in grub2", + "remarks": "rule_set_036" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "grub2_password", + "remarks": "rule_set_036" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Set Boot Loader Password in grub2", + "remarks": "rule_set_036" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_groupowner_grub2_cfg", + "remarks": "rule_set_037" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify /boot/grub2/grub.cfg Group Ownership", + "remarks": "rule_set_037" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_groupowner_grub2_cfg", + "remarks": "rule_set_037" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify /boot/grub2/grub.cfg Group Ownership", + "remarks": "rule_set_037" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_owner_grub2_cfg", + "remarks": "rule_set_038" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify /boot/grub2/grub.cfg User Ownership", + "remarks": "rule_set_038" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_mcstrans_removed", - "remarks": "rule_set_028" + "value": "file_owner_grub2_cfg", + "remarks": "rule_set_038" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall mcstrans Package", - "remarks": "rule_set_028" + "value": "Verify /boot/grub2/grub.cfg User Ownership", + "remarks": "rule_set_038" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_setroubleshoot_removed", - "remarks": "rule_set_029" + "value": "file_permissions_grub2_cfg", + "remarks": "rule_set_039" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall setroubleshoot Package", - "remarks": "rule_set_029" + "value": "Verify /boot/grub2/grub.cfg Permissions", + "remarks": "rule_set_039" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_setroubleshoot_removed", - "remarks": "rule_set_029" + "value": "file_permissions_grub2_cfg", + "remarks": "rule_set_039" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall setroubleshoot Package", - "remarks": "rule_set_029" + "value": "Verify /boot/grub2/grub.cfg Permissions", + "remarks": "rule_set_039" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "grub2_password", - "remarks": "rule_set_030" + "value": "file_groupowner_user_cfg", + "remarks": "rule_set_040" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Boot Loader Password in grub2", - "remarks": "rule_set_030" + "value": "Verify /boot/grub2/user.cfg Group Ownership", + "remarks": "rule_set_040" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "grub2_password", - "remarks": "rule_set_030" + "value": "file_groupowner_user_cfg", + "remarks": "rule_set_040" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Boot Loader Password in grub2", - "remarks": "rule_set_030" + "value": "Verify /boot/grub2/user.cfg Group Ownership", + "remarks": "rule_set_040" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_grub2_cfg", - "remarks": "rule_set_031" + "value": "file_owner_user_cfg", + "remarks": "rule_set_041" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/grub.cfg Group Ownership", - "remarks": "rule_set_031" + "value": "Verify /boot/grub2/user.cfg User Ownership", + "remarks": "rule_set_041" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_grub2_cfg", - "remarks": "rule_set_031" + "value": "file_owner_user_cfg", + "remarks": "rule_set_041" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/grub.cfg Group Ownership", - "remarks": "rule_set_031" + "value": "Verify /boot/grub2/user.cfg User Ownership", + "remarks": "rule_set_041" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_grub2_cfg", - "remarks": "rule_set_032" + "value": "file_permissions_user_cfg", + "remarks": "rule_set_042" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/grub.cfg User Ownership", - "remarks": "rule_set_032" + "value": "Verify /boot/grub2/user.cfg Permissions", + "remarks": "rule_set_042" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_grub2_cfg", - "remarks": "rule_set_032" + "value": "file_permissions_user_cfg", + "remarks": "rule_set_042" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/grub.cfg User Ownership", - "remarks": "rule_set_032" + "value": "Verify /boot/grub2/user.cfg Permissions", + "remarks": "rule_set_042" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_grub2_cfg", - "remarks": "rule_set_033" + "value": "disable_users_coredumps", + "remarks": "rule_set_043" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/grub.cfg Permissions", - "remarks": "rule_set_033" + "value": "Disable Core Dumps for All Users", + "remarks": "rule_set_043" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_grub2_cfg", - "remarks": "rule_set_033" + "value": "disable_users_coredumps", + "remarks": "rule_set_043" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/grub.cfg Permissions", - "remarks": "rule_set_033" + "value": "Disable Core Dumps for All Users", + "remarks": "rule_set_043" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_user_cfg", - "remarks": "rule_set_034" + "value": "sysctl_fs_protected_hardlinks", + "remarks": "rule_set_044" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/user.cfg Group Ownership", - "remarks": "rule_set_034" + "value": "Enable Kernel Parameter to Enforce DAC on Hardlinks", + "remarks": "rule_set_044" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_user_cfg", - "remarks": "rule_set_034" + "value": "sysctl_fs_protected_hardlinks", + "remarks": "rule_set_044" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/user.cfg Group Ownership", - "remarks": "rule_set_034" + "value": "Enable Kernel Parameter to Enforce DAC on Hardlinks", + "remarks": "rule_set_044" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_user_cfg", - "remarks": "rule_set_035" + "value": "sysctl_fs_suid_dumpable", + "remarks": "rule_set_045" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/user.cfg User Ownership", - "remarks": "rule_set_035" + "value": "Disable Core Dumps for SUID programs", + "remarks": "rule_set_045" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_user_cfg", - "remarks": "rule_set_035" + "value": "sysctl_fs_suid_dumpable", + "remarks": "rule_set_045" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/user.cfg User Ownership", - "remarks": "rule_set_035" + "value": "Disable Core Dumps for SUID programs", + "remarks": "rule_set_045" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_user_cfg", - "remarks": "rule_set_036" + "value": "sysctl_kernel_dmesg_restrict", + "remarks": "rule_set_046" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/user.cfg Permissions", - "remarks": "rule_set_036" + "value": "Restrict Access to Kernel Message Buffer", + "remarks": "rule_set_046" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_user_cfg", - "remarks": "rule_set_036" + "value": "sysctl_kernel_dmesg_restrict", + "remarks": "rule_set_046" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/user.cfg Permissions", - "remarks": "rule_set_036" + "value": "Restrict Access to Kernel Message Buffer", + "remarks": "rule_set_046" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_kernel_randomize_va_space", - "remarks": "rule_set_037" + "value": "sysctl_kernel_kptr_restrict", + "remarks": "rule_set_047" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Randomized Layout of Virtual Address Space", - "remarks": "rule_set_037" + "value": "Restrict Exposed Kernel Pointer Addresses Access", + "remarks": "rule_set_047" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_kernel_randomize_va_space", - "remarks": "rule_set_037" + "value": "sysctl_kernel_kptr_restrict", + "remarks": "rule_set_047" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Randomized Layout of Virtual Address Space", - "remarks": "rule_set_037" + "value": "Restrict Exposed Kernel Pointer Addresses Access", + "remarks": "rule_set_047" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_kernel_yama_ptrace_scope", - "remarks": "rule_set_038" + "remarks": "rule_set_048" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Restrict usage of ptrace to descendant processes", - "remarks": "rule_set_038" + "remarks": "rule_set_048" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_kernel_yama_ptrace_scope", - "remarks": "rule_set_038" + "remarks": "rule_set_048" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Restrict usage of ptrace to descendant processes", - "remarks": "rule_set_038" + "remarks": "rule_set_048" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_backtraces", - "remarks": "rule_set_039" + "value": "sysctl_kernel_randomize_va_space", + "remarks": "rule_set_049" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable core dump backtraces", - "remarks": "rule_set_039" + "value": "Enable Randomized Layout of Virtual Address Space", + "remarks": "rule_set_049" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_backtraces", - "remarks": "rule_set_039" + "value": "sysctl_kernel_randomize_va_space", + "remarks": "rule_set_049" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable core dump backtraces", - "remarks": "rule_set_039" + "value": "Enable Randomized Layout of Virtual Address Space", + "remarks": "rule_set_049" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_storage", - "remarks": "rule_set_040" + "value": "coredump_disable_backtraces", + "remarks": "rule_set_050" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable storing core dump", - "remarks": "rule_set_040" + "value": "Disable core dump backtraces", + "remarks": "rule_set_050" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_storage", - "remarks": "rule_set_040" + "value": "coredump_disable_backtraces", + "remarks": "rule_set_050" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable storing core dump", - "remarks": "rule_set_040" + "value": "Disable core dump backtraces", + "remarks": "rule_set_050" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_crypto_policy", - "remarks": "rule_set_041" + "value": "coredump_disable_storage", + "remarks": "rule_set_051" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure System Cryptography Policy", - "remarks": "rule_set_041" + "value": "Disable storing core dump", + "remarks": "rule_set_051" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_crypto_policy", - "remarks": "rule_set_041" + "value": "coredump_disable_storage", + "remarks": "rule_set_051" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure System Cryptography Policy", - "remarks": "rule_set_041" + "value": "Disable storing core dump", + "remarks": "rule_set_051" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_ssh_crypto_policy", - "remarks": "rule_set_042" + "value": "configure_crypto_policy", + "remarks": "rule_set_052" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure SSH to use System Crypto Policy", - "remarks": "rule_set_042" + "value": "Configure System Cryptography Policy", + "remarks": "rule_set_052" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_ssh_crypto_policy", - "remarks": "rule_set_042" + "value": "configure_crypto_policy", + "remarks": "rule_set_052" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure SSH to use System Crypto Policy", - "remarks": "rule_set_042" + "value": "Configure System Cryptography Policy", + "remarks": "rule_set_052" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "banner_etc_motd_cis", - "remarks": "rule_set_043" + "remarks": "rule_set_053" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Message Of The Day Is Configured Properly", - "remarks": "rule_set_043" + "remarks": "rule_set_053" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "banner_etc_motd_cis", - "remarks": "rule_set_043" + "remarks": "rule_set_053" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Message Of The Day Is Configured Properly", - "remarks": "rule_set_043" + "remarks": "rule_set_053" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "banner_etc_issue_cis", - "remarks": "rule_set_044" + "remarks": "rule_set_054" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Local Login Warning Banner Is Configured Properly", - "remarks": "rule_set_044" + "remarks": "rule_set_054" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "banner_etc_issue_cis", - "remarks": "rule_set_044" + "remarks": "rule_set_054" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Local Login Warning Banner Is Configured Properly", - "remarks": "rule_set_044" + "remarks": "rule_set_054" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "banner_etc_issue_net_cis", - "remarks": "rule_set_045" + "remarks": "rule_set_055" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Remote Login Warning Banner Is Configured Properly", - "remarks": "rule_set_045" + "remarks": "rule_set_055" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "banner_etc_issue_net_cis", - "remarks": "rule_set_045" + "remarks": "rule_set_055" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Remote Login Warning Banner Is Configured Properly", - "remarks": "rule_set_045" + "remarks": "rule_set_055" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_motd", - "remarks": "rule_set_046" + "remarks": "rule_set_056" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Ownership of Message of the Day Banner", - "remarks": "rule_set_046" + "remarks": "rule_set_056" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_motd", - "remarks": "rule_set_046" + "remarks": "rule_set_056" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Ownership of Message of the Day Banner", - "remarks": "rule_set_046" + "remarks": "rule_set_056" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_motd", - "remarks": "rule_set_047" + "remarks": "rule_set_057" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify ownership of Message of the Day Banner", - "remarks": "rule_set_047" + "remarks": "rule_set_057" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_motd", - "remarks": "rule_set_047" + "remarks": "rule_set_057" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify ownership of Message of the Day Banner", - "remarks": "rule_set_047" + "remarks": "rule_set_057" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_motd", - "remarks": "rule_set_048" + "remarks": "rule_set_058" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify permissions on Message of the Day Banner", - "remarks": "rule_set_048" + "remarks": "rule_set_058" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_motd", - "remarks": "rule_set_048" + "remarks": "rule_set_058" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify permissions on Message of the Day Banner", - "remarks": "rule_set_048" + "remarks": "rule_set_058" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_issue", - "remarks": "rule_set_049" + "remarks": "rule_set_059" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Ownership of System Login Banner", - "remarks": "rule_set_049" + "remarks": "rule_set_059" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_issue", - "remarks": "rule_set_049" + "remarks": "rule_set_059" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Ownership of System Login Banner", - "remarks": "rule_set_049" + "remarks": "rule_set_059" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_issue", - "remarks": "rule_set_050" + "remarks": "rule_set_060" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify ownership of System Login Banner", - "remarks": "rule_set_050" + "remarks": "rule_set_060" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_issue", - "remarks": "rule_set_050" + "remarks": "rule_set_060" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify ownership of System Login Banner", - "remarks": "rule_set_050" + "remarks": "rule_set_060" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_issue", - "remarks": "rule_set_051" + "remarks": "rule_set_061" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify permissions on System Login Banner", - "remarks": "rule_set_051" + "remarks": "rule_set_061" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_issue", - "remarks": "rule_set_051" + "remarks": "rule_set_061" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify permissions on System Login Banner", - "remarks": "rule_set_051" + "remarks": "rule_set_061" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_issue_net", - "remarks": "rule_set_052" + "remarks": "rule_set_062" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Ownership of System Login Banner for Remote Connections", - "remarks": "rule_set_052" + "remarks": "rule_set_062" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_issue_net", - "remarks": "rule_set_052" + "remarks": "rule_set_062" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Ownership of System Login Banner for Remote Connections", - "remarks": "rule_set_052" + "remarks": "rule_set_062" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_issue_net", - "remarks": "rule_set_053" + "remarks": "rule_set_063" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify ownership of System Login Banner for Remote Connections", - "remarks": "rule_set_053" + "remarks": "rule_set_063" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_issue_net", - "remarks": "rule_set_053" + "remarks": "rule_set_063" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify ownership of System Login Banner for Remote Connections", - "remarks": "rule_set_053" + "remarks": "rule_set_063" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_issue_net", - "remarks": "rule_set_054" + "remarks": "rule_set_064" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify permissions on System Login Banner for Remote Connections", - "remarks": "rule_set_054" + "remarks": "rule_set_064" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_issue_net", - "remarks": "rule_set_054" + "remarks": "rule_set_064" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify permissions on System Login Banner for Remote Connections", - "remarks": "rule_set_054" + "remarks": "rule_set_064" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_banner_enabled", - "remarks": "rule_set_055" + "remarks": "rule_set_065" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable GNOME3 Login Warning Banner", - "remarks": "rule_set_055" + "remarks": "rule_set_065" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_banner_enabled", - "remarks": "rule_set_055" + "remarks": "rule_set_065" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable GNOME3 Login Warning Banner", - "remarks": "rule_set_055" + "remarks": "rule_set_065" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_login_banner_text", - "remarks": "rule_set_056" + "remarks": "rule_set_066" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set the GNOME3 Login Warning Banner Text", - "remarks": "rule_set_056" + "remarks": "rule_set_066" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_login_banner_text", - "remarks": "rule_set_056" + "remarks": "rule_set_066" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set the GNOME3 Login Warning Banner Text", - "remarks": "rule_set_056" + "remarks": "rule_set_066" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_disable_user_list", - "remarks": "rule_set_057" + "remarks": "rule_set_067" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable the GNOME3 Login User List", - "remarks": "rule_set_057" + "remarks": "rule_set_067" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_disable_user_list", - "remarks": "rule_set_057" + "remarks": "rule_set_067" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable the GNOME3 Login User List", - "remarks": "rule_set_057" + "remarks": "rule_set_067" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_screensaver_idle_delay", - "remarks": "rule_set_058" + "remarks": "rule_set_068" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set GNOME3 Screensaver Inactivity Timeout", - "remarks": "rule_set_058" + "remarks": "rule_set_068" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_screensaver_idle_delay", - "remarks": "rule_set_058" + "remarks": "rule_set_068" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set GNOME3 Screensaver Inactivity Timeout", - "remarks": "rule_set_058" + "remarks": "rule_set_068" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_screensaver_lock_delay", - "remarks": "rule_set_059" + "remarks": "rule_set_069" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set GNOME3 Screensaver Lock Delay After Activation Period", - "remarks": "rule_set_059" + "remarks": "rule_set_069" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_screensaver_lock_delay", - "remarks": "rule_set_059" + "remarks": "rule_set_069" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set GNOME3 Screensaver Lock Delay After Activation Period", - "remarks": "rule_set_059" + "remarks": "rule_set_069" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_session_idle_user_locks", - "remarks": "rule_set_060" + "remarks": "rule_set_070" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Users Cannot Change GNOME3 Session Idle Settings", - "remarks": "rule_set_060" + "remarks": "rule_set_070" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_session_idle_user_locks", - "remarks": "rule_set_060" + "remarks": "rule_set_070" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Users Cannot Change GNOME3 Session Idle Settings", - "remarks": "rule_set_060" + "remarks": "rule_set_070" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_screensaver_user_locks", - "remarks": "rule_set_061" + "remarks": "rule_set_071" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Users Cannot Change GNOME3 Screensaver Settings", - "remarks": "rule_set_061" + "remarks": "rule_set_071" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_screensaver_user_locks", - "remarks": "rule_set_061" + "remarks": "rule_set_071" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Users Cannot Change GNOME3 Screensaver Settings", - "remarks": "rule_set_061" + "remarks": "rule_set_071" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_disable_automount", - "remarks": "rule_set_062" + "remarks": "rule_set_072" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable GNOME3 Automounting", - "remarks": "rule_set_062" + "remarks": "rule_set_072" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_disable_automount", - "remarks": "rule_set_062" + "remarks": "rule_set_072" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable GNOME3 Automounting", - "remarks": "rule_set_062" + "remarks": "rule_set_072" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_disable_automount_open", - "remarks": "rule_set_063" + "remarks": "rule_set_073" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable GNOME3 Automount Opening", - "remarks": "rule_set_063" + "remarks": "rule_set_073" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_disable_automount_open", - "remarks": "rule_set_063" + "remarks": "rule_set_073" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable GNOME3 Automount Opening", - "remarks": "rule_set_063" + "remarks": "rule_set_073" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_disable_autorun", - "remarks": "rule_set_064" + "remarks": "rule_set_074" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable GNOME3 Automount running", - "remarks": "rule_set_064" + "remarks": "rule_set_074" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_disable_autorun", - "remarks": "rule_set_064" + "remarks": "rule_set_074" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable GNOME3 Automount running", - "remarks": "rule_set_064" + "remarks": "rule_set_074" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_autofs_disabled", - "remarks": "rule_set_065" + "remarks": "rule_set_075" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable the Automounter", - "remarks": "rule_set_065" + "remarks": "rule_set_075" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_autofs_disabled", - "remarks": "rule_set_065" + "remarks": "rule_set_075" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable the Automounter", - "remarks": "rule_set_065" + "remarks": "rule_set_075" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_avahi-daemon_disabled", - "remarks": "rule_set_066" + "remarks": "rule_set_076" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Avahi Server Software", - "remarks": "rule_set_066" + "remarks": "rule_set_076" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_avahi-daemon_disabled", - "remarks": "rule_set_066" + "remarks": "rule_set_076" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Avahi Server Software", - "remarks": "rule_set_066" + "remarks": "rule_set_076" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_kea_removed", - "remarks": "rule_set_067" + "remarks": "rule_set_077" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall kea Package", - "remarks": "rule_set_067" + "remarks": "rule_set_077" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_kea_removed", - "remarks": "rule_set_067" + "remarks": "rule_set_077" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall kea Package", - "remarks": "rule_set_067" + "remarks": "rule_set_077" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_bind_removed", - "remarks": "rule_set_068" + "remarks": "rule_set_078" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall bind Package", - "remarks": "rule_set_068" + "remarks": "rule_set_078" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_bind_removed", - "remarks": "rule_set_068" + "remarks": "rule_set_078" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall bind Package", - "remarks": "rule_set_068" + "remarks": "rule_set_078" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_dnsmasq_removed", - "remarks": "rule_set_069" + "remarks": "rule_set_079" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall dnsmasq Package", - "remarks": "rule_set_069" + "remarks": "rule_set_079" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_dnsmasq_removed", - "remarks": "rule_set_069" + "remarks": "rule_set_079" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall dnsmasq Package", - "remarks": "rule_set_069" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_samba_removed", - "remarks": "rule_set_070" - }, - { - "name": "Rule_Description", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall Samba Package", - "remarks": "rule_set_070" - }, - { - "name": "Check_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_samba_removed", - "remarks": "rule_set_070" - }, - { - "name": "Check_Description", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall Samba Package", - "remarks": "rule_set_070" + "remarks": "rule_set_079" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_vsftpd_removed", - "remarks": "rule_set_071" + "remarks": "rule_set_080" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall vsftpd Package", - "remarks": "rule_set_071" + "remarks": "rule_set_080" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_vsftpd_removed", - "remarks": "rule_set_071" + "remarks": "rule_set_080" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall vsftpd Package", - "remarks": "rule_set_071" + "remarks": "rule_set_080" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_dovecot_removed", - "remarks": "rule_set_072" + "remarks": "rule_set_081" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall dovecot Package", - "remarks": "rule_set_072" + "remarks": "rule_set_081" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_dovecot_removed", - "remarks": "rule_set_072" + "remarks": "rule_set_081" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall dovecot Package", - "remarks": "rule_set_072" + "remarks": "rule_set_081" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_cyrus-imapd_removed", - "remarks": "rule_set_073" + "remarks": "rule_set_082" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall cyrus-imapd Package", - "remarks": "rule_set_073" + "remarks": "rule_set_082" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_cyrus-imapd_removed", - "remarks": "rule_set_073" + "remarks": "rule_set_082" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall cyrus-imapd Package", - "remarks": "rule_set_073" + "remarks": "rule_set_082" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_nfs_disabled", - "remarks": "rule_set_074" + "remarks": "rule_set_083" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Network File System (nfs)", - "remarks": "rule_set_074" + "remarks": "rule_set_083" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_nfs_disabled", - "remarks": "rule_set_074" + "remarks": "rule_set_083" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Network File System (nfs)", - "remarks": "rule_set_074" + "remarks": "rule_set_083" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_cups_disabled", - "remarks": "rule_set_075" + "remarks": "rule_set_084" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable the CUPS Service", - "remarks": "rule_set_075" + "remarks": "rule_set_084" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_cups_disabled", - "remarks": "rule_set_075" + "remarks": "rule_set_084" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable the CUPS Service", - "remarks": "rule_set_075" + "remarks": "rule_set_084" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_rpcbind_disabled", - "remarks": "rule_set_076" + "remarks": "rule_set_085" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable rpcbind Service", - "remarks": "rule_set_076" + "remarks": "rule_set_085" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_rpcbind_disabled", - "remarks": "rule_set_076" + "remarks": "rule_set_085" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable rpcbind Service", - "remarks": "rule_set_076" + "remarks": "rule_set_085" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "package_rsync_removed", + "remarks": "rule_set_086" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Uninstall rsync Package", + "remarks": "rule_set_086" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "package_rsync_removed", + "remarks": "rule_set_086" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Uninstall rsync Package", + "remarks": "rule_set_086" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_rsync_removed", - "remarks": "rule_set_077" + "value": "package_samba_removed", + "remarks": "rule_set_087" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall rsync Package", - "remarks": "rule_set_077" + "value": "Uninstall Samba Package", + "remarks": "rule_set_087" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_rsync_removed", - "remarks": "rule_set_077" + "value": "package_samba_removed", + "remarks": "rule_set_087" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall rsync Package", - "remarks": "rule_set_077" + "value": "Uninstall Samba Package", + "remarks": "rule_set_087" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_net-snmp_removed", - "remarks": "rule_set_078" + "remarks": "rule_set_088" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall net-snmp Package", - "remarks": "rule_set_078" + "remarks": "rule_set_088" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_net-snmp_removed", - "remarks": "rule_set_078" + "remarks": "rule_set_088" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall net-snmp Package", - "remarks": "rule_set_078" + "remarks": "rule_set_088" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_telnet-server_removed", - "remarks": "rule_set_079" + "remarks": "rule_set_089" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall telnet-server Package", - "remarks": "rule_set_079" + "remarks": "rule_set_089" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_telnet-server_removed", - "remarks": "rule_set_079" + "remarks": "rule_set_089" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall telnet-server Package", - "remarks": "rule_set_079" + "remarks": "rule_set_089" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_tftp-server_removed", - "remarks": "rule_set_080" + "remarks": "rule_set_090" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall tftp-server Package", - "remarks": "rule_set_080" + "remarks": "rule_set_090" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_tftp-server_removed", - "remarks": "rule_set_080" + "remarks": "rule_set_090" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall tftp-server Package", - "remarks": "rule_set_080" + "remarks": "rule_set_090" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_squid_removed", - "remarks": "rule_set_081" + "remarks": "rule_set_091" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall squid Package", - "remarks": "rule_set_081" + "remarks": "rule_set_091" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_squid_removed", - "remarks": "rule_set_081" + "remarks": "rule_set_091" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall squid Package", - "remarks": "rule_set_081" + "remarks": "rule_set_091" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_httpd_removed", - "remarks": "rule_set_082" + "remarks": "rule_set_092" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall httpd Package", - "remarks": "rule_set_082" + "remarks": "rule_set_092" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_httpd_removed", - "remarks": "rule_set_082" + "remarks": "rule_set_092" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall httpd Package", - "remarks": "rule_set_082" + "remarks": "rule_set_092" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_nginx_removed", - "remarks": "rule_set_083" + "remarks": "rule_set_093" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall nginx Package", - "remarks": "rule_set_083" + "remarks": "rule_set_093" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_nginx_removed", - "remarks": "rule_set_083" + "remarks": "rule_set_093" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Uninstall nginx Package", - "remarks": "rule_set_083" + "remarks": "rule_set_093" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "postfix_network_listening_disabled", - "remarks": "rule_set_084" + "remarks": "rule_set_094" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Postfix Network Listening", - "remarks": "rule_set_084" + "remarks": "rule_set_094" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "postfix_network_listening_disabled", - "remarks": "rule_set_084" + "remarks": "rule_set_094" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Postfix Network Listening", - "remarks": "rule_set_084" + "remarks": "rule_set_094" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "has_nonlocal_mta", - "remarks": "rule_set_085" + "remarks": "rule_set_095" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Mail Transfer Agent is not Listening on any non-loopback Address", - "remarks": "rule_set_085" + "remarks": "rule_set_095" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "has_nonlocal_mta", - "remarks": "rule_set_085" + "remarks": "rule_set_095" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Mail Transfer Agent is not Listening on any non-loopback Address", - "remarks": "rule_set_085" + "remarks": "rule_set_095" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_ftp_removed", - "remarks": "rule_set_086" + "remarks": "rule_set_096" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Remove ftp Package", - "remarks": "rule_set_086" + "remarks": "rule_set_096" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_ftp_removed", - "remarks": "rule_set_086" + "remarks": "rule_set_096" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Remove ftp Package", - "remarks": "rule_set_086" + "remarks": "rule_set_096" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_telnet_removed", - "remarks": "rule_set_087" + "remarks": "rule_set_097" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Remove telnet Clients", - "remarks": "rule_set_087" + "remarks": "rule_set_097" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_telnet_removed", - "remarks": "rule_set_087" + "remarks": "rule_set_097" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Remove telnet Clients", - "remarks": "rule_set_087" + "remarks": "rule_set_097" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_tftp_removed", - "remarks": "rule_set_088" + "remarks": "rule_set_098" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Remove tftp Daemon", - "remarks": "rule_set_088" + "remarks": "rule_set_098" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_tftp_removed", - "remarks": "rule_set_088" + "remarks": "rule_set_098" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Remove tftp Daemon", - "remarks": "rule_set_088" + "remarks": "rule_set_098" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "chronyd_specify_remote_server", - "remarks": "rule_set_089" + "remarks": "rule_set_099" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "A remote time server for Chrony is configured", - "remarks": "rule_set_089" + "remarks": "rule_set_099" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "chronyd_specify_remote_server", - "remarks": "rule_set_089" + "remarks": "rule_set_099" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "A remote time server for Chrony is configured", - "remarks": "rule_set_089" + "remarks": "rule_set_099" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "chronyd_run_as_chrony_user", - "remarks": "rule_set_090" + "remarks": "rule_set_100" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that chronyd is running under chrony user account", - "remarks": "rule_set_090" + "remarks": "rule_set_100" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "chronyd_run_as_chrony_user", - "remarks": "rule_set_090" + "remarks": "rule_set_100" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that chronyd is running under chrony user account", - "remarks": "rule_set_090" + "remarks": "rule_set_100" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_cron_installed", - "remarks": "rule_set_091" + "remarks": "rule_set_101" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Install the cron service", - "remarks": "rule_set_091" + "remarks": "rule_set_101" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_cron_installed", - "remarks": "rule_set_091" + "remarks": "rule_set_101" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Install the cron service", - "remarks": "rule_set_091" + "remarks": "rule_set_101" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_crond_enabled", - "remarks": "rule_set_092" + "remarks": "rule_set_102" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable cron Service", - "remarks": "rule_set_092" + "remarks": "rule_set_102" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_crond_enabled", - "remarks": "rule_set_092" + "remarks": "rule_set_102" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable cron Service", - "remarks": "rule_set_092" + "remarks": "rule_set_102" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_crontab", - "remarks": "rule_set_093" + "remarks": "rule_set_103" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns Crontab", - "remarks": "rule_set_093" + "remarks": "rule_set_103" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_crontab", - "remarks": "rule_set_093" + "remarks": "rule_set_103" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns Crontab", - "remarks": "rule_set_093" + "remarks": "rule_set_103" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_crontab", - "remarks": "rule_set_094" + "remarks": "rule_set_104" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on crontab", - "remarks": "rule_set_094" + "remarks": "rule_set_104" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_crontab", - "remarks": "rule_set_094" + "remarks": "rule_set_104" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on crontab", - "remarks": "rule_set_094" + "remarks": "rule_set_104" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_crontab", - "remarks": "rule_set_095" + "remarks": "rule_set_105" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on crontab", - "remarks": "rule_set_095" + "remarks": "rule_set_105" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_crontab", - "remarks": "rule_set_095" + "remarks": "rule_set_105" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on crontab", - "remarks": "rule_set_095" + "remarks": "rule_set_105" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_cron_hourly", - "remarks": "rule_set_096" + "remarks": "rule_set_106" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns cron.hourly", - "remarks": "rule_set_096" + "remarks": "rule_set_106" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_cron_hourly", - "remarks": "rule_set_096" + "remarks": "rule_set_106" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns cron.hourly", - "remarks": "rule_set_096" + "remarks": "rule_set_106" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_cron_hourly", - "remarks": "rule_set_097" + "remarks": "rule_set_107" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on cron.hourly", - "remarks": "rule_set_097" + "remarks": "rule_set_107" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_cron_hourly", - "remarks": "rule_set_097" + "remarks": "rule_set_107" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on cron.hourly", - "remarks": "rule_set_097" + "remarks": "rule_set_107" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_cron_hourly", - "remarks": "rule_set_098" + "remarks": "rule_set_108" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on cron.hourly", - "remarks": "rule_set_098" + "remarks": "rule_set_108" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_cron_hourly", - "remarks": "rule_set_098" + "remarks": "rule_set_108" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on cron.hourly", - "remarks": "rule_set_098" + "remarks": "rule_set_108" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_cron_daily", - "remarks": "rule_set_099" + "remarks": "rule_set_109" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns cron.daily", - "remarks": "rule_set_099" + "remarks": "rule_set_109" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_cron_daily", - "remarks": "rule_set_099" + "remarks": "rule_set_109" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns cron.daily", - "remarks": "rule_set_099" + "remarks": "rule_set_109" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_cron_daily", - "remarks": "rule_set_100" + "remarks": "rule_set_110" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on cron.daily", - "remarks": "rule_set_100" + "remarks": "rule_set_110" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_cron_daily", - "remarks": "rule_set_100" + "remarks": "rule_set_110" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on cron.daily", - "remarks": "rule_set_100" + "remarks": "rule_set_110" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_cron_daily", - "remarks": "rule_set_101" + "remarks": "rule_set_111" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on cron.daily", - "remarks": "rule_set_101" + "remarks": "rule_set_111" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_cron_daily", - "remarks": "rule_set_101" + "remarks": "rule_set_111" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on cron.daily", - "remarks": "rule_set_101" + "remarks": "rule_set_111" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_cron_weekly", - "remarks": "rule_set_102" + "remarks": "rule_set_112" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns cron.weekly", - "remarks": "rule_set_102" + "remarks": "rule_set_112" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_cron_weekly", - "remarks": "rule_set_102" + "remarks": "rule_set_112" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns cron.weekly", - "remarks": "rule_set_102" + "remarks": "rule_set_112" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_cron_weekly", - "remarks": "rule_set_103" + "remarks": "rule_set_113" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on cron.weekly", - "remarks": "rule_set_103" + "remarks": "rule_set_113" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_cron_weekly", - "remarks": "rule_set_103" + "remarks": "rule_set_113" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on cron.weekly", - "remarks": "rule_set_103" + "remarks": "rule_set_113" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_cron_weekly", - "remarks": "rule_set_104" + "remarks": "rule_set_114" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on cron.weekly", - "remarks": "rule_set_104" + "remarks": "rule_set_114" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_cron_weekly", - "remarks": "rule_set_104" + "remarks": "rule_set_114" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on cron.weekly", - "remarks": "rule_set_104" + "remarks": "rule_set_114" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_cron_monthly", - "remarks": "rule_set_105" + "remarks": "rule_set_115" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns cron.monthly", - "remarks": "rule_set_105" + "remarks": "rule_set_115" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_cron_monthly", - "remarks": "rule_set_105" + "remarks": "rule_set_115" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns cron.monthly", - "remarks": "rule_set_105" + "remarks": "rule_set_115" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_cron_monthly", - "remarks": "rule_set_106" + "remarks": "rule_set_116" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on cron.monthly", - "remarks": "rule_set_106" + "remarks": "rule_set_116" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_cron_monthly", - "remarks": "rule_set_106" + "remarks": "rule_set_116" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on cron.monthly", - "remarks": "rule_set_106" + "remarks": "rule_set_116" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_cron_monthly", - "remarks": "rule_set_107" + "remarks": "rule_set_117" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on cron.monthly", - "remarks": "rule_set_107" + "remarks": "rule_set_117" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_cron_monthly", - "remarks": "rule_set_107" + "remarks": "rule_set_117" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on cron.monthly", - "remarks": "rule_set_107" + "remarks": "rule_set_117" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_cron_d", - "remarks": "rule_set_108" + "remarks": "rule_set_118" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns cron.d", - "remarks": "rule_set_108" + "remarks": "rule_set_118" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_cron_d", - "remarks": "rule_set_108" + "remarks": "rule_set_118" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns cron.d", - "remarks": "rule_set_108" + "remarks": "rule_set_118" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_cron_d", - "remarks": "rule_set_109" + "remarks": "rule_set_119" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on cron.d", - "remarks": "rule_set_109" + "remarks": "rule_set_119" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_cron_d", - "remarks": "rule_set_109" + "remarks": "rule_set_119" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on cron.d", - "remarks": "rule_set_109" + "remarks": "rule_set_119" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_cron_d", - "remarks": "rule_set_110" + "remarks": "rule_set_120" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on cron.d", - "remarks": "rule_set_110" + "remarks": "rule_set_120" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_cron_d", - "remarks": "rule_set_110" + "remarks": "rule_set_120" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on cron.d", - "remarks": "rule_set_110" + "remarks": "rule_set_120" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_cron_deny_not_exist", - "remarks": "rule_set_111" + "remarks": "rule_set_121" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that /etc/cron.deny does not exist", - "remarks": "rule_set_111" + "remarks": "rule_set_121" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_cron_deny_not_exist", - "remarks": "rule_set_111" + "remarks": "rule_set_121" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that /etc/cron.deny does not exist", - "remarks": "rule_set_111" + "remarks": "rule_set_121" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_cron_allow_exists", - "remarks": "rule_set_112" + "remarks": "rule_set_122" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that /etc/cron.allow exists", - "remarks": "rule_set_112" + "remarks": "rule_set_122" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_cron_allow_exists", - "remarks": "rule_set_112" + "remarks": "rule_set_122" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that /etc/cron.allow exists", - "remarks": "rule_set_112" + "remarks": "rule_set_122" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_cron_allow", - "remarks": "rule_set_113" + "remarks": "rule_set_123" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns /etc/cron.allow file", - "remarks": "rule_set_113" + "remarks": "rule_set_123" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_cron_allow", - "remarks": "rule_set_113" + "remarks": "rule_set_123" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns /etc/cron.allow file", - "remarks": "rule_set_113" + "remarks": "rule_set_123" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_cron_allow", - "remarks": "rule_set_114" + "remarks": "rule_set_124" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns /etc/cron.allow file", - "remarks": "rule_set_114" + "remarks": "rule_set_124" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_cron_allow", - "remarks": "rule_set_114" + "remarks": "rule_set_124" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns /etc/cron.allow file", - "remarks": "rule_set_114" + "remarks": "rule_set_124" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_cron_allow", - "remarks": "rule_set_115" + "remarks": "rule_set_125" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on /etc/cron.allow file", - "remarks": "rule_set_115" + "remarks": "rule_set_125" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_cron_allow", - "remarks": "rule_set_115" + "remarks": "rule_set_125" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on /etc/cron.allow file", - "remarks": "rule_set_115" + "remarks": "rule_set_125" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_at_deny_not_exist", - "remarks": "rule_set_116" + "remarks": "rule_set_126" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that /etc/at.deny does not exist", - "remarks": "rule_set_116" + "remarks": "rule_set_126" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_at_deny_not_exist", - "remarks": "rule_set_116" + "remarks": "rule_set_126" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that /etc/at.deny does not exist", - "remarks": "rule_set_116" + "remarks": "rule_set_126" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_at_allow", - "remarks": "rule_set_117" + "remarks": "rule_set_127" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns /etc/at.allow file", - "remarks": "rule_set_117" + "remarks": "rule_set_127" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_at_allow", - "remarks": "rule_set_117" + "remarks": "rule_set_127" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns /etc/at.allow file", - "remarks": "rule_set_117" + "remarks": "rule_set_127" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_at_allow", - "remarks": "rule_set_118" + "remarks": "rule_set_128" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns /etc/at.allow file", - "remarks": "rule_set_118" + "remarks": "rule_set_128" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_at_allow", - "remarks": "rule_set_118" + "remarks": "rule_set_128" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns /etc/at.allow file", - "remarks": "rule_set_118" + "remarks": "rule_set_128" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_at_allow", - "remarks": "rule_set_119" + "remarks": "rule_set_129" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on /etc/at.allow file", - "remarks": "rule_set_119" + "remarks": "rule_set_129" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_at_allow", - "remarks": "rule_set_119" + "remarks": "rule_set_129" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on /etc/at.allow file", - "remarks": "rule_set_119" + "remarks": "rule_set_129" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "wireless_disable_interfaces", - "remarks": "rule_set_120" + "remarks": "rule_set_130" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Deactivate Wireless Network Interfaces", - "remarks": "rule_set_120" + "remarks": "rule_set_130" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "wireless_disable_interfaces", - "remarks": "rule_set_120" + "remarks": "rule_set_130" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Deactivate Wireless Network Interfaces", - "remarks": "rule_set_120" + "remarks": "rule_set_130" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_bluetooth_disabled", - "remarks": "rule_set_121" + "remarks": "rule_set_131" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Bluetooth Service", - "remarks": "rule_set_121" + "remarks": "rule_set_131" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_bluetooth_disabled", - "remarks": "rule_set_121" + "remarks": "rule_set_131" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Bluetooth Service", - "remarks": "rule_set_121" + "remarks": "rule_set_131" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_ip_forward", - "remarks": "rule_set_122" + "value": "kernel_module_atm_disabled", + "remarks": "rule_set_132" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for IP Forwarding on IPv4 Interfaces", - "remarks": "rule_set_122" + "value": "Disable ATM Support", + "remarks": "rule_set_132" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_ip_forward", - "remarks": "rule_set_122" + "value": "kernel_module_atm_disabled", + "remarks": "rule_set_132" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for IP Forwarding on IPv4 Interfaces", - "remarks": "rule_set_122" + "value": "Disable ATM Support", + "remarks": "rule_set_132" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_forwarding", - "remarks": "rule_set_123" + "value": "kernel_module_can_disabled", + "remarks": "rule_set_133" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for IPv6 Forwarding", - "remarks": "rule_set_123" + "value": "Disable CAN Support", + "remarks": "rule_set_133" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_forwarding", - "remarks": "rule_set_123" + "value": "kernel_module_can_disabled", + "remarks": "rule_set_133" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for IPv6 Forwarding", - "remarks": "rule_set_123" + "value": "Disable CAN Support", + "remarks": "rule_set_133" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "kernel_module_dccp_disabled", + "remarks": "rule_set_134" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Disable DCCP Support", + "remarks": "rule_set_134" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "kernel_module_dccp_disabled", + "remarks": "rule_set_134" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Disable DCCP Support", + "remarks": "rule_set_134" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "kernel_module_tipc_disabled", + "remarks": "rule_set_135" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Disable TIPC Support", + "remarks": "rule_set_135" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "kernel_module_tipc_disabled", + "remarks": "rule_set_135" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Disable TIPC Support", + "remarks": "rule_set_135" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "kernel_module_rds_disabled", + "remarks": "rule_set_136" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Disable RDS Support", + "remarks": "rule_set_136" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "kernel_module_rds_disabled", + "remarks": "rule_set_136" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Disable RDS Support", + "remarks": "rule_set_136" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "kernel_module_sctp_disabled", + "remarks": "rule_set_137" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Disable SCTP Support", + "remarks": "rule_set_137" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "kernel_module_sctp_disabled", + "remarks": "rule_set_137" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Disable SCTP Support", + "remarks": "rule_set_137" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sysctl_net_ipv4_conf_all_forwarding", + "remarks": "rule_set_138" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Disable Kernel Parameter for IPv4 Forwarding on all IPv4 Interfaces", + "remarks": "rule_set_138" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sysctl_net_ipv4_conf_all_forwarding", + "remarks": "rule_set_138" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Disable Kernel Parameter for IPv4 Forwarding on all IPv4 Interfaces", + "remarks": "rule_set_138" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_conf_all_send_redirects", - "remarks": "rule_set_124" + "remarks": "rule_set_139" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces", - "remarks": "rule_set_124" + "remarks": "rule_set_139" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_conf_all_send_redirects", - "remarks": "rule_set_124" + "remarks": "rule_set_139" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces", - "remarks": "rule_set_124" + "remarks": "rule_set_139" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_conf_default_send_redirects", - "remarks": "rule_set_125" + "remarks": "rule_set_140" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces by Default", - "remarks": "rule_set_125" + "remarks": "rule_set_140" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_conf_default_send_redirects", - "remarks": "rule_set_125" + "remarks": "rule_set_140" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces by Default", - "remarks": "rule_set_125" + "remarks": "rule_set_140" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses", - "remarks": "rule_set_126" + "remarks": "rule_set_141" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable Kernel Parameter to Ignore Bogus ICMP Error Responses on IPv4 Interfaces", - "remarks": "rule_set_126" + "remarks": "rule_set_141" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses", - "remarks": "rule_set_126" + "remarks": "rule_set_141" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable Kernel Parameter to Ignore Bogus ICMP Error Responses on IPv4 Interfaces", - "remarks": "rule_set_126" + "remarks": "rule_set_141" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts", - "remarks": "rule_set_127" + "remarks": "rule_set_142" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable Kernel Parameter to Ignore ICMP Broadcast Echo Requests on IPv4 Interfaces", - "remarks": "rule_set_127" + "remarks": "rule_set_142" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts", - "remarks": "rule_set_127" + "remarks": "rule_set_142" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable Kernel Parameter to Ignore ICMP Broadcast Echo Requests on IPv4 Interfaces", - "remarks": "rule_set_127" + "remarks": "rule_set_142" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_conf_all_accept_redirects", - "remarks": "rule_set_128" + "remarks": "rule_set_143" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Accepting ICMP Redirects for All IPv4 Interfaces", - "remarks": "rule_set_128" + "remarks": "rule_set_143" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_conf_all_accept_redirects", - "remarks": "rule_set_128" + "remarks": "rule_set_143" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Accepting ICMP Redirects for All IPv4 Interfaces", - "remarks": "rule_set_128" + "remarks": "rule_set_143" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_conf_default_accept_redirects", - "remarks": "rule_set_129" + "remarks": "rule_set_144" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 Interfaces", - "remarks": "rule_set_129" + "remarks": "rule_set_144" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sysctl_net_ipv4_conf_default_accept_redirects", - "remarks": "rule_set_129" + "remarks": "rule_set_144" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 Interfaces", - "remarks": "rule_set_129" + "remarks": "rule_set_144" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_redirects", - "remarks": "rule_set_130" + "value": "sysctl_net_ipv4_conf_all_secure_redirects", + "remarks": "rule_set_145" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Accepting ICMP Redirects for All IPv6 Interfaces", - "remarks": "rule_set_130" + "value": "Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces", + "remarks": "rule_set_145" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_redirects", - "remarks": "rule_set_130" + "value": "sysctl_net_ipv4_conf_all_secure_redirects", + "remarks": "rule_set_145" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Accepting ICMP Redirects for All IPv6 Interfaces", - "remarks": "rule_set_130" + "value": "Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces", + "remarks": "rule_set_145" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_redirects", - "remarks": "rule_set_131" + "value": "sysctl_net_ipv4_conf_default_secure_redirects", + "remarks": "rule_set_146" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces", - "remarks": "rule_set_131" + "value": "Configure Kernel Parameter for Accepting Secure Redirects By Default", + "remarks": "rule_set_146" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_redirects", - "remarks": "rule_set_131" + "value": "sysctl_net_ipv4_conf_default_secure_redirects", + "remarks": "rule_set_146" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces", - "remarks": "rule_set_131" + "value": "Configure Kernel Parameter for Accepting Secure Redirects By Default", + "remarks": "rule_set_146" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_secure_redirects", - "remarks": "rule_set_132" + "value": "sysctl_net_ipv4_conf_all_rp_filter", + "remarks": "rule_set_147" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces", - "remarks": "rule_set_132" + "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces", + "remarks": "rule_set_147" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_secure_redirects", - "remarks": "rule_set_132" + "value": "sysctl_net_ipv4_conf_all_rp_filter", + "remarks": "rule_set_147" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces", - "remarks": "rule_set_132" + "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces", + "remarks": "rule_set_147" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_secure_redirects", - "remarks": "rule_set_133" + "value": "sysctl_net_ipv4_conf_default_rp_filter", + "remarks": "rule_set_148" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Kernel Parameter for Accepting Secure Redirects By Default", - "remarks": "rule_set_133" + "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces by Default", + "remarks": "rule_set_148" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_secure_redirects", - "remarks": "rule_set_133" + "value": "sysctl_net_ipv4_conf_default_rp_filter", + "remarks": "rule_set_148" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Kernel Parameter for Accepting Secure Redirects By Default", - "remarks": "rule_set_133" + "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces by Default", + "remarks": "rule_set_148" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_rp_filter", - "remarks": "rule_set_134" + "value": "sysctl_net_ipv4_conf_all_accept_source_route", + "remarks": "rule_set_149" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces", - "remarks": "rule_set_134" + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces", + "remarks": "rule_set_149" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_rp_filter", - "remarks": "rule_set_134" + "value": "sysctl_net_ipv4_conf_all_accept_source_route", + "remarks": "rule_set_149" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces", - "remarks": "rule_set_134" + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces", + "remarks": "rule_set_149" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_rp_filter", - "remarks": "rule_set_135" + "value": "sysctl_net_ipv4_conf_default_accept_source_route", + "remarks": "rule_set_150" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces by Default", - "remarks": "rule_set_135" + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces by Default", + "remarks": "rule_set_150" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_rp_filter", - "remarks": "rule_set_135" + "value": "sysctl_net_ipv4_conf_default_accept_source_route", + "remarks": "rule_set_150" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces by Default", - "remarks": "rule_set_135" + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces by Default", + "remarks": "rule_set_150" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_accept_source_route", - "remarks": "rule_set_136" + "value": "sysctl_net_ipv4_conf_all_log_martians", + "remarks": "rule_set_151" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces", - "remarks": "rule_set_136" + "value": "Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces", + "remarks": "rule_set_151" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_accept_source_route", - "remarks": "rule_set_136" + "value": "sysctl_net_ipv4_conf_all_log_martians", + "remarks": "rule_set_151" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces", - "remarks": "rule_set_136" + "value": "Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces", + "remarks": "rule_set_151" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_accept_source_route", - "remarks": "rule_set_137" + "value": "sysctl_net_ipv4_conf_default_log_martians", + "remarks": "rule_set_152" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces by Default", - "remarks": "rule_set_137" + "value": "Enable Kernel Paremeter to Log Martian Packets on all IPv4 Interfaces by Default", + "remarks": "rule_set_152" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_accept_source_route", - "remarks": "rule_set_137" + "value": "sysctl_net_ipv4_conf_default_log_martians", + "remarks": "rule_set_152" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces by Default", - "remarks": "rule_set_137" + "value": "Enable Kernel Paremeter to Log Martian Packets on all IPv4 Interfaces by Default", + "remarks": "rule_set_152" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_source_route", - "remarks": "rule_set_138" + "value": "sysctl_net_ipv4_tcp_syncookies", + "remarks": "rule_set_153" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces", - "remarks": "rule_set_138" + "value": "Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces", + "remarks": "rule_set_153" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_source_route", - "remarks": "rule_set_138" + "value": "sysctl_net_ipv4_tcp_syncookies", + "remarks": "rule_set_153" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces", - "remarks": "rule_set_138" + "value": "Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces", + "remarks": "rule_set_153" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_source_route", - "remarks": "rule_set_139" + "value": "sysctl_net_ipv6_conf_all_forwarding", + "remarks": "rule_set_154" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces by Default", - "remarks": "rule_set_139" + "value": "Disable Kernel Parameter for IPv6 Forwarding", + "remarks": "rule_set_154" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_source_route", - "remarks": "rule_set_139" + "value": "sysctl_net_ipv6_conf_all_forwarding", + "remarks": "rule_set_154" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces by Default", - "remarks": "rule_set_139" + "value": "Disable Kernel Parameter for IPv6 Forwarding", + "remarks": "rule_set_154" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_log_martians", - "remarks": "rule_set_140" + "value": "sysctl_net_ipv6_conf_default_forwarding", + "remarks": "rule_set_155" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces", - "remarks": "rule_set_140" + "value": "Disable Kernel Parameter for IPv6 Forwarding by default", + "remarks": "rule_set_155" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_log_martians", - "remarks": "rule_set_140" + "value": "sysctl_net_ipv6_conf_default_forwarding", + "remarks": "rule_set_155" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces", - "remarks": "rule_set_140" + "value": "Disable Kernel Parameter for IPv6 Forwarding by default", + "remarks": "rule_set_155" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_log_martians", - "remarks": "rule_set_141" + "value": "sysctl_net_ipv6_conf_all_accept_redirects", + "remarks": "rule_set_156" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Paremeter to Log Martian Packets on all IPv4 Interfaces by Default", - "remarks": "rule_set_141" + "value": "Disable Accepting ICMP Redirects for All IPv6 Interfaces", + "remarks": "rule_set_156" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_log_martians", - "remarks": "rule_set_141" + "value": "sysctl_net_ipv6_conf_all_accept_redirects", + "remarks": "rule_set_156" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Paremeter to Log Martian Packets on all IPv4 Interfaces by Default", - "remarks": "rule_set_141" + "value": "Disable Accepting ICMP Redirects for All IPv6 Interfaces", + "remarks": "rule_set_156" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_tcp_syncookies", - "remarks": "rule_set_142" + "value": "sysctl_net_ipv6_conf_default_accept_redirects", + "remarks": "rule_set_157" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces", - "remarks": "rule_set_142" + "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces", + "remarks": "rule_set_157" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_tcp_syncookies", - "remarks": "rule_set_142" + "value": "sysctl_net_ipv6_conf_default_accept_redirects", + "remarks": "rule_set_157" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces", - "remarks": "rule_set_142" + "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces", + "remarks": "rule_set_157" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_ra", - "remarks": "rule_set_143" + "value": "sysctl_net_ipv6_conf_all_accept_source_route", + "remarks": "rule_set_158" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Accepting Router Advertisements on All IPv6 Interfaces", - "remarks": "rule_set_143" + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces", + "remarks": "rule_set_158" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_ra", - "remarks": "rule_set_143" + "value": "sysctl_net_ipv6_conf_all_accept_source_route", + "remarks": "rule_set_158" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Accepting Router Advertisements on All IPv6 Interfaces", - "remarks": "rule_set_143" + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces", + "remarks": "rule_set_158" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_ra", - "remarks": "rule_set_144" + "value": "sysctl_net_ipv6_conf_default_accept_source_route", + "remarks": "rule_set_159" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Accepting Router Advertisements on all IPv6 Interfaces by Default", - "remarks": "rule_set_144" + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces by Default", + "remarks": "rule_set_159" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_ra", - "remarks": "rule_set_144" + "value": "sysctl_net_ipv6_conf_default_accept_source_route", + "remarks": "rule_set_159" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Accepting Router Advertisements on all IPv6 Interfaces by Default", - "remarks": "rule_set_144" + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces by Default", + "remarks": "rule_set_159" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_nftables_installed", - "remarks": "rule_set_145" + "value": "sysctl_net_ipv6_conf_all_accept_ra", + "remarks": "rule_set_160" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install nftables Package", - "remarks": "rule_set_145" + "value": "Configure Accepting Router Advertisements on All IPv6 Interfaces", + "remarks": "rule_set_160" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_nftables_installed", - "remarks": "rule_set_145" + "value": "sysctl_net_ipv6_conf_all_accept_ra", + "remarks": "rule_set_160" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install nftables Package", - "remarks": "rule_set_145" + "value": "Configure Accepting Router Advertisements on All IPv6 Interfaces", + "remarks": "rule_set_160" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_firewalld_enabled", - "remarks": "rule_set_146" + "value": "sysctl_net_ipv6_conf_default_accept_ra", + "remarks": "rule_set_161" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify firewalld Enabled", - "remarks": "rule_set_146" + "value": "Disable Accepting Router Advertisements on all IPv6 Interfaces by Default", + "remarks": "rule_set_161" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_firewalld_enabled", - "remarks": "rule_set_146" + "value": "sysctl_net_ipv6_conf_default_accept_ra", + "remarks": "rule_set_161" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify firewalld Enabled", - "remarks": "rule_set_146" + "value": "Disable Accepting Router Advertisements on all IPv6 Interfaces by Default", + "remarks": "rule_set_161" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_firewalld_installed", - "remarks": "rule_set_147" + "remarks": "rule_set_162" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Install firewalld Package", - "remarks": "rule_set_147" + "remarks": "rule_set_162" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_firewalld_installed", - "remarks": "rule_set_147" + "remarks": "rule_set_162" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Install firewalld Package", - "remarks": "rule_set_147" + "remarks": "rule_set_162" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_nftables_disabled", - "remarks": "rule_set_148" + "value": "service_firewalld_enabled", + "remarks": "rule_set_163" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify nftables Service is Disabled", - "remarks": "rule_set_148" + "value": "Verify firewalld Enabled", + "remarks": "rule_set_163" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_nftables_disabled", - "remarks": "rule_set_148" + "value": "service_firewalld_enabled", + "remarks": "rule_set_163" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify nftables Service is Disabled", - "remarks": "rule_set_148" + "value": "Verify firewalld Enabled", + "remarks": "rule_set_163" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "firewalld_loopback_traffic_trusted", - "remarks": "rule_set_149" + "remarks": "rule_set_164" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure Firewalld to Trust Loopback Traffic", - "remarks": "rule_set_149" + "remarks": "rule_set_164" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "firewalld_loopback_traffic_trusted", - "remarks": "rule_set_149" + "remarks": "rule_set_164" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure Firewalld to Trust Loopback Traffic", - "remarks": "rule_set_149" + "remarks": "rule_set_164" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "firewalld_loopback_traffic_restricted", - "remarks": "rule_set_150" + "remarks": "rule_set_165" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure Firewalld to Restrict Loopback Traffic", - "remarks": "rule_set_150" + "remarks": "rule_set_165" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "firewalld_loopback_traffic_restricted", - "remarks": "rule_set_150" + "remarks": "rule_set_165" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure Firewalld to Restrict Loopback Traffic", - "remarks": "rule_set_150" + "remarks": "rule_set_165" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_sshd_config", - "remarks": "rule_set_151" + "remarks": "rule_set_166" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns SSH Server config file", - "remarks": "rule_set_151" + "remarks": "rule_set_166" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_sshd_config", - "remarks": "rule_set_151" + "remarks": "rule_set_166" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns SSH Server config file", - "remarks": "rule_set_151" + "remarks": "rule_set_166" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_sshd_config", - "remarks": "rule_set_152" + "remarks": "rule_set_167" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on SSH Server config file", - "remarks": "rule_set_152" + "remarks": "rule_set_167" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_sshd_config", - "remarks": "rule_set_152" + "remarks": "rule_set_167" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Owner on SSH Server config file", - "remarks": "rule_set_152" + "remarks": "rule_set_167" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_sshd_config", - "remarks": "rule_set_153" + "remarks": "rule_set_168" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on SSH Server config file", - "remarks": "rule_set_153" + "remarks": "rule_set_168" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_sshd_config", - "remarks": "rule_set_153" + "remarks": "rule_set_168" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on SSH Server config file", - "remarks": "rule_set_153" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_private_key", - "remarks": "rule_set_154" - }, - { - "name": "Rule_Description", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on SSH Server Private *_key Key Files", - "remarks": "rule_set_154" - }, - { - "name": "Check_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_private_key", - "remarks": "rule_set_154" - }, - { - "name": "Check_Description", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on SSH Server Private *_key Key Files", - "remarks": "rule_set_154" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_private_key", - "remarks": "rule_set_155" - }, - { - "name": "Rule_Description", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Ownership on SSH Server Private *_key Key Files", - "remarks": "rule_set_155" - }, - { - "name": "Check_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_private_key", - "remarks": "rule_set_155" - }, - { - "name": "Check_Description", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Ownership on SSH Server Private *_key Key Files", - "remarks": "rule_set_155" + "remarks": "rule_set_168" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupownership_sshd_private_key", - "remarks": "rule_set_156" + "remarks": "rule_set_169" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Ownership on SSH Server Private *_key Key Files", - "remarks": "rule_set_156" + "remarks": "rule_set_169" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupownership_sshd_private_key", - "remarks": "rule_set_156" + "remarks": "rule_set_169" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Ownership on SSH Server Private *_key Key Files", - "remarks": "rule_set_156" + "remarks": "rule_set_169" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_pub_key", - "remarks": "rule_set_157" + "value": "file_ownership_sshd_private_key", + "remarks": "rule_set_170" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on SSH Server Public *.pub Key Files", - "remarks": "rule_set_157" + "value": "Verify Ownership on SSH Server Private *_key Key Files", + "remarks": "rule_set_170" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_pub_key", - "remarks": "rule_set_157" + "value": "file_ownership_sshd_private_key", + "remarks": "rule_set_170" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on SSH Server Public *.pub Key Files", - "remarks": "rule_set_157" + "value": "Verify Ownership on SSH Server Private *_key Key Files", + "remarks": "rule_set_170" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_pub_key", - "remarks": "rule_set_158" + "value": "file_permissions_sshd_private_key", + "remarks": "rule_set_171" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Ownership on SSH Server Public *.pub Key Files", - "remarks": "rule_set_158" + "value": "Verify Permissions on SSH Server Private *_key Key Files", + "remarks": "rule_set_171" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_pub_key", - "remarks": "rule_set_158" + "value": "file_permissions_sshd_private_key", + "remarks": "rule_set_171" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Ownership on SSH Server Public *.pub Key Files", - "remarks": "rule_set_158" + "value": "Verify Permissions on SSH Server Private *_key Key Files", + "remarks": "rule_set_171" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupownership_sshd_pub_key", - "remarks": "rule_set_159" + "remarks": "rule_set_172" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Ownership on SSH Server Public *.pub Key Files", - "remarks": "rule_set_159" + "remarks": "rule_set_172" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupownership_sshd_pub_key", - "remarks": "rule_set_159" + "remarks": "rule_set_172" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Ownership on SSH Server Public *.pub Key Files", - "remarks": "rule_set_159" + "remarks": "rule_set_172" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_kex", - "remarks": "rule_set_160" + "value": "file_ownership_sshd_pub_key", + "remarks": "rule_set_173" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Use Only Strong Key Exchange algorithms", - "remarks": "rule_set_160" + "value": "Verify Ownership on SSH Server Public *.pub Key Files", + "remarks": "rule_set_173" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_kex", - "remarks": "rule_set_160" + "value": "file_ownership_sshd_pub_key", + "remarks": "rule_set_173" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Use Only Strong Key Exchange algorithms", - "remarks": "rule_set_160" + "value": "Verify Ownership on SSH Server Public *.pub Key Files", + "remarks": "rule_set_173" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_macs", - "remarks": "rule_set_161" + "value": "file_permissions_sshd_pub_key", + "remarks": "rule_set_174" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Use Only Strong MACs", - "remarks": "rule_set_161" + "value": "Verify Permissions on SSH Server Public *.pub Key Files", + "remarks": "rule_set_174" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_macs", - "remarks": "rule_set_161" + "value": "file_permissions_sshd_pub_key", + "remarks": "rule_set_174" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Use Only Strong MACs", - "remarks": "rule_set_161" + "value": "Verify Permissions on SSH Server Public *.pub Key Files", + "remarks": "rule_set_174" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_limit_user_access", - "remarks": "rule_set_162" + "remarks": "rule_set_175" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Limit Users' SSH Access", - "remarks": "rule_set_162" + "remarks": "rule_set_175" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_limit_user_access", - "remarks": "rule_set_162" + "remarks": "rule_set_175" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Limit Users' SSH Access", - "remarks": "rule_set_162" + "remarks": "rule_set_175" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_enable_warning_banner_net", - "remarks": "rule_set_163" + "remarks": "rule_set_176" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable SSH Warning Banner", - "remarks": "rule_set_163" + "remarks": "rule_set_176" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_enable_warning_banner_net", - "remarks": "rule_set_163" + "remarks": "rule_set_176" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable SSH Warning Banner", - "remarks": "rule_set_163" + "remarks": "rule_set_176" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_idle_timeout", - "remarks": "rule_set_164" + "remarks": "rule_set_177" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set SSH Client Alive Interval", - "remarks": "rule_set_164" + "remarks": "rule_set_177" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_idle_timeout", - "remarks": "rule_set_164" + "remarks": "rule_set_177" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set SSH Client Alive Interval", - "remarks": "rule_set_164" + "remarks": "rule_set_177" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_keepalive", - "remarks": "rule_set_165" + "remarks": "rule_set_178" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set SSH Client Alive Count Max", - "remarks": "rule_set_165" + "remarks": "rule_set_178" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_keepalive", - "remarks": "rule_set_165" + "remarks": "rule_set_178" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set SSH Client Alive Count Max", - "remarks": "rule_set_165" + "remarks": "rule_set_178" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "disable_host_auth", - "remarks": "rule_set_166" + "remarks": "rule_set_179" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Host-Based Authentication", - "remarks": "rule_set_166" + "remarks": "rule_set_179" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "disable_host_auth", - "remarks": "rule_set_166" + "remarks": "rule_set_179" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Host-Based Authentication", - "remarks": "rule_set_166" + "remarks": "rule_set_179" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_disable_rhosts", - "remarks": "rule_set_167" + "remarks": "rule_set_180" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable SSH Support for .rhosts Files", - "remarks": "rule_set_167" + "remarks": "rule_set_180" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_disable_rhosts", - "remarks": "rule_set_167" + "remarks": "rule_set_180" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable SSH Support for .rhosts Files", - "remarks": "rule_set_167" + "remarks": "rule_set_180" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_use_strong_kex", + "remarks": "rule_set_181" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Use Only Strong Key Exchange algorithms", + "remarks": "rule_set_181" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_use_strong_kex", + "remarks": "rule_set_181" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Use Only Strong Key Exchange algorithms", + "remarks": "rule_set_181" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_login_grace_time", - "remarks": "rule_set_168" + "remarks": "rule_set_182" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure SSH LoginGraceTime is configured", - "remarks": "rule_set_168" + "remarks": "rule_set_182" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_login_grace_time", - "remarks": "rule_set_168" + "remarks": "rule_set_182" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure SSH LoginGraceTime is configured", - "remarks": "rule_set_168" + "remarks": "rule_set_182" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_loglevel_verbose", - "remarks": "rule_set_169" + "remarks": "rule_set_183" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set SSH Daemon LogLevel to VERBOSE", - "remarks": "rule_set_169" + "remarks": "rule_set_183" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_loglevel_verbose", - "remarks": "rule_set_169" + "remarks": "rule_set_183" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set SSH Daemon LogLevel to VERBOSE", - "remarks": "rule_set_169" + "remarks": "rule_set_183" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_use_strong_macs", + "remarks": "rule_set_184" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Use Only Strong MACs", + "remarks": "rule_set_184" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_use_strong_macs", + "remarks": "rule_set_184" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Use Only Strong MACs", + "remarks": "rule_set_184" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_max_auth_tries", - "remarks": "rule_set_170" + "remarks": "rule_set_185" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set SSH authentication attempt limit", - "remarks": "rule_set_170" + "remarks": "rule_set_185" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_max_auth_tries", - "remarks": "rule_set_170" + "remarks": "rule_set_185" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set SSH authentication attempt limit", - "remarks": "rule_set_170" + "remarks": "rule_set_185" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_maxstartups", - "remarks": "rule_set_171" + "remarks": "rule_set_186" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure SSH MaxStartups is configured", - "remarks": "rule_set_171" + "remarks": "rule_set_186" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_maxstartups", - "remarks": "rule_set_171" + "remarks": "rule_set_186" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure SSH MaxStartups is configured", - "remarks": "rule_set_171" + "remarks": "rule_set_186" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_max_sessions", - "remarks": "rule_set_172" + "remarks": "rule_set_187" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set SSH MaxSessions limit", - "remarks": "rule_set_172" + "remarks": "rule_set_187" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_set_max_sessions", - "remarks": "rule_set_172" + "remarks": "rule_set_187" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set SSH MaxSessions limit", - "remarks": "rule_set_172" + "remarks": "rule_set_187" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_disable_empty_passwords", - "remarks": "rule_set_173" + "remarks": "rule_set_188" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable SSH Access via Empty Passwords", - "remarks": "rule_set_173" + "remarks": "rule_set_188" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_disable_empty_passwords", - "remarks": "rule_set_173" + "remarks": "rule_set_188" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable SSH Access via Empty Passwords", - "remarks": "rule_set_173" + "remarks": "rule_set_188" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_disable_root_login", - "remarks": "rule_set_174" + "remarks": "rule_set_189" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable SSH Root Login", - "remarks": "rule_set_174" + "remarks": "rule_set_189" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_disable_root_login", - "remarks": "rule_set_174" + "remarks": "rule_set_189" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable SSH Root Login", - "remarks": "rule_set_174" + "remarks": "rule_set_189" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_do_not_permit_user_env", - "remarks": "rule_set_175" + "remarks": "rule_set_190" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Do Not Allow SSH Environment Options", - "remarks": "rule_set_175" + "remarks": "rule_set_190" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_do_not_permit_user_env", - "remarks": "rule_set_175" + "remarks": "rule_set_190" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Do Not Allow SSH Environment Options", - "remarks": "rule_set_175" + "remarks": "rule_set_190" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_enable_pam", - "remarks": "rule_set_176" + "remarks": "rule_set_191" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable PAM", - "remarks": "rule_set_176" + "remarks": "rule_set_191" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sshd_enable_pam", - "remarks": "rule_set_176" + "remarks": "rule_set_191" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable PAM", - "remarks": "rule_set_176" + "remarks": "rule_set_191" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_sudo_installed", - "remarks": "rule_set_177" + "remarks": "rule_set_192" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Install sudo Package", - "remarks": "rule_set_177" + "remarks": "rule_set_192" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_sudo_installed", - "remarks": "rule_set_177" + "remarks": "rule_set_192" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Install sudo Package", - "remarks": "rule_set_177" + "remarks": "rule_set_192" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sudo_add_use_pty", - "remarks": "rule_set_178" + "remarks": "rule_set_193" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Only Users Logged In To Real tty Can Execute Sudo - sudo use_pty", - "remarks": "rule_set_178" + "remarks": "rule_set_193" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sudo_add_use_pty", - "remarks": "rule_set_178" + "remarks": "rule_set_193" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Only Users Logged In To Real tty Can Execute Sudo - sudo use_pty", - "remarks": "rule_set_178" + "remarks": "rule_set_193" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sudo_custom_logfile", - "remarks": "rule_set_179" + "remarks": "rule_set_194" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Sudo Logfile Exists - sudo logfile", - "remarks": "rule_set_179" + "remarks": "rule_set_194" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sudo_custom_logfile", - "remarks": "rule_set_179" + "remarks": "rule_set_194" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Sudo Logfile Exists - sudo logfile", - "remarks": "rule_set_179" + "remarks": "rule_set_194" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sudo_require_authentication", + "remarks": "rule_set_195" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure Users Re-Authenticate for Privilege Escalation - sudo", + "remarks": "rule_set_195" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sudo_require_authentication", + "remarks": "rule_set_195" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure Users Re-Authenticate for Privilege Escalation - sudo", + "remarks": "rule_set_195" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sudo_require_reauthentication", - "remarks": "rule_set_180" + "remarks": "rule_set_196" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Require Re-Authentication When Using the sudo Command", - "remarks": "rule_set_180" + "remarks": "rule_set_196" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "sudo_require_reauthentication", - "remarks": "rule_set_180" + "remarks": "rule_set_196" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Require Re-Authentication When Using the sudo Command", - "remarks": "rule_set_180" + "remarks": "rule_set_196" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "use_pam_wheel_group_for_su", - "remarks": "rule_set_181" + "remarks": "rule_set_197" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enforce Usage of pam_wheel with Group Parameter for su Authentication", - "remarks": "rule_set_181" + "remarks": "rule_set_197" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "use_pam_wheel_group_for_su", - "remarks": "rule_set_181" + "remarks": "rule_set_197" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enforce Usage of pam_wheel with Group Parameter for su Authentication", - "remarks": "rule_set_181" + "remarks": "rule_set_197" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "ensure_pam_wheel_group_empty", - "remarks": "rule_set_182" + "remarks": "rule_set_198" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure the Group Used by pam_wheel.so Module Exists on System and is Empty", - "remarks": "rule_set_182" + "remarks": "rule_set_198" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "ensure_pam_wheel_group_empty", - "remarks": "rule_set_182" + "remarks": "rule_set_198" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure the Group Used by pam_wheel.so Module Exists on System and is Empty", - "remarks": "rule_set_182" + "remarks": "rule_set_198" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_pam_pwquality_installed", - "remarks": "rule_set_183" + "value": "account_password_pam_faillock_password_auth", + "remarks": "rule_set_199" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install pam_pwquality Package", - "remarks": "rule_set_183" + "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth File.", + "remarks": "rule_set_199" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_pam_pwquality_installed", - "remarks": "rule_set_183" + "value": "account_password_pam_faillock_password_auth", + "remarks": "rule_set_199" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install pam_pwquality Package", - "remarks": "rule_set_183" + "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth File.", + "remarks": "rule_set_199" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_password_auth", - "remarks": "rule_set_184" + "value": "account_password_pam_faillock_system_auth", + "remarks": "rule_set_200" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth File.", - "remarks": "rule_set_184" + "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth File.", + "remarks": "rule_set_200" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_password_auth", - "remarks": "rule_set_184" + "value": "account_password_pam_faillock_system_auth", + "remarks": "rule_set_200" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth File.", - "remarks": "rule_set_184" + "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth File.", + "remarks": "rule_set_200" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_system_auth", - "remarks": "rule_set_185" + "value": "package_pam_pwquality_installed", + "remarks": "rule_set_201" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth File.", - "remarks": "rule_set_185" + "value": "Install pam_pwquality Package", + "remarks": "rule_set_201" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_system_auth", - "remarks": "rule_set_185" + "value": "package_pam_pwquality_installed", + "remarks": "rule_set_201" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth File.", - "remarks": "rule_set_185" + "value": "Install pam_pwquality Package", + "remarks": "rule_set_201" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_passwords_pam_faillock_deny", - "remarks": "rule_set_186" + "remarks": "rule_set_202" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Lock Accounts After Failed Password Attempts", - "remarks": "rule_set_186" + "remarks": "rule_set_202" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_passwords_pam_faillock_deny", - "remarks": "rule_set_186" + "remarks": "rule_set_202" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Lock Accounts After Failed Password Attempts", - "remarks": "rule_set_186" + "remarks": "rule_set_202" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_passwords_pam_faillock_unlock_time", - "remarks": "rule_set_187" + "remarks": "rule_set_203" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Lockout Time for Failed Password Attempts", - "remarks": "rule_set_187" + "remarks": "rule_set_203" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_passwords_pam_faillock_unlock_time", - "remarks": "rule_set_187" + "remarks": "rule_set_203" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Lockout Time for Failed Password Attempts", - "remarks": "rule_set_187" + "remarks": "rule_set_203" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_difok", - "remarks": "rule_set_188" + "remarks": "rule_set_204" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure PAM Enforces Password Requirements - Minimum Different Characters", - "remarks": "rule_set_188" + "remarks": "rule_set_204" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_difok", - "remarks": "rule_set_188" + "remarks": "rule_set_204" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure PAM Enforces Password Requirements - Minimum Different Characters", - "remarks": "rule_set_188" + "remarks": "rule_set_204" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_minlen", - "remarks": "rule_set_189" + "remarks": "rule_set_205" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure PAM Enforces Password Requirements - Minimum Length", - "remarks": "rule_set_189" + "remarks": "rule_set_205" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_minlen", - "remarks": "rule_set_189" + "remarks": "rule_set_205" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure PAM Enforces Password Requirements - Minimum Length", - "remarks": "rule_set_189" + "remarks": "rule_set_205" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_minclass", - "remarks": "rule_set_190" + "remarks": "rule_set_206" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure PAM Enforces Password Requirements - Minimum Different Categories", - "remarks": "rule_set_190" + "remarks": "rule_set_206" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_minclass", - "remarks": "rule_set_190" + "remarks": "rule_set_206" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure PAM Enforces Password Requirements - Minimum Different Categories", - "remarks": "rule_set_190" + "remarks": "rule_set_206" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_maxrepeat", - "remarks": "rule_set_191" + "remarks": "rule_set_207" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Password Maximum Consecutive Repeating Characters", - "remarks": "rule_set_191" + "remarks": "rule_set_207" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_maxrepeat", - "remarks": "rule_set_191" + "remarks": "rule_set_207" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Password Maximum Consecutive Repeating Characters", - "remarks": "rule_set_191" + "remarks": "rule_set_207" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_dictcheck", - "remarks": "rule_set_192" + "remarks": "rule_set_208" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure PAM Enforces Password Requirements - Prevent the Use of Dictionary Words", - "remarks": "rule_set_192" + "remarks": "rule_set_208" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_dictcheck", - "remarks": "rule_set_192" + "remarks": "rule_set_208" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure PAM Enforces Password Requirements - Prevent the Use of Dictionary Words", - "remarks": "rule_set_192" + "remarks": "rule_set_208" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_enforce_root", - "remarks": "rule_set_193" + "remarks": "rule_set_209" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure PAM Enforces Password Requirements - Enforce for root User", - "remarks": "rule_set_193" + "remarks": "rule_set_209" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_enforce_root", - "remarks": "rule_set_193" + "remarks": "rule_set_209" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure PAM Enforces Password Requirements - Enforce for root User", - "remarks": "rule_set_193" + "remarks": "rule_set_209" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_pwhistory_remember_password_auth", - "remarks": "rule_set_194" + "remarks": "rule_set_210" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Limit Password Reuse: password-auth", - "remarks": "rule_set_194" + "remarks": "rule_set_210" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_pwhistory_remember_password_auth", - "remarks": "rule_set_194" + "remarks": "rule_set_210" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Limit Password Reuse: password-auth", - "remarks": "rule_set_194" + "remarks": "rule_set_210" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_pwhistory_remember_system_auth", - "remarks": "rule_set_195" + "remarks": "rule_set_211" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Limit Password Reuse: system-auth", - "remarks": "rule_set_195" + "remarks": "rule_set_211" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_pam_pwhistory_remember_system_auth", - "remarks": "rule_set_195" + "remarks": "rule_set_211" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Limit Password Reuse: system-auth", - "remarks": "rule_set_195" + "remarks": "rule_set_211" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_empty_passwords", - "remarks": "rule_set_196" + "remarks": "rule_set_212" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Prevent Login to Accounts With Empty Password", - "remarks": "rule_set_196" + "remarks": "rule_set_212" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_empty_passwords", - "remarks": "rule_set_196" + "remarks": "rule_set_212" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Prevent Login to Accounts With Empty Password", - "remarks": "rule_set_196" + "remarks": "rule_set_212" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "set_password_hashing_algorithm_systemauth", - "remarks": "rule_set_197" + "remarks": "rule_set_213" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set PAM''s Password Hashing Algorithm", - "remarks": "rule_set_197" + "remarks": "rule_set_213" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "set_password_hashing_algorithm_systemauth", - "remarks": "rule_set_197" + "remarks": "rule_set_213" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set PAM''s Password Hashing Algorithm", - "remarks": "rule_set_197" + "remarks": "rule_set_213" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "set_password_hashing_algorithm_passwordauth", - "remarks": "rule_set_198" + "remarks": "rule_set_214" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set PAM''s Password Hashing Algorithm - password-auth", - "remarks": "rule_set_198" + "remarks": "rule_set_214" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "set_password_hashing_algorithm_passwordauth", - "remarks": "rule_set_198" + "remarks": "rule_set_214" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set PAM''s Password Hashing Algorithm - password-auth", - "remarks": "rule_set_198" + "remarks": "rule_set_214" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_maximum_age_login_defs", - "remarks": "rule_set_199" + "remarks": "rule_set_215" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Password Maximum Age", - "remarks": "rule_set_199" + "remarks": "rule_set_215" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_maximum_age_login_defs", - "remarks": "rule_set_199" + "remarks": "rule_set_215" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Password Maximum Age", - "remarks": "rule_set_199" + "remarks": "rule_set_215" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_set_max_life_existing", - "remarks": "rule_set_200" + "remarks": "rule_set_216" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Existing Passwords Maximum Age", - "remarks": "rule_set_200" + "remarks": "rule_set_216" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_set_max_life_existing", - "remarks": "rule_set_200" + "remarks": "rule_set_216" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Existing Passwords Maximum Age", - "remarks": "rule_set_200" + "remarks": "rule_set_216" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_warn_age_login_defs", - "remarks": "rule_set_201" + "remarks": "rule_set_217" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Password Warning Age", - "remarks": "rule_set_201" + "remarks": "rule_set_217" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_warn_age_login_defs", - "remarks": "rule_set_201" + "remarks": "rule_set_217" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Password Warning Age", - "remarks": "rule_set_201" + "remarks": "rule_set_217" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_set_warn_age_existing", - "remarks": "rule_set_202" + "remarks": "rule_set_218" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Existing Passwords Warning Age", - "remarks": "rule_set_202" + "remarks": "rule_set_218" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_set_warn_age_existing", - "remarks": "rule_set_202" + "remarks": "rule_set_218" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Existing Passwords Warning Age", - "remarks": "rule_set_202" + "remarks": "rule_set_218" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "set_password_hashing_algorithm_libuserconf", - "remarks": "rule_set_203" + "remarks": "rule_set_219" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Password Hashing Algorithm in /etc/libuser.conf", - "remarks": "rule_set_203" + "remarks": "rule_set_219" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "set_password_hashing_algorithm_libuserconf", - "remarks": "rule_set_203" + "remarks": "rule_set_219" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Password Hashing Algorithm in /etc/libuser.conf", - "remarks": "rule_set_203" + "remarks": "rule_set_219" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "set_password_hashing_algorithm_logindefs", - "remarks": "rule_set_204" + "remarks": "rule_set_220" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Password Hashing Algorithm in /etc/login.defs", - "remarks": "rule_set_204" + "remarks": "rule_set_220" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "set_password_hashing_algorithm_logindefs", - "remarks": "rule_set_204" + "remarks": "rule_set_220" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Password Hashing Algorithm in /etc/login.defs", - "remarks": "rule_set_204" + "remarks": "rule_set_220" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "account_disable_post_pw_expiration", - "remarks": "rule_set_205" + "remarks": "rule_set_221" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Account Expiration Following Inactivity", - "remarks": "rule_set_205" + "remarks": "rule_set_221" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "account_disable_post_pw_expiration", - "remarks": "rule_set_205" + "remarks": "rule_set_221" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Account Expiration Following Inactivity", - "remarks": "rule_set_205" + "remarks": "rule_set_221" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_set_post_pw_existing", - "remarks": "rule_set_206" + "remarks": "rule_set_222" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set existing passwords a period of inactivity before they been locked", - "remarks": "rule_set_206" + "remarks": "rule_set_222" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_set_post_pw_existing", - "remarks": "rule_set_206" + "remarks": "rule_set_222" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set existing passwords a period of inactivity before they been locked", - "remarks": "rule_set_206" + "remarks": "rule_set_222" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_last_change_is_in_past", - "remarks": "rule_set_207" + "remarks": "rule_set_223" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure all users last password change date is in the past", - "remarks": "rule_set_207" + "remarks": "rule_set_223" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_last_change_is_in_past", - "remarks": "rule_set_207" + "remarks": "rule_set_223" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure all users last password change date is in the past", - "remarks": "rule_set_207" + "remarks": "rule_set_223" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_no_uid_except_zero", - "remarks": "rule_set_208" + "remarks": "rule_set_224" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Only Root Has UID 0", - "remarks": "rule_set_208" + "remarks": "rule_set_224" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_no_uid_except_zero", - "remarks": "rule_set_208" + "remarks": "rule_set_224" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Only Root Has UID 0", - "remarks": "rule_set_208" + "remarks": "rule_set_224" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_root_gid_zero", - "remarks": "rule_set_209" + "remarks": "rule_set_225" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Root Has A Primary GID 0", - "remarks": "rule_set_209" + "remarks": "rule_set_225" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_root_gid_zero", - "remarks": "rule_set_209" + "remarks": "rule_set_225" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Root Has A Primary GID 0", - "remarks": "rule_set_209" + "remarks": "rule_set_225" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "groups_no_zero_gid_except_root", + "remarks": "rule_set_226" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify Only Group Root Has GID 0", + "remarks": "rule_set_226" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "groups_no_zero_gid_except_root", + "remarks": "rule_set_226" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify Only Group Root Has GID 0", + "remarks": "rule_set_226" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "ensure_root_password_configured", - "remarks": "rule_set_210" + "remarks": "rule_set_227" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Authentication Required for Single User Mode", - "remarks": "rule_set_210" + "remarks": "rule_set_227" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "ensure_root_password_configured", - "remarks": "rule_set_210" + "remarks": "rule_set_227" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Authentication Required for Single User Mode", - "remarks": "rule_set_210" + "remarks": "rule_set_227" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_root_path_dirs_no_write", - "remarks": "rule_set_211" + "remarks": "rule_set_228" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that Root's Path Does Not Include World or Group-Writable Directories", - "remarks": "rule_set_211" + "remarks": "rule_set_228" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_root_path_dirs_no_write", - "remarks": "rule_set_211" + "remarks": "rule_set_228" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure that Root's Path Does Not Include World or Group-Writable Directories", + "remarks": "rule_set_228" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "root_path_no_dot", + "remarks": "rule_set_229" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure that Root's Path Does Not Include Relative Paths or Null Directories", + "remarks": "rule_set_229" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "root_path_no_dot", + "remarks": "rule_set_229" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that Root's Path Does Not Include World or Group-Writable Directories", - "remarks": "rule_set_211" + "value": "Ensure that Root's Path Does Not Include Relative Paths or Null Directories", + "remarks": "rule_set_229" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "root_path_no_dot", - "remarks": "rule_set_212" + "value": "accounts_umask_root", + "remarks": "rule_set_230" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that Root's Path Does Not Include Relative Paths or Null Directories", - "remarks": "rule_set_212" + "value": "Ensure the Root Bash Umask is Set Correctly", + "remarks": "rule_set_230" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "root_path_no_dot", - "remarks": "rule_set_212" + "value": "accounts_umask_root", + "remarks": "rule_set_230" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that Root's Path Does Not Include Relative Paths or Null Directories", - "remarks": "rule_set_212" + "value": "Ensure the Root Bash Umask is Set Correctly", + "remarks": "rule_set_230" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_password_auth_for_systemaccounts", - "remarks": "rule_set_213" + "remarks": "rule_set_231" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that System Accounts Are Locked", - "remarks": "rule_set_213" + "remarks": "rule_set_231" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_password_auth_for_systemaccounts", - "remarks": "rule_set_213" + "remarks": "rule_set_231" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that System Accounts Are Locked", - "remarks": "rule_set_213" + "remarks": "rule_set_231" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_shelllogin_for_systemaccounts", - "remarks": "rule_set_214" + "remarks": "rule_set_232" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that System Accounts Do Not Run a Shell Upon Login", - "remarks": "rule_set_214" + "remarks": "rule_set_232" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_shelllogin_for_systemaccounts", - "remarks": "rule_set_214" + "remarks": "rule_set_232" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure that System Accounts Do Not Run a Shell Upon Login", - "remarks": "rule_set_214" + "remarks": "rule_set_232" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_tmout", - "remarks": "rule_set_215" + "remarks": "rule_set_233" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Interactive Session Timeout", - "remarks": "rule_set_215" + "remarks": "rule_set_233" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_tmout", - "remarks": "rule_set_215" + "remarks": "rule_set_233" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Interactive Session Timeout", - "remarks": "rule_set_215" + "remarks": "rule_set_233" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_umask_etc_bashrc", - "remarks": "rule_set_216" + "remarks": "rule_set_234" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure the Default Bash Umask is Set Correctly", - "remarks": "rule_set_216" + "remarks": "rule_set_234" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_umask_etc_bashrc", - "remarks": "rule_set_216" + "remarks": "rule_set_234" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure the Default Bash Umask is Set Correctly", - "remarks": "rule_set_216" + "remarks": "rule_set_234" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_umask_etc_login_defs", - "remarks": "rule_set_217" + "remarks": "rule_set_235" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure the Default Umask is Set Correctly in login.defs", - "remarks": "rule_set_217" + "remarks": "rule_set_235" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_umask_etc_login_defs", - "remarks": "rule_set_217" + "remarks": "rule_set_235" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure the Default Umask is Set Correctly in login.defs", - "remarks": "rule_set_217" + "remarks": "rule_set_235" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_umask_etc_profile", - "remarks": "rule_set_218" + "remarks": "rule_set_236" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure the Default Umask is Set Correctly in /etc/profile", - "remarks": "rule_set_218" + "remarks": "rule_set_236" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_umask_etc_profile", - "remarks": "rule_set_218" + "remarks": "rule_set_236" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure the Default Umask is Set Correctly in /etc/profile", - "remarks": "rule_set_218" + "remarks": "rule_set_236" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_aide_installed", - "remarks": "rule_set_219" + "remarks": "rule_set_237" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Install AIDE", - "remarks": "rule_set_219" + "remarks": "rule_set_237" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_aide_installed", - "remarks": "rule_set_219" + "remarks": "rule_set_237" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Install AIDE", - "remarks": "rule_set_219" + "remarks": "rule_set_237" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "aide_build_database", - "remarks": "rule_set_220" + "remarks": "rule_set_238" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Build and Test AIDE Database", - "remarks": "rule_set_220" + "remarks": "rule_set_238" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "aide_build_database", - "remarks": "rule_set_220" + "remarks": "rule_set_238" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Build and Test AIDE Database", - "remarks": "rule_set_220" + "remarks": "rule_set_238" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "aide_periodic_cron_checking", - "remarks": "rule_set_221" + "remarks": "rule_set_239" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure Periodic Execution of AIDE", - "remarks": "rule_set_221" + "remarks": "rule_set_239" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "aide_periodic_cron_checking", - "remarks": "rule_set_221" + "remarks": "rule_set_239" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure Periodic Execution of AIDE", - "remarks": "rule_set_221" + "remarks": "rule_set_239" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "aide_check_audit_tools", - "remarks": "rule_set_222" + "remarks": "rule_set_240" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure AIDE to Verify the Audit Tools", - "remarks": "rule_set_222" + "remarks": "rule_set_240" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "aide_check_audit_tools", - "remarks": "rule_set_222" + "remarks": "rule_set_240" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure AIDE to Verify the Audit Tools", - "remarks": "rule_set_222" + "remarks": "rule_set_240" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_systemd-journald_enabled", - "remarks": "rule_set_223" + "remarks": "rule_set_241" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable systemd-journald Service", - "remarks": "rule_set_223" + "remarks": "rule_set_241" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_systemd-journald_enabled", - "remarks": "rule_set_223" + "remarks": "rule_set_241" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable systemd-journald Service", - "remarks": "rule_set_223" + "remarks": "rule_set_241" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_systemd-journal-remote_installed", - "remarks": "rule_set_224" + "value": "journald_compress", + "remarks": "rule_set_242" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install systemd-journal-remote Package", - "remarks": "rule_set_224" + "value": "Ensure journald is configured to compress large log files", + "remarks": "rule_set_242" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_systemd-journal-remote_installed", - "remarks": "rule_set_224" + "value": "journald_compress", + "remarks": "rule_set_242" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install systemd-journal-remote Package", - "remarks": "rule_set_224" + "value": "Ensure journald is configured to compress large log files", + "remarks": "rule_set_242" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "socket_systemd-journal-remote_disabled", - "remarks": "rule_set_225" + "value": "journald_storage", + "remarks": "rule_set_243" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable systemd-journal-remote Socket", - "remarks": "rule_set_225" + "value": "Ensure journald is configured to write log files to persistent disk", + "remarks": "rule_set_243" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "socket_systemd-journal-remote_disabled", - "remarks": "rule_set_225" + "value": "journald_storage", + "remarks": "rule_set_243" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable systemd-journal-remote Socket", - "remarks": "rule_set_225" + "value": "Ensure journald is configured to write log files to persistent disk", + "remarks": "rule_set_243" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_compress", - "remarks": "rule_set_226" + "value": "package_systemd-journal-remote_installed", + "remarks": "rule_set_244" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure journald is configured to compress large log files", - "remarks": "rule_set_226" + "value": "Install systemd-journal-remote Package", + "remarks": "rule_set_244" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_compress", - "remarks": "rule_set_226" + "value": "package_systemd-journal-remote_installed", + "remarks": "rule_set_244" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure journald is configured to compress large log files", - "remarks": "rule_set_226" + "value": "Install systemd-journal-remote Package", + "remarks": "rule_set_244" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_storage", - "remarks": "rule_set_227" + "value": "socket_systemd-journal-remote_disabled", + "remarks": "rule_set_245" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure journald is configured to write log files to persistent disk", - "remarks": "rule_set_227" + "value": "Disable systemd-journal-remote Socket", + "remarks": "rule_set_245" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_storage", - "remarks": "rule_set_227" + "value": "socket_systemd-journal-remote_disabled", + "remarks": "rule_set_245" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure journald is configured to write log files to persistent disk", - "remarks": "rule_set_227" + "value": "Disable systemd-journal-remote Socket", + "remarks": "rule_set_245" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "rsyslog_files_groupownership", - "remarks": "rule_set_228" + "remarks": "rule_set_246" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Log Files Are Owned By Appropriate Group", - "remarks": "rule_set_228" + "remarks": "rule_set_246" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "rsyslog_files_groupownership", - "remarks": "rule_set_228" + "remarks": "rule_set_246" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Log Files Are Owned By Appropriate Group", - "remarks": "rule_set_228" + "remarks": "rule_set_246" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "rsyslog_files_ownership", - "remarks": "rule_set_229" + "remarks": "rule_set_247" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Log Files Are Owned By Appropriate User", - "remarks": "rule_set_229" + "remarks": "rule_set_247" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "rsyslog_files_ownership", - "remarks": "rule_set_229" + "remarks": "rule_set_247" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure Log Files Are Owned By Appropriate User", - "remarks": "rule_set_229" + "remarks": "rule_set_247" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "rsyslog_files_permissions", - "remarks": "rule_set_230" + "remarks": "rule_set_248" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure System Log Files Have Correct Permissions", - "remarks": "rule_set_230" + "remarks": "rule_set_248" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "rsyslog_files_permissions", - "remarks": "rule_set_230" + "remarks": "rule_set_248" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure System Log Files Have Correct Permissions", - "remarks": "rule_set_230" + "remarks": "rule_set_248" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_passwd", - "remarks": "rule_set_231" + "remarks": "rule_set_249" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns passwd File", - "remarks": "rule_set_231" + "remarks": "rule_set_249" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_passwd", - "remarks": "rule_set_231" + "remarks": "rule_set_249" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns passwd File", - "remarks": "rule_set_231" + "remarks": "rule_set_249" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_passwd", - "remarks": "rule_set_232" + "remarks": "rule_set_250" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns passwd File", - "remarks": "rule_set_232" + "remarks": "rule_set_250" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_passwd", - "remarks": "rule_set_232" + "remarks": "rule_set_250" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns passwd File", - "remarks": "rule_set_232" + "remarks": "rule_set_250" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_passwd", - "remarks": "rule_set_233" + "remarks": "rule_set_251" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on passwd File", - "remarks": "rule_set_233" + "remarks": "rule_set_251" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_passwd", - "remarks": "rule_set_233" + "remarks": "rule_set_251" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on passwd File", - "remarks": "rule_set_233" + "remarks": "rule_set_251" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_backup_etc_passwd", - "remarks": "rule_set_234" + "remarks": "rule_set_252" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns Backup passwd File", - "remarks": "rule_set_234" + "remarks": "rule_set_252" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_backup_etc_passwd", - "remarks": "rule_set_234" + "remarks": "rule_set_252" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns Backup passwd File", - "remarks": "rule_set_234" + "remarks": "rule_set_252" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_backup_etc_passwd", - "remarks": "rule_set_235" + "remarks": "rule_set_253" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns Backup passwd File", - "remarks": "rule_set_235" + "remarks": "rule_set_253" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_backup_etc_passwd", - "remarks": "rule_set_235" + "remarks": "rule_set_253" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns Backup passwd File", - "remarks": "rule_set_235" + "remarks": "rule_set_253" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_backup_etc_passwd", - "remarks": "rule_set_236" + "remarks": "rule_set_254" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on Backup passwd File", - "remarks": "rule_set_236" + "remarks": "rule_set_254" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_backup_etc_passwd", - "remarks": "rule_set_236" + "remarks": "rule_set_254" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on Backup passwd File", - "remarks": "rule_set_236" + "remarks": "rule_set_254" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_group", - "remarks": "rule_set_237" + "remarks": "rule_set_255" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns group File", - "remarks": "rule_set_237" + "remarks": "rule_set_255" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_group", - "remarks": "rule_set_237" + "remarks": "rule_set_255" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns group File", - "remarks": "rule_set_237" + "remarks": "rule_set_255" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_group", - "remarks": "rule_set_238" + "remarks": "rule_set_256" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns group File", - "remarks": "rule_set_238" + "remarks": "rule_set_256" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_group", - "remarks": "rule_set_238" + "remarks": "rule_set_256" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns group File", - "remarks": "rule_set_238" + "remarks": "rule_set_256" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_group", - "remarks": "rule_set_239" + "remarks": "rule_set_257" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on group File", - "remarks": "rule_set_239" + "remarks": "rule_set_257" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_group", - "remarks": "rule_set_239" + "remarks": "rule_set_257" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on group File", - "remarks": "rule_set_239" + "remarks": "rule_set_257" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_backup_etc_group", - "remarks": "rule_set_240" + "remarks": "rule_set_258" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns Backup group File", - "remarks": "rule_set_240" + "remarks": "rule_set_258" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_backup_etc_group", - "remarks": "rule_set_240" + "remarks": "rule_set_258" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns Backup group File", - "remarks": "rule_set_240" + "remarks": "rule_set_258" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_backup_etc_group", - "remarks": "rule_set_241" + "remarks": "rule_set_259" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns Backup group File", - "remarks": "rule_set_241" + "remarks": "rule_set_259" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_backup_etc_group", - "remarks": "rule_set_241" + "remarks": "rule_set_259" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns Backup group File", - "remarks": "rule_set_241" + "remarks": "rule_set_259" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_backup_etc_group", - "remarks": "rule_set_242" + "remarks": "rule_set_260" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on Backup group File", - "remarks": "rule_set_242" + "remarks": "rule_set_260" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_backup_etc_group", - "remarks": "rule_set_242" + "remarks": "rule_set_260" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on Backup group File", - "remarks": "rule_set_242" + "remarks": "rule_set_260" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_shadow", - "remarks": "rule_set_243" + "remarks": "rule_set_261" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns shadow File", - "remarks": "rule_set_243" + "remarks": "rule_set_261" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_shadow", - "remarks": "rule_set_243" + "remarks": "rule_set_261" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns shadow File", - "remarks": "rule_set_243" + "remarks": "rule_set_261" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_shadow", - "remarks": "rule_set_244" + "remarks": "rule_set_262" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns shadow File", - "remarks": "rule_set_244" + "remarks": "rule_set_262" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_shadow", - "remarks": "rule_set_244" + "remarks": "rule_set_262" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns shadow File", - "remarks": "rule_set_244" + "remarks": "rule_set_262" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_shadow", - "remarks": "rule_set_245" + "remarks": "rule_set_263" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on shadow File", - "remarks": "rule_set_245" + "remarks": "rule_set_263" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_shadow", - "remarks": "rule_set_245" + "remarks": "rule_set_263" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on shadow File", - "remarks": "rule_set_245" + "remarks": "rule_set_263" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_backup_etc_shadow", - "remarks": "rule_set_246" + "remarks": "rule_set_264" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns Backup shadow File", - "remarks": "rule_set_246" + "remarks": "rule_set_264" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_backup_etc_shadow", - "remarks": "rule_set_246" + "remarks": "rule_set_264" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns Backup shadow File", - "remarks": "rule_set_246" + "remarks": "rule_set_264" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_backup_etc_shadow", - "remarks": "rule_set_247" + "remarks": "rule_set_265" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns Backup shadow File", - "remarks": "rule_set_247" + "remarks": "rule_set_265" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_backup_etc_shadow", - "remarks": "rule_set_247" + "remarks": "rule_set_265" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns Backup shadow File", - "remarks": "rule_set_247" + "remarks": "rule_set_265" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_backup_etc_shadow", - "remarks": "rule_set_248" + "remarks": "rule_set_266" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on Backup shadow File", - "remarks": "rule_set_248" + "remarks": "rule_set_266" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_backup_etc_shadow", - "remarks": "rule_set_248" + "remarks": "rule_set_266" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on Backup shadow File", - "remarks": "rule_set_248" + "remarks": "rule_set_266" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_gshadow", - "remarks": "rule_set_249" + "remarks": "rule_set_267" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns gshadow File", - "remarks": "rule_set_249" + "remarks": "rule_set_267" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_gshadow", - "remarks": "rule_set_249" + "remarks": "rule_set_267" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns gshadow File", - "remarks": "rule_set_249" + "remarks": "rule_set_267" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_gshadow", - "remarks": "rule_set_250" + "remarks": "rule_set_268" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns gshadow File", - "remarks": "rule_set_250" + "remarks": "rule_set_268" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_gshadow", - "remarks": "rule_set_250" + "remarks": "rule_set_268" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns gshadow File", - "remarks": "rule_set_250" + "remarks": "rule_set_268" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_gshadow", - "remarks": "rule_set_251" + "remarks": "rule_set_269" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on gshadow File", - "remarks": "rule_set_251" + "remarks": "rule_set_269" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_gshadow", - "remarks": "rule_set_251" + "remarks": "rule_set_269" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on gshadow File", - "remarks": "rule_set_251" + "remarks": "rule_set_269" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_backup_etc_gshadow", - "remarks": "rule_set_252" + "remarks": "rule_set_270" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns Backup gshadow File", - "remarks": "rule_set_252" + "remarks": "rule_set_270" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_backup_etc_gshadow", - "remarks": "rule_set_252" + "remarks": "rule_set_270" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns Backup gshadow File", - "remarks": "rule_set_252" + "remarks": "rule_set_270" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_backup_etc_gshadow", - "remarks": "rule_set_253" + "remarks": "rule_set_271" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns Backup gshadow File", - "remarks": "rule_set_253" + "remarks": "rule_set_271" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_backup_etc_gshadow", - "remarks": "rule_set_253" + "remarks": "rule_set_271" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify User Who Owns Backup gshadow File", - "remarks": "rule_set_253" + "remarks": "rule_set_271" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_backup_etc_gshadow", - "remarks": "rule_set_254" + "remarks": "rule_set_272" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on Backup gshadow File", - "remarks": "rule_set_254" + "remarks": "rule_set_272" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_backup_etc_gshadow", - "remarks": "rule_set_254" + "remarks": "rule_set_272" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on Backup gshadow File", - "remarks": "rule_set_254" + "remarks": "rule_set_272" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_shells", - "remarks": "rule_set_255" + "remarks": "rule_set_273" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns /etc/shells File", - "remarks": "rule_set_255" + "remarks": "rule_set_273" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupowner_etc_shells", - "remarks": "rule_set_255" + "remarks": "rule_set_273" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Group Who Owns /etc/shells File", - "remarks": "rule_set_255" + "remarks": "rule_set_273" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_shells", - "remarks": "rule_set_256" + "remarks": "rule_set_274" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Who Owns /etc/shells File", - "remarks": "rule_set_256" + "remarks": "rule_set_274" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_owner_etc_shells", - "remarks": "rule_set_256" + "remarks": "rule_set_274" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Who Owns /etc/shells File", - "remarks": "rule_set_256" + "remarks": "rule_set_274" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_shells", - "remarks": "rule_set_257" + "remarks": "rule_set_275" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on /etc/shells File", - "remarks": "rule_set_257" + "remarks": "rule_set_275" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_etc_shells", - "remarks": "rule_set_257" + "remarks": "rule_set_275" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions on /etc/shells File", - "remarks": "rule_set_257" + "remarks": "rule_set_275" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_etc_security_opasswd", - "remarks": "rule_set_258" + "remarks": "rule_set_276" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions and Ownership of Old Passwords File", - "remarks": "rule_set_258" + "remarks": "rule_set_276" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_etc_security_opasswd", - "remarks": "rule_set_258" + "remarks": "rule_set_276" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify Permissions and Ownership of Old Passwords File", - "remarks": "rule_set_258" + "remarks": "rule_set_276" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_unauthorized_world_writable", - "remarks": "rule_set_259" + "remarks": "rule_set_277" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure No World-Writable Files Exist", - "remarks": "rule_set_259" + "remarks": "rule_set_277" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_unauthorized_world_writable", - "remarks": "rule_set_259" + "remarks": "rule_set_277" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure No World-Writable Files Exist", - "remarks": "rule_set_259" + "remarks": "rule_set_277" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dir_perms_world_writable_sticky_bits", - "remarks": "rule_set_260" + "remarks": "rule_set_278" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify that All World-Writable Directories Have Sticky Bits Set", - "remarks": "rule_set_260" + "remarks": "rule_set_278" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dir_perms_world_writable_sticky_bits", - "remarks": "rule_set_260" + "remarks": "rule_set_278" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify that All World-Writable Directories Have Sticky Bits Set", - "remarks": "rule_set_260" + "remarks": "rule_set_278" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_files_unowned_by_user", - "remarks": "rule_set_261" + "remarks": "rule_set_279" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Files Are Owned by a User", - "remarks": "rule_set_261" + "remarks": "rule_set_279" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_files_unowned_by_user", - "remarks": "rule_set_261" + "remarks": "rule_set_279" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Files Are Owned by a User", - "remarks": "rule_set_261" + "remarks": "rule_set_279" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_ungroupowned", - "remarks": "rule_set_262" + "remarks": "rule_set_280" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Files Are Owned by a Group", - "remarks": "rule_set_262" + "remarks": "rule_set_280" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_ungroupowned", - "remarks": "rule_set_262" + "remarks": "rule_set_280" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Files Are Owned by a Group", - "remarks": "rule_set_262" + "remarks": "rule_set_280" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_all_shadowed", - "remarks": "rule_set_263" + "remarks": "rule_set_281" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify All Account Password Hashes are Shadowed", - "remarks": "rule_set_263" + "remarks": "rule_set_281" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_all_shadowed", - "remarks": "rule_set_263" + "remarks": "rule_set_281" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify All Account Password Hashes are Shadowed", - "remarks": "rule_set_263" + "remarks": "rule_set_281" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_empty_passwords_etc_shadow", - "remarks": "rule_set_264" + "remarks": "rule_set_282" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure There Are No Accounts With Blank or Null Passwords", - "remarks": "rule_set_264" + "remarks": "rule_set_282" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_empty_passwords_etc_shadow", - "remarks": "rule_set_264" + "remarks": "rule_set_282" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure There Are No Accounts With Blank or Null Passwords", - "remarks": "rule_set_264" + "remarks": "rule_set_282" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "gid_passwd_group_same", - "remarks": "rule_set_265" + "remarks": "rule_set_283" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "All GIDs referenced in /etc/passwd must be defined in /etc/group", - "remarks": "rule_set_265" + "remarks": "rule_set_283" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "gid_passwd_group_same", - "remarks": "rule_set_265" + "remarks": "rule_set_283" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "All GIDs referenced in /etc/passwd must be defined in /etc/group", - "remarks": "rule_set_265" + "remarks": "rule_set_283" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "account_unique_id", - "remarks": "rule_set_266" + "remarks": "rule_set_284" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Accounts on the System Have Unique User IDs", - "remarks": "rule_set_266" + "remarks": "rule_set_284" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "account_unique_id", - "remarks": "rule_set_266" + "remarks": "rule_set_284" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Accounts on the System Have Unique User IDs", - "remarks": "rule_set_266" + "remarks": "rule_set_284" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "group_unique_id", - "remarks": "rule_set_267" + "remarks": "rule_set_285" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Groups on the System Have Unique Group ID", - "remarks": "rule_set_267" + "remarks": "rule_set_285" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "group_unique_id", - "remarks": "rule_set_267" + "remarks": "rule_set_285" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Groups on the System Have Unique Group ID", - "remarks": "rule_set_267" + "remarks": "rule_set_285" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "account_unique_name", - "remarks": "rule_set_268" + "remarks": "rule_set_286" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Accounts on the System Have Unique Names", - "remarks": "rule_set_268" + "remarks": "rule_set_286" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "account_unique_name", - "remarks": "rule_set_268" + "remarks": "rule_set_286" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Accounts on the System Have Unique Names", - "remarks": "rule_set_268" + "remarks": "rule_set_286" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "group_unique_name", - "remarks": "rule_set_269" + "remarks": "rule_set_287" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Groups on the System Have Unique Group Names", - "remarks": "rule_set_269" + "remarks": "rule_set_287" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "group_unique_name", - "remarks": "rule_set_269" + "remarks": "rule_set_287" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All Groups on the System Have Unique Group Names", - "remarks": "rule_set_269" + "remarks": "rule_set_287" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_user_interactive_home_directory_exists", - "remarks": "rule_set_270" + "remarks": "rule_set_288" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "All Interactive Users Home Directories Must Exist", - "remarks": "rule_set_270" + "remarks": "rule_set_288" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_user_interactive_home_directory_exists", - "remarks": "rule_set_270" + "remarks": "rule_set_288" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "All Interactive Users Home Directories Must Exist", - "remarks": "rule_set_270" + "remarks": "rule_set_288" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_ownership_home_directories", - "remarks": "rule_set_271" + "remarks": "rule_set_289" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "All Interactive User Home Directories Must Be Owned By The Primary User", - "remarks": "rule_set_271" + "remarks": "rule_set_289" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_ownership_home_directories", - "remarks": "rule_set_271" + "remarks": "rule_set_289" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "All Interactive User Home Directories Must Be Owned By The Primary User", - "remarks": "rule_set_271" + "remarks": "rule_set_289" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_home_directories", - "remarks": "rule_set_272" + "remarks": "rule_set_290" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "All Interactive User Home Directories Must Have mode 0750 Or Less Permissive", - "remarks": "rule_set_272" + "remarks": "rule_set_290" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_home_directories", - "remarks": "rule_set_272" + "remarks": "rule_set_290" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "All Interactive User Home Directories Must Have mode 0750 Or Less Permissive", - "remarks": "rule_set_272" + "remarks": "rule_set_290" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_user_dot_group_ownership", - "remarks": "rule_set_273" + "remarks": "rule_set_291" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "User Initialization Files Must Be Group-Owned By The Primary Group", - "remarks": "rule_set_273" + "remarks": "rule_set_291" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_user_dot_group_ownership", - "remarks": "rule_set_273" + "remarks": "rule_set_291" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "User Initialization Files Must Be Group-Owned By The Primary Group", - "remarks": "rule_set_273" + "remarks": "rule_set_291" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_user_dot_user_ownership", - "remarks": "rule_set_274" + "remarks": "rule_set_292" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "User Initialization Files Must Be Owned By the Primary User", - "remarks": "rule_set_274" + "remarks": "rule_set_292" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_user_dot_user_ownership", - "remarks": "rule_set_274" + "remarks": "rule_set_292" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "User Initialization Files Must Be Owned By the Primary User", - "remarks": "rule_set_274" + "remarks": "rule_set_292" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_user_dot_no_world_writable_programs", - "remarks": "rule_set_275" + "remarks": "rule_set_293" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "User Initialization Files Must Not Run World-Writable Programs", - "remarks": "rule_set_275" + "remarks": "rule_set_293" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_user_dot_no_world_writable_programs", - "remarks": "rule_set_275" + "remarks": "rule_set_293" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "User Initialization Files Must Not Run World-Writable Programs", - "remarks": "rule_set_275" + "remarks": "rule_set_293" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permission_user_init_files", - "remarks": "rule_set_276" + "remarks": "rule_set_294" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All User Initialization Files Have Mode 0740 Or Less Permissive", - "remarks": "rule_set_276" + "remarks": "rule_set_294" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permission_user_init_files", - "remarks": "rule_set_276" + "remarks": "rule_set_294" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure All User Initialization Files Have Mode 0740 Or Less Permissive", - "remarks": "rule_set_276" + "remarks": "rule_set_294" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_forward_files", - "remarks": "rule_set_277" + "remarks": "rule_set_295" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify No .forward Files Exist", - "remarks": "rule_set_277" + "remarks": "rule_set_295" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_forward_files", - "remarks": "rule_set_277" + "remarks": "rule_set_295" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify No .forward Files Exist", - "remarks": "rule_set_277" + "remarks": "rule_set_295" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_netrc_files", - "remarks": "rule_set_278" + "remarks": "rule_set_296" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify No netrc Files Exist", - "remarks": "rule_set_278" + "remarks": "rule_set_296" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "no_netrc_files", - "remarks": "rule_set_278" + "remarks": "rule_set_296" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify No netrc Files Exist", - "remarks": "rule_set_278" + "remarks": "rule_set_296" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "kernel_module_overlayfs_disabled", + "remarks": "rule_set_297" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure overlayfs kernel module is not available", + "remarks": "rule_set_297" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "kernel_module_overlayfs_disabled", + "remarks": "rule_set_297" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure overlayfs kernel module is not available", + "remarks": "rule_set_297" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "kernel_module_squashfs_disabled", - "remarks": "rule_set_279" + "remarks": "rule_set_298" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Mounting of squashfs", - "remarks": "rule_set_279" + "remarks": "rule_set_298" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "kernel_module_squashfs_disabled", - "remarks": "rule_set_279" + "remarks": "rule_set_298" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Mounting of squashfs", - "remarks": "rule_set_279" + "remarks": "rule_set_298" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "kernel_module_udf_disabled", - "remarks": "rule_set_280" + "remarks": "rule_set_299" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Mounting of udf", - "remarks": "rule_set_280" + "remarks": "rule_set_299" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "kernel_module_udf_disabled", - "remarks": "rule_set_280" + "remarks": "rule_set_299" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Disable Mounting of udf", - "remarks": "rule_set_280" + "remarks": "rule_set_299" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "partition_for_home", - "remarks": "rule_set_281" + "remarks": "rule_set_300" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure /home Located On Separate Partition", - "remarks": "rule_set_281" + "remarks": "rule_set_300" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "partition_for_home", - "remarks": "rule_set_281" + "remarks": "rule_set_300" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure /home Located On Separate Partition", - "remarks": "rule_set_281" + "remarks": "rule_set_300" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "partition_for_var", - "remarks": "rule_set_282" + "remarks": "rule_set_301" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure /var Located On Separate Partition", - "remarks": "rule_set_282" + "remarks": "rule_set_301" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "partition_for_var", - "remarks": "rule_set_282" + "remarks": "rule_set_301" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure /var Located On Separate Partition", - "remarks": "rule_set_282" + "remarks": "rule_set_301" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "partition_for_var_tmp", - "remarks": "rule_set_283" + "remarks": "rule_set_302" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure /var/tmp Located On Separate Partition", - "remarks": "rule_set_283" + "remarks": "rule_set_302" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "partition_for_var_tmp", - "remarks": "rule_set_283" + "remarks": "rule_set_302" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure /var/tmp Located On Separate Partition", - "remarks": "rule_set_283" + "remarks": "rule_set_302" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "partition_for_var_log", - "remarks": "rule_set_284" + "remarks": "rule_set_303" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure /var/log Located On Separate Partition", - "remarks": "rule_set_284" + "remarks": "rule_set_303" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "partition_for_var_log", - "remarks": "rule_set_284" + "remarks": "rule_set_303" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure /var/log Located On Separate Partition", - "remarks": "rule_set_284" + "remarks": "rule_set_303" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "partition_for_var_log_audit", - "remarks": "rule_set_285" + "remarks": "rule_set_304" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure /var/log/audit Located On Separate Partition", - "remarks": "rule_set_285" + "remarks": "rule_set_304" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "partition_for_var_log_audit", - "remarks": "rule_set_285" + "remarks": "rule_set_304" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure /var/log/audit Located On Separate Partition", - "remarks": "rule_set_285" + "remarks": "rule_set_304" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "selinux_state", - "remarks": "rule_set_286" + "remarks": "rule_set_305" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure SELinux State is Enforcing", - "remarks": "rule_set_286" + "remarks": "rule_set_305" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "selinux_state", - "remarks": "rule_set_286" + "remarks": "rule_set_305" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure SELinux State is Enforcing", - "remarks": "rule_set_286" + "remarks": "rule_set_305" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_gdm_removed", - "remarks": "rule_set_287" + "value": "sysctl_fs_protected_symlinks", + "remarks": "rule_set_306" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Remove the GDM Package Group", - "remarks": "rule_set_287" + "value": "Enable Kernel Parameter to Enforce DAC on Symlinks", + "remarks": "rule_set_306" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_gdm_removed", - "remarks": "rule_set_287" + "value": "sysctl_fs_protected_symlinks", + "remarks": "rule_set_306" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Remove the GDM Package Group", - "remarks": "rule_set_287" + "value": "Enable Kernel Parameter to Enforce DAC on Symlinks", + "remarks": "rule_set_306" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "xwindows_runlevel_target", - "remarks": "rule_set_288" + "value": "service_cockpit_disabled", + "remarks": "rule_set_307" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Graphical Environment Startup By Setting Default Target", - "remarks": "rule_set_288" + "value": "Disable Cockpit Management Server", + "remarks": "rule_set_307" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "xwindows_runlevel_target", - "remarks": "rule_set_288" + "value": "service_cockpit_disabled", + "remarks": "rule_set_307" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Graphical Environment Startup By Setting Default Target", - "remarks": "rule_set_288" + "value": "Disable Cockpit Management Server", + "remarks": "rule_set_307" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_openldap-clients_removed", - "remarks": "rule_set_289" + "value": "package_gdm_removed", + "remarks": "rule_set_308" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure LDAP client is not installed", - "remarks": "rule_set_289" + "value": "Remove the GDM Package Group", + "remarks": "rule_set_308" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_openldap-clients_removed", - "remarks": "rule_set_289" + "value": "package_gdm_removed", + "remarks": "rule_set_308" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure LDAP client is not installed", - "remarks": "rule_set_289" + "value": "Remove the GDM Package Group", + "remarks": "rule_set_308" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_tipc_disabled", - "remarks": "rule_set_290" + "value": "xwindows_runlevel_target", + "remarks": "rule_set_309" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable TIPC Support", - "remarks": "rule_set_290" + "value": "Disable Graphical Environment Startup By Setting Default Target", + "remarks": "rule_set_309" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_tipc_disabled", - "remarks": "rule_set_290" + "value": "xwindows_runlevel_target", + "remarks": "rule_set_309" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable TIPC Support", - "remarks": "rule_set_290" + "value": "Disable Graphical Environment Startup By Setting Default Target", + "remarks": "rule_set_309" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_sctp_disabled", - "remarks": "rule_set_291" + "value": "package_openldap-clients_removed", + "remarks": "rule_set_310" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable SCTP Support", - "remarks": "rule_set_291" + "value": "Ensure LDAP client is not installed", + "remarks": "rule_set_310" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_sctp_disabled", - "remarks": "rule_set_291" + "value": "package_openldap-clients_removed", + "remarks": "rule_set_310" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable SCTP Support", - "remarks": "rule_set_291" + "value": "Ensure LDAP client is not installed", + "remarks": "rule_set_310" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_gssapi_auth", - "remarks": "rule_set_292" + "value": "sysctl_net_ipv4_ip_forward", + "remarks": "rule_set_311" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable GSSAPI Authentication", - "remarks": "rule_set_292" + "value": "Disable Kernel Parameter for IP Forwarding on IPv4 Interfaces", + "remarks": "rule_set_311" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_gssapi_auth", - "remarks": "rule_set_292" + "value": "sysctl_net_ipv4_ip_forward", + "remarks": "rule_set_311" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Disable Kernel Parameter for IP Forwarding on IPv4 Interfaces", + "remarks": "rule_set_311" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_disable_forwarding", + "remarks": "rule_set_312" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Disable SSH Forwarding", + "remarks": "rule_set_312" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_disable_forwarding", + "remarks": "rule_set_312" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable GSSAPI Authentication", - "remarks": "rule_set_292" + "value": "Disable SSH Forwarding", + "remarks": "rule_set_312" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_require_authentication", - "remarks": "rule_set_293" + "value": "sshd_disable_gssapi_auth", + "remarks": "rule_set_313" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Users Re-Authenticate for Privilege Escalation - sudo", - "remarks": "rule_set_293" + "value": "Disable GSSAPI Authentication", + "remarks": "rule_set_313" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_require_authentication", - "remarks": "rule_set_293" + "value": "sshd_disable_gssapi_auth", + "remarks": "rule_set_313" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Users Re-Authenticate for Privilege Escalation - sudo", - "remarks": "rule_set_293" + "value": "Disable GSSAPI Authentication", + "remarks": "rule_set_313" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_passwords_pam_faillock_deny_root", - "remarks": "rule_set_294" + "remarks": "rule_set_314" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure the root Account for Failed Password Attempts", - "remarks": "rule_set_294" + "remarks": "rule_set_314" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_passwords_pam_faillock_deny_root", - "remarks": "rule_set_294" + "remarks": "rule_set_314" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure the root Account for Failed Password Attempts", - "remarks": "rule_set_294" + "remarks": "rule_set_314" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_minimum_age_login_defs", - "remarks": "rule_set_295" + "remarks": "rule_set_315" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Password Minimum Age", - "remarks": "rule_set_295" + "remarks": "rule_set_315" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_minimum_age_login_defs", - "remarks": "rule_set_295" + "remarks": "rule_set_315" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Password Minimum Age", - "remarks": "rule_set_295" + "remarks": "rule_set_315" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_set_min_life_existing", - "remarks": "rule_set_296" + "remarks": "rule_set_316" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Existing Passwords Minimum Age", - "remarks": "rule_set_296" + "remarks": "rule_set_316" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "accounts_password_set_min_life_existing", - "remarks": "rule_set_296" + "remarks": "rule_set_316" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Set Existing Passwords Minimum Age", - "remarks": "rule_set_296" + "remarks": "rule_set_316" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "no_nologin_in_shells", + "remarks": "rule_set_317" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure nologin Shell is Not Listed in /etc/shells", + "remarks": "rule_set_317" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "no_nologin_in_shells", + "remarks": "rule_set_317" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure nologin Shell is Not Listed in /etc/shells", + "remarks": "rule_set_317" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_audit_installed", - "remarks": "rule_set_297" + "remarks": "rule_set_318" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure the audit Subsystem is Installed", - "remarks": "rule_set_297" + "remarks": "rule_set_318" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_audit_installed", - "remarks": "rule_set_297" + "remarks": "rule_set_318" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure the audit Subsystem is Installed", - "remarks": "rule_set_297" + "remarks": "rule_set_318" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_audit-libs_installed", - "remarks": "rule_set_298" + "remarks": "rule_set_319" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure the audit-libs package as a part of audit Subsystem is Installed", - "remarks": "rule_set_298" + "remarks": "rule_set_319" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "package_audit-libs_installed", - "remarks": "rule_set_298" + "remarks": "rule_set_319" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure the audit-libs package as a part of audit Subsystem is Installed", - "remarks": "rule_set_298" + "remarks": "rule_set_319" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "grub2_audit_argument", - "remarks": "rule_set_299" + "remarks": "rule_set_320" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable Auditing for Processes Which Start Prior to the Audit Daemon", - "remarks": "rule_set_299" + "remarks": "rule_set_320" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "grub2_audit_argument", - "remarks": "rule_set_299" + "remarks": "rule_set_320" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable Auditing for Processes Which Start Prior to the Audit Daemon", - "remarks": "rule_set_299" + "remarks": "rule_set_320" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "grub2_audit_backlog_limit_argument", - "remarks": "rule_set_300" + "remarks": "rule_set_321" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Extend Audit Backlog Limit for the Audit Daemon", - "remarks": "rule_set_300" + "remarks": "rule_set_321" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "grub2_audit_backlog_limit_argument", - "remarks": "rule_set_300" + "remarks": "rule_set_321" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Extend Audit Backlog Limit for the Audit Daemon", - "remarks": "rule_set_300" + "remarks": "rule_set_321" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_auditd_enabled", - "remarks": "rule_set_301" + "remarks": "rule_set_322" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable auditd Service", - "remarks": "rule_set_301" + "remarks": "rule_set_322" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "service_auditd_enabled", - "remarks": "rule_set_301" + "remarks": "rule_set_322" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Enable auditd Service", - "remarks": "rule_set_301" + "remarks": "rule_set_322" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "auditd_data_retention_max_log_file", - "remarks": "rule_set_302" + "remarks": "rule_set_323" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure auditd Max Log File Size", - "remarks": "rule_set_302" + "remarks": "rule_set_323" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "auditd_data_retention_max_log_file", - "remarks": "rule_set_302" + "remarks": "rule_set_323" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure auditd Max Log File Size", - "remarks": "rule_set_302" + "remarks": "rule_set_323" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "auditd_data_retention_max_log_file_action", - "remarks": "rule_set_303" + "remarks": "rule_set_324" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure auditd max_log_file_action Upon Reaching Maximum Log Size", - "remarks": "rule_set_303" + "remarks": "rule_set_324" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "auditd_data_retention_max_log_file_action", - "remarks": "rule_set_303" + "remarks": "rule_set_324" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure auditd max_log_file_action Upon Reaching Maximum Log Size", - "remarks": "rule_set_303" + "remarks": "rule_set_324" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "auditd_data_disk_error_action", - "remarks": "rule_set_304" + "remarks": "rule_set_325" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure auditd Disk Error Action on Disk Error", - "remarks": "rule_set_304" + "remarks": "rule_set_325" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "auditd_data_disk_error_action", - "remarks": "rule_set_304" + "remarks": "rule_set_325" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure auditd Disk Error Action on Disk Error", - "remarks": "rule_set_304" + "remarks": "rule_set_325" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "auditd_data_disk_full_action", - "remarks": "rule_set_305" + "remarks": "rule_set_326" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure auditd Disk Full Action when Disk Space Is Full", - "remarks": "rule_set_305" + "remarks": "rule_set_326" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "auditd_data_disk_full_action", - "remarks": "rule_set_305" + "remarks": "rule_set_326" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure auditd Disk Full Action when Disk Space Is Full", - "remarks": "rule_set_305" + "remarks": "rule_set_326" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "auditd_data_retention_action_mail_acct", - "remarks": "rule_set_306" + "remarks": "rule_set_327" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure auditd mail_acct Action on Low Disk Space", - "remarks": "rule_set_306" + "remarks": "rule_set_327" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "auditd_data_retention_action_mail_acct", - "remarks": "rule_set_306" + "remarks": "rule_set_327" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure auditd mail_acct Action on Low Disk Space", - "remarks": "rule_set_306" + "remarks": "rule_set_327" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "auditd_data_retention_admin_space_left_action", - "remarks": "rule_set_307" + "remarks": "rule_set_328" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure auditd admin_space_left Action on Low Disk Space", - "remarks": "rule_set_307" + "remarks": "rule_set_328" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "auditd_data_retention_admin_space_left_action", - "remarks": "rule_set_307" + "remarks": "rule_set_328" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure auditd admin_space_left Action on Low Disk Space", - "remarks": "rule_set_307" + "remarks": "rule_set_328" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "auditd_data_retention_space_left_action", - "remarks": "rule_set_308" + "remarks": "rule_set_329" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure auditd space_left Action on Low Disk Space", - "remarks": "rule_set_308" + "remarks": "rule_set_329" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "auditd_data_retention_space_left_action", - "remarks": "rule_set_308" + "remarks": "rule_set_329" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Configure auditd space_left Action on Low Disk Space", - "remarks": "rule_set_308" + "remarks": "rule_set_329" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_sysadmin_actions", - "remarks": "rule_set_309" + "remarks": "rule_set_330" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure auditd Collects System Administrator Actions", - "remarks": "rule_set_309" + "remarks": "rule_set_330" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_sysadmin_actions", - "remarks": "rule_set_309" + "remarks": "rule_set_330" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure auditd Collects System Administrator Actions", - "remarks": "rule_set_309" + "remarks": "rule_set_330" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_suid_auid_privilege_function", - "remarks": "rule_set_310" + "remarks": "rule_set_331" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Events When Executables Are Run As Another User", - "remarks": "rule_set_310" + "remarks": "rule_set_331" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_suid_auid_privilege_function", - "remarks": "rule_set_310" + "remarks": "rule_set_331" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Events When Executables Are Run As Another User", - "remarks": "rule_set_310" + "remarks": "rule_set_331" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_sudo_log_events", - "remarks": "rule_set_311" + "remarks": "rule_set_332" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Attempts to perform maintenance activities", - "remarks": "rule_set_311" + "remarks": "rule_set_332" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_sudo_log_events", - "remarks": "rule_set_311" + "remarks": "rule_set_332" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Attempts to perform maintenance activities", - "remarks": "rule_set_311" + "remarks": "rule_set_332" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_time_adjtimex", - "remarks": "rule_set_312" + "remarks": "rule_set_333" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record attempts to alter time through adjtimex", - "remarks": "rule_set_312" + "remarks": "rule_set_333" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_time_adjtimex", - "remarks": "rule_set_312" + "remarks": "rule_set_333" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record attempts to alter time through adjtimex", - "remarks": "rule_set_312" + "remarks": "rule_set_333" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_time_settimeofday", - "remarks": "rule_set_313" + "remarks": "rule_set_334" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record attempts to alter time through settimeofday", - "remarks": "rule_set_313" + "remarks": "rule_set_334" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_time_settimeofday", - "remarks": "rule_set_313" + "remarks": "rule_set_334" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record attempts to alter time through settimeofday", - "remarks": "rule_set_313" + "remarks": "rule_set_334" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_time_clock_settime", - "remarks": "rule_set_314" + "remarks": "rule_set_335" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Attempts to Alter Time Through clock_settime", - "remarks": "rule_set_314" + "remarks": "rule_set_335" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_time_clock_settime", - "remarks": "rule_set_314" + "remarks": "rule_set_335" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Attempts to Alter Time Through clock_settime", - "remarks": "rule_set_314" + "remarks": "rule_set_335" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_time_watch_localtime", - "remarks": "rule_set_315" + "remarks": "rule_set_336" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Attempts to Alter the localtime File", - "remarks": "rule_set_315" + "remarks": "rule_set_336" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_time_watch_localtime", - "remarks": "rule_set_315" + "remarks": "rule_set_336" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Attempts to Alter the localtime File", - "remarks": "rule_set_315" + "remarks": "rule_set_336" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_networkconfig_modification", - "remarks": "rule_set_316" + "remarks": "rule_set_337" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Events that Modify the System's Network Environment", - "remarks": "rule_set_316" + "remarks": "rule_set_337" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_networkconfig_modification", - "remarks": "rule_set_316" + "remarks": "rule_set_337" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Events that Modify the System's Network Environment", - "remarks": "rule_set_316" + "remarks": "rule_set_337" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_networkconfig_modification_network_scripts", - "remarks": "rule_set_317" + "remarks": "rule_set_338" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Events that Modify the System's Network Environment", - "remarks": "rule_set_317" + "remarks": "rule_set_338" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_networkconfig_modification_network_scripts", - "remarks": "rule_set_317" + "remarks": "rule_set_338" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Events that Modify the System's Network Environment", - "remarks": "rule_set_317" + "remarks": "rule_set_338" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_privileged_commands", - "remarks": "rule_set_318" + "remarks": "rule_set_339" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure auditd Collects Information on the Use of Privileged Commands", - "remarks": "rule_set_318" + "remarks": "rule_set_339" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_privileged_commands", - "remarks": "rule_set_318" + "remarks": "rule_set_339" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure auditd Collects Information on the Use of Privileged Commands", - "remarks": "rule_set_318" + "remarks": "rule_set_339" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_unsuccessful_file_modification_creat", - "remarks": "rule_set_319" + "remarks": "rule_set_340" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Unsuccessful Access Attempts to Files - creat", - "remarks": "rule_set_319" + "remarks": "rule_set_340" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_unsuccessful_file_modification_creat", - "remarks": "rule_set_319" + "remarks": "rule_set_340" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Unsuccessful Access Attempts to Files - creat", - "remarks": "rule_set_319" + "remarks": "rule_set_340" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_unsuccessful_file_modification_ftruncate", - "remarks": "rule_set_320" + "remarks": "rule_set_341" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Unsuccessful Access Attempts to Files - ftruncate", - "remarks": "rule_set_320" + "remarks": "rule_set_341" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_unsuccessful_file_modification_ftruncate", - "remarks": "rule_set_320" + "remarks": "rule_set_341" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Unsuccessful Access Attempts to Files - ftruncate", - "remarks": "rule_set_320" + "remarks": "rule_set_341" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_unsuccessful_file_modification_open", - "remarks": "rule_set_321" + "remarks": "rule_set_342" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Unsuccessful Access Attempts to Files - open", - "remarks": "rule_set_321" + "remarks": "rule_set_342" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_unsuccessful_file_modification_open", - "remarks": "rule_set_321" + "remarks": "rule_set_342" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Unsuccessful Access Attempts to Files - open", - "remarks": "rule_set_321" + "remarks": "rule_set_342" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_unsuccessful_file_modification_openat", - "remarks": "rule_set_322" + "remarks": "rule_set_343" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Unsuccessful Access Attempts to Files - openat", - "remarks": "rule_set_322" + "remarks": "rule_set_343" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_unsuccessful_file_modification_openat", - "remarks": "rule_set_322" + "remarks": "rule_set_343" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Unsuccessful Access Attempts to Files - openat", - "remarks": "rule_set_322" + "remarks": "rule_set_343" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_unsuccessful_file_modification_truncate", - "remarks": "rule_set_323" + "remarks": "rule_set_344" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Unsuccessful Access Attempts to Files - truncate", - "remarks": "rule_set_323" + "remarks": "rule_set_344" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_unsuccessful_file_modification_truncate", - "remarks": "rule_set_323" + "remarks": "rule_set_344" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Unsuccessful Access Attempts to Files - truncate", - "remarks": "rule_set_323" + "remarks": "rule_set_344" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_usergroup_modification_group", - "remarks": "rule_set_324" + "remarks": "rule_set_345" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Events that Modify User/Group Information - /etc/group", - "remarks": "rule_set_324" + "remarks": "rule_set_345" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_usergroup_modification_group", - "remarks": "rule_set_324" + "remarks": "rule_set_345" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Events that Modify User/Group Information - /etc/group", - "remarks": "rule_set_324" + "remarks": "rule_set_345" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_gshadow", - "remarks": "rule_set_325" + "value": "audit_rules_usergroup_modification_passwd", + "remarks": "rule_set_346" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify User/Group Information - /etc/gshadow", - "remarks": "rule_set_325" + "value": "Record Events that Modify User/Group Information - /etc/passwd", + "remarks": "rule_set_346" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_gshadow", - "remarks": "rule_set_325" + "value": "audit_rules_usergroup_modification_passwd", + "remarks": "rule_set_346" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify User/Group Information - /etc/gshadow", - "remarks": "rule_set_325" + "value": "Record Events that Modify User/Group Information - /etc/passwd", + "remarks": "rule_set_346" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_opasswd", - "remarks": "rule_set_326" + "value": "audit_rules_usergroup_modification_gshadow", + "remarks": "rule_set_347" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify User/Group Information - /etc/security/opasswd", - "remarks": "rule_set_326" + "value": "Record Events that Modify User/Group Information - /etc/gshadow", + "remarks": "rule_set_347" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_opasswd", - "remarks": "rule_set_326" + "value": "audit_rules_usergroup_modification_gshadow", + "remarks": "rule_set_347" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify User/Group Information - /etc/security/opasswd", - "remarks": "rule_set_326" + "value": "Record Events that Modify User/Group Information - /etc/gshadow", + "remarks": "rule_set_347" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_passwd", - "remarks": "rule_set_327" + "value": "audit_rules_usergroup_modification_shadow", + "remarks": "rule_set_348" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify User/Group Information - /etc/passwd", - "remarks": "rule_set_327" + "value": "Record Events that Modify User/Group Information - /etc/shadow", + "remarks": "rule_set_348" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_passwd", - "remarks": "rule_set_327" + "value": "audit_rules_usergroup_modification_shadow", + "remarks": "rule_set_348" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify User/Group Information - /etc/passwd", - "remarks": "rule_set_327" + "value": "Record Events that Modify User/Group Information - /etc/shadow", + "remarks": "rule_set_348" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_shadow", - "remarks": "rule_set_328" + "value": "audit_rules_usergroup_modification_opasswd", + "remarks": "rule_set_349" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify User/Group Information - /etc/shadow", - "remarks": "rule_set_328" + "value": "Record Events that Modify User/Group Information - /etc/security/opasswd", + "remarks": "rule_set_349" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_shadow", - "remarks": "rule_set_328" + "value": "audit_rules_usergroup_modification_opasswd", + "remarks": "rule_set_349" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify User/Group Information - /etc/shadow", - "remarks": "rule_set_328" + "value": "Record Events that Modify User/Group Information - /etc/security/opasswd", + "remarks": "rule_set_349" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_dac_modification_chmod", - "remarks": "rule_set_329" + "remarks": "rule_set_350" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Events that Modify the System's Discretionary Access Controls - chmod", - "remarks": "rule_set_329" + "remarks": "rule_set_350" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_dac_modification_chmod", - "remarks": "rule_set_329" + "remarks": "rule_set_350" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Events that Modify the System's Discretionary Access Controls - chmod", - "remarks": "rule_set_329" + "remarks": "rule_set_350" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_chown", - "remarks": "rule_set_330" + "value": "audit_rules_dac_modification_fchmod", + "remarks": "rule_set_351" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - chown", - "remarks": "rule_set_330" + "value": "Record Events that Modify the System's Discretionary Access Controls - fchmod", + "remarks": "rule_set_351" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_chown", - "remarks": "rule_set_330" + "value": "audit_rules_dac_modification_fchmod", + "remarks": "rule_set_351" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - chown", - "remarks": "rule_set_330" + "value": "Record Events that Modify the System's Discretionary Access Controls - fchmod", + "remarks": "rule_set_351" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchmod", - "remarks": "rule_set_331" + "value": "audit_rules_dac_modification_fchmodat", + "remarks": "rule_set_352" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fchmod", - "remarks": "rule_set_331" + "value": "Record Events that Modify the System's Discretionary Access Controls - fchmodat", + "remarks": "rule_set_352" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchmod", - "remarks": "rule_set_331" + "value": "audit_rules_dac_modification_fchmodat", + "remarks": "rule_set_352" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fchmod", - "remarks": "rule_set_331" + "value": "Record Events that Modify the System's Discretionary Access Controls - fchmodat", + "remarks": "rule_set_352" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchmodat", - "remarks": "rule_set_332" + "value": "audit_rules_dac_modification_fchmodat2", + "remarks": "rule_set_353" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fchmodat", - "remarks": "rule_set_332" + "value": "Record Events that Modify the System's Discretionary Access Controls - fchmodat2", + "remarks": "rule_set_353" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchmodat", - "remarks": "rule_set_332" + "value": "audit_rules_dac_modification_fchmodat2", + "remarks": "rule_set_353" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fchmodat", - "remarks": "rule_set_332" + "value": "Record Events that Modify the System's Discretionary Access Controls - fchmodat2", + "remarks": "rule_set_353" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchmodat2", - "remarks": "rule_set_333" + "value": "audit_rules_dac_modification_chown", + "remarks": "rule_set_354" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fchmodat2", - "remarks": "rule_set_333" + "value": "Record Events that Modify the System's Discretionary Access Controls - chown", + "remarks": "rule_set_354" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchmodat2", - "remarks": "rule_set_333" + "value": "audit_rules_dac_modification_chown", + "remarks": "rule_set_354" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fchmodat2", - "remarks": "rule_set_333" + "value": "Record Events that Modify the System's Discretionary Access Controls - chown", + "remarks": "rule_set_354" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_dac_modification_fchown", - "remarks": "rule_set_334" + "remarks": "rule_set_355" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Events that Modify the System's Discretionary Access Controls - fchown", - "remarks": "rule_set_334" + "remarks": "rule_set_355" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_dac_modification_fchown", - "remarks": "rule_set_334" + "remarks": "rule_set_355" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Events that Modify the System's Discretionary Access Controls - fchown", - "remarks": "rule_set_334" + "remarks": "rule_set_355" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_dac_modification_fchownat", - "remarks": "rule_set_335" + "remarks": "rule_set_356" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Events that Modify the System's Discretionary Access Controls - fchownat", - "remarks": "rule_set_335" + "remarks": "rule_set_356" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_dac_modification_fchownat", - "remarks": "rule_set_335" + "remarks": "rule_set_356" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Events that Modify the System's Discretionary Access Controls - fchownat", - "remarks": "rule_set_335" + "remarks": "rule_set_356" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fremovexattr", - "remarks": "rule_set_336" + "value": "audit_rules_dac_modification_lchown", + "remarks": "rule_set_357" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fremovexattr", - "remarks": "rule_set_336" + "value": "Record Events that Modify the System's Discretionary Access Controls - lchown", + "remarks": "rule_set_357" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fremovexattr", - "remarks": "rule_set_336" + "value": "audit_rules_dac_modification_lchown", + "remarks": "rule_set_357" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fremovexattr", - "remarks": "rule_set_336" + "value": "Record Events that Modify the System's Discretionary Access Controls - lchown", + "remarks": "rule_set_357" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fsetxattr", - "remarks": "rule_set_337" + "value": "audit_rules_dac_modification_fremovexattr", + "remarks": "rule_set_358" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fsetxattr", - "remarks": "rule_set_337" + "value": "Record Events that Modify the System's Discretionary Access Controls - fremovexattr", + "remarks": "rule_set_358" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fsetxattr", - "remarks": "rule_set_337" + "value": "audit_rules_dac_modification_fremovexattr", + "remarks": "rule_set_358" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fsetxattr", - "remarks": "rule_set_337" + "value": "Record Events that Modify the System's Discretionary Access Controls - fremovexattr", + "remarks": "rule_set_358" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_lchown", - "remarks": "rule_set_338" + "value": "audit_rules_dac_modification_fsetxattr", + "remarks": "rule_set_359" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - lchown", - "remarks": "rule_set_338" + "value": "Record Events that Modify the System's Discretionary Access Controls - fsetxattr", + "remarks": "rule_set_359" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_lchown", - "remarks": "rule_set_338" + "value": "audit_rules_dac_modification_fsetxattr", + "remarks": "rule_set_359" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - lchown", - "remarks": "rule_set_338" + "value": "Record Events that Modify the System's Discretionary Access Controls - fsetxattr", + "remarks": "rule_set_359" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_dac_modification_lremovexattr", - "remarks": "rule_set_339" + "remarks": "rule_set_360" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Events that Modify the System's Discretionary Access Controls - lremovexattr", - "remarks": "rule_set_339" + "remarks": "rule_set_360" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_dac_modification_lremovexattr", - "remarks": "rule_set_339" + "remarks": "rule_set_360" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Events that Modify the System's Discretionary Access Controls - lremovexattr", - "remarks": "rule_set_339" + "remarks": "rule_set_360" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_dac_modification_lsetxattr", - "remarks": "rule_set_340" + "remarks": "rule_set_361" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Events that Modify the System's Discretionary Access Controls - lsetxattr", - "remarks": "rule_set_340" + "remarks": "rule_set_361" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_dac_modification_lsetxattr", - "remarks": "rule_set_340" + "remarks": "rule_set_361" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Events that Modify the System's Discretionary Access Controls - lsetxattr", - "remarks": "rule_set_340" + "remarks": "rule_set_361" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_dac_modification_removexattr", - "remarks": "rule_set_341" + "remarks": "rule_set_362" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Events that Modify the System's Discretionary Access Controls - removexattr", - "remarks": "rule_set_341" + "remarks": "rule_set_362" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_dac_modification_removexattr", - "remarks": "rule_set_341" + "remarks": "rule_set_362" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Events that Modify the System's Discretionary Access Controls - removexattr", - "remarks": "rule_set_341" + "remarks": "rule_set_362" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_dac_modification_setxattr", - "remarks": "rule_set_342" + "remarks": "rule_set_363" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Events that Modify the System's Discretionary Access Controls - setxattr", - "remarks": "rule_set_342" + "remarks": "rule_set_363" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_dac_modification_setxattr", - "remarks": "rule_set_342" + "remarks": "rule_set_363" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Events that Modify the System's Discretionary Access Controls - setxattr", - "remarks": "rule_set_342" + "remarks": "rule_set_363" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_media_export", - "remarks": "rule_set_343" + "remarks": "rule_set_364" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure auditd Collects Information on Exporting to Media (successful)", - "remarks": "rule_set_343" + "remarks": "rule_set_364" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_media_export", - "remarks": "rule_set_343" + "remarks": "rule_set_364" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure auditd Collects Information on Exporting to Media (successful)", - "remarks": "rule_set_343" + "remarks": "rule_set_364" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_session_events_utmp", - "remarks": "rule_set_344" + "remarks": "rule_set_365" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Attempts to Alter Process and Session Initiation Information utmp", - "remarks": "rule_set_344" + "remarks": "rule_set_365" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_session_events_utmp", - "remarks": "rule_set_344" + "remarks": "rule_set_365" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Attempts to Alter Process and Session Initiation Information utmp", - "remarks": "rule_set_344" + "remarks": "rule_set_365" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_session_events_btmp", - "remarks": "rule_set_345" + "remarks": "rule_set_366" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Attempts to Alter Process and Session Initiation Information btmp", - "remarks": "rule_set_345" + "remarks": "rule_set_366" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_session_events_btmp", - "remarks": "rule_set_345" + "remarks": "rule_set_366" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Attempts to Alter Process and Session Initiation Information btmp", - "remarks": "rule_set_345" + "remarks": "rule_set_366" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_session_events_wtmp", - "remarks": "rule_set_346" + "remarks": "rule_set_367" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Attempts to Alter Process and Session Initiation Information wtmp", - "remarks": "rule_set_346" + "remarks": "rule_set_367" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_session_events_wtmp", - "remarks": "rule_set_346" + "remarks": "rule_set_367" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Attempts to Alter Process and Session Initiation Information wtmp", - "remarks": "rule_set_346" + "remarks": "rule_set_367" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_login_events_faillock", - "remarks": "rule_set_347" + "remarks": "rule_set_368" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Attempts to Alter Logon and Logout Events - faillock", - "remarks": "rule_set_347" + "remarks": "rule_set_368" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_login_events_faillock", - "remarks": "rule_set_347" + "remarks": "rule_set_368" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Attempts to Alter Logon and Logout Events - faillock", - "remarks": "rule_set_347" + "remarks": "rule_set_368" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_login_events_lastlog", - "remarks": "rule_set_348" + "remarks": "rule_set_369" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Attempts to Alter Logon and Logout Events - lastlog", - "remarks": "rule_set_348" + "remarks": "rule_set_369" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_login_events_lastlog", - "remarks": "rule_set_348" + "remarks": "rule_set_369" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Attempts to Alter Logon and Logout Events - lastlog", - "remarks": "rule_set_348" + "remarks": "rule_set_369" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_rename", - "remarks": "rule_set_349" + "value": "audit_rules_file_deletion_events_unlink", + "remarks": "rule_set_370" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects File Deletion Events by User - rename", - "remarks": "rule_set_349" + "value": "Ensure auditd Collects File Deletion Events by User - unlink", + "remarks": "rule_set_370" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_rename", - "remarks": "rule_set_349" + "value": "audit_rules_file_deletion_events_unlink", + "remarks": "rule_set_370" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects File Deletion Events by User - rename", - "remarks": "rule_set_349" + "value": "Ensure auditd Collects File Deletion Events by User - unlink", + "remarks": "rule_set_370" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_renameat", - "remarks": "rule_set_350" + "value": "audit_rules_file_deletion_events_unlinkat", + "remarks": "rule_set_371" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects File Deletion Events by User - renameat", - "remarks": "rule_set_350" + "value": "Ensure auditd Collects File Deletion Events by User - unlinkat", + "remarks": "rule_set_371" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_renameat", - "remarks": "rule_set_350" + "value": "audit_rules_file_deletion_events_unlinkat", + "remarks": "rule_set_371" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects File Deletion Events by User - renameat", - "remarks": "rule_set_350" + "value": "Ensure auditd Collects File Deletion Events by User - unlinkat", + "remarks": "rule_set_371" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_renameat2", - "remarks": "rule_set_351" + "value": "audit_rules_file_deletion_events_rename", + "remarks": "rule_set_372" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects File Deletion Events by User - renameat2", - "remarks": "rule_set_351" + "value": "Ensure auditd Collects File Deletion Events by User - rename", + "remarks": "rule_set_372" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_renameat2", - "remarks": "rule_set_351" + "value": "audit_rules_file_deletion_events_rename", + "remarks": "rule_set_372" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects File Deletion Events by User - renameat2", - "remarks": "rule_set_351" + "value": "Ensure auditd Collects File Deletion Events by User - rename", + "remarks": "rule_set_372" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_unlink", - "remarks": "rule_set_352" + "value": "audit_rules_file_deletion_events_renameat", + "remarks": "rule_set_373" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects File Deletion Events by User - unlink", - "remarks": "rule_set_352" + "value": "Ensure auditd Collects File Deletion Events by User - renameat", + "remarks": "rule_set_373" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_unlink", - "remarks": "rule_set_352" + "value": "audit_rules_file_deletion_events_renameat", + "remarks": "rule_set_373" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects File Deletion Events by User - unlink", - "remarks": "rule_set_352" + "value": "Ensure auditd Collects File Deletion Events by User - renameat", + "remarks": "rule_set_373" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_unlinkat", - "remarks": "rule_set_353" + "value": "audit_rules_file_deletion_events_renameat2", + "remarks": "rule_set_374" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects File Deletion Events by User - unlinkat", - "remarks": "rule_set_353" + "value": "Ensure auditd Collects File Deletion Events by User - renameat2", + "remarks": "rule_set_374" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_unlinkat", - "remarks": "rule_set_353" + "value": "audit_rules_file_deletion_events_renameat2", + "remarks": "rule_set_374" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects File Deletion Events by User - unlinkat", - "remarks": "rule_set_353" + "value": "Ensure auditd Collects File Deletion Events by User - renameat2", + "remarks": "rule_set_374" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_mac_modification_etc_selinux", - "remarks": "rule_set_354" + "remarks": "rule_set_375" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Events that Modify the System's Mandatory Access Controls (/etc/selinux)", - "remarks": "rule_set_354" + "remarks": "rule_set_375" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_mac_modification_etc_selinux", - "remarks": "rule_set_354" + "remarks": "rule_set_375" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Events that Modify the System's Mandatory Access Controls (/etc/selinux)", - "remarks": "rule_set_354" + "remarks": "rule_set_375" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_mac_modification_usr_share", - "remarks": "rule_set_355" + "remarks": "rule_set_376" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Events that Modify the System's Mandatory Access Controls in usr/share", - "remarks": "rule_set_355" + "remarks": "rule_set_376" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_mac_modification_usr_share", - "remarks": "rule_set_355" + "remarks": "rule_set_376" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Events that Modify the System's Mandatory Access Controls in usr/share", - "remarks": "rule_set_355" + "remarks": "rule_set_376" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_execution_chcon", - "remarks": "rule_set_356" + "remarks": "rule_set_377" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Any Attempts to Run chcon", - "remarks": "rule_set_356" + "remarks": "rule_set_377" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_execution_chcon", - "remarks": "rule_set_356" + "remarks": "rule_set_377" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Any Attempts to Run chcon", - "remarks": "rule_set_356" + "remarks": "rule_set_377" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_execution_setfacl", - "remarks": "rule_set_357" + "remarks": "rule_set_378" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Any Attempts to Run setfacl", - "remarks": "rule_set_357" + "remarks": "rule_set_378" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_execution_setfacl", - "remarks": "rule_set_357" + "remarks": "rule_set_378" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Any Attempts to Run setfacl", - "remarks": "rule_set_357" + "remarks": "rule_set_378" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_execution_chacl", - "remarks": "rule_set_358" + "remarks": "rule_set_379" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Any Attempts to Run chacl", - "remarks": "rule_set_358" + "remarks": "rule_set_379" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_execution_chacl", - "remarks": "rule_set_358" + "remarks": "rule_set_379" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Record Any Attempts to Run chacl", - "remarks": "rule_set_358" + "remarks": "rule_set_379" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_privileged_commands_usermod", - "remarks": "rule_set_359" + "remarks": "rule_set_380" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure auditd Collects Information on the Use of Privileged Commands - usermod", - "remarks": "rule_set_359" + "remarks": "rule_set_380" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_privileged_commands_usermod", - "remarks": "rule_set_359" + "remarks": "rule_set_380" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure auditd Collects Information on the Use of Privileged Commands - usermod", - "remarks": "rule_set_359" + "remarks": "rule_set_380" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_delete", - "remarks": "rule_set_360" + "value": "audit_rules_privileged_commands_kmod", + "remarks": "rule_set_381" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on Kernel Module Unloading - delete_module", - "remarks": "rule_set_360" + "value": "Ensure auditd Collects Information on the Use of Privileged Commands - kmod", + "remarks": "rule_set_381" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_delete", - "remarks": "rule_set_360" + "value": "audit_rules_privileged_commands_kmod", + "remarks": "rule_set_381" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on Kernel Module Unloading - delete_module", - "remarks": "rule_set_360" + "value": "Ensure auditd Collects Information on the Use of Privileged Commands - kmod", + "remarks": "rule_set_381" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_kernel_module_loading_init", + "remarks": "rule_set_382" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure auditd Collects Information on Kernel Module Loading - init_module", + "remarks": "rule_set_382" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_kernel_module_loading_init", + "remarks": "rule_set_382" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure auditd Collects Information on Kernel Module Loading - init_module", + "remarks": "rule_set_382" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_kernel_module_loading_finit", - "remarks": "rule_set_361" + "remarks": "rule_set_383" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure auditd Collects Information on Kernel Module Loading and Unloading - finit_module", - "remarks": "rule_set_361" + "remarks": "rule_set_383" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_kernel_module_loading_finit", - "remarks": "rule_set_361" + "remarks": "rule_set_383" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Ensure auditd Collects Information on Kernel Module Loading and Unloading - finit_module", - "remarks": "rule_set_361" + "remarks": "rule_set_383" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_init", - "remarks": "rule_set_362" + "value": "audit_rules_kernel_module_loading_delete", + "remarks": "rule_set_384" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on Kernel Module Loading - init_module", - "remarks": "rule_set_362" + "value": "Ensure auditd Collects Information on Kernel Module Unloading - delete_module", + "remarks": "rule_set_384" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_init", - "remarks": "rule_set_362" + "value": "audit_rules_kernel_module_loading_delete", + "remarks": "rule_set_384" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on Kernel Module Loading - init_module", - "remarks": "rule_set_362" + "value": "Ensure auditd Collects Information on Kernel Module Unloading - delete_module", + "remarks": "rule_set_384" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_query", - "remarks": "rule_set_363" + "value": "audit_rules_kernel_module_loading_create", + "remarks": "rule_set_385" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on Kernel Module Loading and Unloading - query_module", - "remarks": "rule_set_363" + "value": "Ensure auditd Collects Information on Kernel Module Unloading - create_module", + "remarks": "rule_set_385" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_query", - "remarks": "rule_set_363" + "value": "audit_rules_kernel_module_loading_create", + "remarks": "rule_set_385" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on Kernel Module Loading and Unloading - query_module", - "remarks": "rule_set_363" + "value": "Ensure auditd Collects Information on Kernel Module Unloading - create_module", + "remarks": "rule_set_385" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_privileged_commands_kmod", - "remarks": "rule_set_364" + "value": "audit_rules_kernel_module_loading_query", + "remarks": "rule_set_386" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on the Use of Privileged Commands - kmod", - "remarks": "rule_set_364" + "value": "Ensure auditd Collects Information on Kernel Module Loading and Unloading - query_module", + "remarks": "rule_set_386" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_privileged_commands_kmod", - "remarks": "rule_set_364" + "value": "audit_rules_kernel_module_loading_query", + "remarks": "rule_set_386" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on the Use of Privileged Commands - kmod", - "remarks": "rule_set_364" + "value": "Ensure auditd Collects Information on Kernel Module Loading and Unloading - query_module", + "remarks": "rule_set_386" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_immutable", - "remarks": "rule_set_365" + "remarks": "rule_set_387" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Make the auditd Configuration Immutable", - "remarks": "rule_set_365" + "remarks": "rule_set_387" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_immutable", - "remarks": "rule_set_365" + "remarks": "rule_set_387" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Make the auditd Configuration Immutable", - "remarks": "rule_set_365" + "remarks": "rule_set_387" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "directory_permissions_var_log_audit", - "remarks": "rule_set_366" + "remarks": "rule_set_388" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "System Audit Logs Must Have Mode 0750 or Less Permissive", - "remarks": "rule_set_366" + "remarks": "rule_set_388" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "directory_permissions_var_log_audit", - "remarks": "rule_set_366" + "remarks": "rule_set_388" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "System Audit Logs Must Have Mode 0750 or Less Permissive", - "remarks": "rule_set_366" + "remarks": "rule_set_388" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_var_log_audit", - "remarks": "rule_set_367" + "remarks": "rule_set_389" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "System Audit Logs Must Have Mode 0640 or Less Permissive", - "remarks": "rule_set_367" + "remarks": "rule_set_389" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_var_log_audit", - "remarks": "rule_set_367" + "remarks": "rule_set_389" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "System Audit Logs Must Have Mode 0640 or Less Permissive", - "remarks": "rule_set_367" + "remarks": "rule_set_389" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_ownership_var_log_audit_stig", - "remarks": "rule_set_368" + "remarks": "rule_set_390" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "System Audit Logs Must Be Owned By Root", - "remarks": "rule_set_368" + "remarks": "rule_set_390" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_ownership_var_log_audit_stig", - "remarks": "rule_set_368" + "remarks": "rule_set_390" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "System Audit Logs Must Be Owned By Root", - "remarks": "rule_set_368" + "remarks": "rule_set_390" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_group_ownership_var_log_audit", - "remarks": "rule_set_369" + "remarks": "rule_set_391" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "System Audit Logs Must Be Group Owned By Root", - "remarks": "rule_set_369" + "remarks": "rule_set_391" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_group_ownership_var_log_audit", - "remarks": "rule_set_369" + "remarks": "rule_set_391" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "System Audit Logs Must Be Group Owned By Root", - "remarks": "rule_set_369" + "remarks": "rule_set_391" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_audit_configuration", - "remarks": "rule_set_370" + "remarks": "rule_set_392" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Audit Configuration Files Permissions are 640 or More Restrictive", - "remarks": "rule_set_370" + "remarks": "rule_set_392" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_audit_configuration", - "remarks": "rule_set_370" + "remarks": "rule_set_392" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Audit Configuration Files Permissions are 640 or More Restrictive", - "remarks": "rule_set_370" + "remarks": "rule_set_392" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_ownership_audit_configuration", - "remarks": "rule_set_371" + "remarks": "rule_set_393" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Audit Configuration Files Must Be Owned By Root", - "remarks": "rule_set_371" + "remarks": "rule_set_393" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_ownership_audit_configuration", - "remarks": "rule_set_371" + "remarks": "rule_set_393" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Audit Configuration Files Must Be Owned By Root", - "remarks": "rule_set_371" + "remarks": "rule_set_393" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupownership_audit_configuration", - "remarks": "rule_set_372" + "remarks": "rule_set_394" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Audit Configuration Files Must Be Owned By Group root", - "remarks": "rule_set_372" + "remarks": "rule_set_394" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupownership_audit_configuration", - "remarks": "rule_set_372" + "remarks": "rule_set_394" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Audit Configuration Files Must Be Owned By Group root", - "remarks": "rule_set_372" + "remarks": "rule_set_394" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_audit_binaries", - "remarks": "rule_set_373" + "remarks": "rule_set_395" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify that audit tools Have Mode 0755 or less", - "remarks": "rule_set_373" + "remarks": "rule_set_395" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_permissions_audit_binaries", - "remarks": "rule_set_373" + "remarks": "rule_set_395" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify that audit tools Have Mode 0755 or less", - "remarks": "rule_set_373" + "remarks": "rule_set_395" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_ownership_audit_binaries", - "remarks": "rule_set_374" + "remarks": "rule_set_396" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify that audit tools are owned by root", - "remarks": "rule_set_374" + "remarks": "rule_set_396" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_ownership_audit_binaries", - "remarks": "rule_set_374" + "remarks": "rule_set_396" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify that audit tools are owned by root", - "remarks": "rule_set_374" + "remarks": "rule_set_396" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupownership_audit_binaries", - "remarks": "rule_set_375" + "remarks": "rule_set_397" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify that audit tools are owned by group root", - "remarks": "rule_set_375" + "remarks": "rule_set_397" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "file_groupownership_audit_binaries", - "remarks": "rule_set_375" + "remarks": "rule_set_397" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "Verify that audit tools are owned by group root", - "remarks": "rule_set_375" + "remarks": "rule_set_397" } ], "control-implementations": [ { - "uuid": "952d8115-758a-4cd5-b2df-c9e5ec24c539", + "uuid": "989d5a48-6b78-4492-8e24-006095b945bd", "source": "trestle://profiles/rhel10-cis_rhel10-l2_server/profile.json", "description": "REPLACE_ME", "props": [ @@ -21791,13 +21696,13 @@ { "param-id": "sshd_strong_kex", "values": [ - "cis_rhel8" + "cis_rhel10" ] }, { "param-id": "sshd_strong_macs", "values": [ - "cis_rhel8" + "cis_rhel10" ] }, { @@ -21875,1069 +21780,290 @@ { "param-id": "sysctl_net_ipv4_tcp_syncookies_value", "values": [ - "enabled" - ] - }, - { - "param-id": "sysctl_net_ipv6_conf_all_accept_ra_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv6_conf_all_accept_redirects_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv6_conf_all_accept_source_route_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv6_conf_all_forwarding_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv6_conf_default_accept_ra_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv6_conf_default_accept_redirects_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv6_conf_default_accept_source_route_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "var_account_disable_post_pw_expiration", - "values": [ - "30" - ] - }, - { - "param-id": "var_accounts_maximum_age_login_defs", - "values": [ - "365" - ] - }, - { - "param-id": "var_accounts_minimum_age_login_defs", - "values": [ - "1" - ] - }, - { - "param-id": "var_accounts_password_warn_age_login_defs", - "values": [ - "7" - ] - }, - { - "param-id": "var_accounts_passwords_pam_faillock_deny", - "values": [ - "5" - ] - }, - { - "param-id": "var_accounts_passwords_pam_faillock_dir", - "values": [ - "run" - ] - }, - { - "param-id": "var_accounts_passwords_pam_faillock_unlock_time", - "values": [ - "900" - ] - }, - { - "param-id": "var_accounts_tmout", - "values": [ - "15_min" - ] - }, - { - "param-id": "var_accounts_user_umask", - "values": [ - "027" - ] - }, - { - "param-id": "var_auditd_action_mail_acct", - "values": [ - "root" - ] - }, - { - "param-id": "var_auditd_admin_space_left_action", - "values": [ - "cis_rhel8" - ] - }, - { - "param-id": "var_auditd_disk_error_action", - "values": [ - "cis_rhel8" - ] - }, - { - "param-id": "var_auditd_disk_full_action", - "values": [ - "cis_rhel8" - ] - }, - { - "param-id": "var_auditd_max_log_file", - "values": [ - "6" - ] - }, - { - "param-id": "var_auditd_max_log_file_action", - "values": [ - "keep_logs" - ] - }, - { - "param-id": "var_auditd_space_left_action", - "values": [ - "cis_rhel8" - ] - }, - { - "param-id": "var_authselect_profile", - "values": [ - "local" - ] - }, - { - "param-id": "var_multiple_time_servers", - "values": [ - "rhel" - ] - }, - { - "param-id": "var_pam_wheel_group_for_su", - "values": [ - "cis" - ] - }, - { - "param-id": "var_password_hashing_algorithm", - "values": [ - "yescrypt" - ] - }, - { - "param-id": "var_password_hashing_algorithm_pam", - "values": [ - "yescrypt" - ] - }, - { - "param-id": "var_password_pam_dictcheck", - "values": [ - "1" - ] - }, - { - "param-id": "var_password_pam_difok", - "values": [ - "2" - ] - }, - { - "param-id": "var_password_pam_maxrepeat", - "values": [ - "3" - ] - }, - { - "param-id": "var_password_pam_minclass", - "values": [ - "4" - ] - }, - { - "param-id": "var_password_pam_minlen", - "values": [ - "14" - ] - }, - { - "param-id": "var_password_pam_remember", - "values": [ - "24" - ] - }, - { - "param-id": "var_password_pam_remember_control_flag", - "values": [ - "requisite_or_required" - ] - }, - { - "param-id": "var_postfix_inet_interfaces", - "values": [ - "loopback-only" - ] - }, - { - "param-id": "var_screensaver_lock_delay", - "values": [ - "5_seconds" - ] - }, - { - "param-id": "var_selinux_policy_name", - "values": [ - "targeted" - ] - }, - { - "param-id": "var_selinux_state", - "values": [ - "enforcing" - ] - }, - { - "param-id": "var_sshd_max_sessions", - "values": [ - "10" + "enabled" ] }, { - "param-id": "var_sshd_set_keepalive", + "param-id": "sysctl_net_ipv6_conf_all_accept_ra_value", "values": [ - "1" + "disabled" ] }, { - "param-id": "var_sshd_set_login_grace_time", + "param-id": "sysctl_net_ipv6_conf_all_accept_redirects_value", "values": [ - "60" + "disabled" ] }, { - "param-id": "var_sshd_set_maxstartups", + "param-id": "sysctl_net_ipv6_conf_all_accept_source_route_value", "values": [ - "10:30:60" + "disabled" ] }, { - "param-id": "var_system_crypto_policy", + "param-id": "sysctl_net_ipv6_conf_all_forwarding_value", "values": [ - "default_policy" + "disabled" ] }, { - "param-id": "var_user_initialization_files_regex", + "param-id": "sysctl_net_ipv6_conf_default_accept_ra_value", "values": [ - "all_dotfiles" + "disabled" ] - } - ], - "implemented-requirements": [ + }, { - "uuid": "4e9c80da-7a93-462c-86c8-460cf2421e64", - "control-id": "cis_rhel10_1-1.1.6", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_squashfs_disabled" - } + "param-id": "sysctl_net_ipv6_conf_default_accept_redirects_value", + "values": [ + "disabled" ] }, { - "uuid": "c6527a2c-4bc3-4b5c-9402-0c857b67f109", - "control-id": "cis_rhel10_1-1.1.7", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_udf_disabled" - } + "param-id": "sysctl_net_ipv6_conf_default_accept_source_route_value", + "values": [ + "disabled" ] }, { - "uuid": "5af26fda-28d8-42c7-9797-cfc2a1f6b61d", - "control-id": "cis_rhel10_1-1.2.3.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_home" - } + "param-id": "sysctl_net_ipv6_conf_default_forwarding_value", + "values": [ + "disabled" ] }, { - "uuid": "1a67897f-86a6-47d0-ae67-a7ff38545187", - "control-id": "cis_rhel10_1-1.2.4.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_var" - } + "param-id": "var_account_disable_post_pw_expiration", + "values": [ + "30" ] }, { - "uuid": "5d6bc6b2-ee74-4132-b544-38a6c38bc8fb", - "control-id": "cis_rhel10_1-1.2.5.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_var_tmp" - } + "param-id": "var_accounts_maximum_age_login_defs", + "values": [ + "365" ] }, { - "uuid": "dd95c719-290e-4c0e-8ea3-a802153cc63d", - "control-id": "cis_rhel10_1-1.2.6.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_var_log" - } + "param-id": "var_accounts_minimum_age_login_defs", + "values": [ + "1" ] }, { - "uuid": "bd6eaf27-4d74-4bd8-982d-bd617b204331", - "control-id": "cis_rhel10_1-1.2.7.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_var_log_audit" - } + "param-id": "var_accounts_password_warn_age_login_defs", + "values": [ + "7" ] }, { - "uuid": "d24b40a9-dd0b-4ddc-b8f1-0fdd825b51e2", - "control-id": "cis_rhel10_1-2.1.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } + "param-id": "var_accounts_passwords_pam_faillock_deny", + "values": [ + "5" ] }, { - "uuid": "e1d72e30-8485-4133-a347-428d8c9ffe73", - "control-id": "cis_rhel10_1-3.1.5", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "selinux_state" - } + "param-id": "var_accounts_passwords_pam_faillock_dir", + "values": [ + "run" ] }, { - "uuid": "5dff9574-8414-44c9-bb94-18217e8001dc", - "control-id": "cis_rhel10_1-3.1.6", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } + "param-id": "var_accounts_passwords_pam_faillock_unlock_time", + "values": [ + "900" ] }, { - "uuid": "34bc7ab2-84f3-4d49-b525-cf60e5dbaf9f", - "control-id": "cis_rhel10_1-8.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_gdm_removed" - } + "param-id": "var_accounts_tmout", + "values": [ + "15_min" ] }, { - "uuid": "0c3c7292-c4fa-4252-a2c3-7a9423459576", - "control-id": "cis_rhel10_2-1.20", - "description": "Review the availability of xorg-x11-server-common package when the product is out.\nThe rule also configures correct run level to prevent unbootable system.", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_gdm_removed" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "xwindows_runlevel_target" - } + "param-id": "var_accounts_user_umask", + "values": [ + "027" ] }, { - "uuid": "84c0cb11-f077-4d5b-80c0-0afd53d648f3", - "control-id": "cis_rhel10_2-2.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_openldap-clients_removed" - } + "param-id": "var_auditd_action_mail_acct", + "values": [ + "root" ] }, { - "uuid": "4e2c1b76-6734-4f87-aee7-33b3aaa5feea", - "control-id": "cis_rhel10_3-2.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_tipc_disabled" - } + "param-id": "var_auditd_admin_space_left_action", + "values": [ + "cis_rhel10" ] }, { - "uuid": "8fb451aa-0f21-401c-b046-f9d5c59860de", - "control-id": "cis_rhel10_3-2.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_sctp_disabled" - } + "param-id": "var_auditd_disk_error_action", + "values": [ + "cis_rhel10" ] }, { - "uuid": "1e38db17-3c0f-4108-ab63-91735316ad58", - "control-id": "cis_rhel10_5-1.10", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "New templated rule is necessary for \"disableforwarding\" option." - } + "param-id": "var_auditd_disk_full_action", + "values": [ + "cis_rhel10" ] }, { - "uuid": "c1dae241-fb90-42c3-aab9-a5808b9f0164", - "control-id": "cis_rhel10_5-1.11", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_gssapi_auth" - } + "param-id": "var_auditd_max_log_file", + "values": [ + "6" ] }, { - "uuid": "cb09176b-468a-4197-96db-64e4f5702b4e", - "control-id": "cis_rhel10_5-2.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_require_authentication" - } + "param-id": "var_auditd_max_log_file_action", + "values": [ + "keep_logs" ] }, { - "uuid": "bab37253-d6bf-4928-8a58-bec88c83325f", - "control-id": "cis_rhel10_5-3.3.1.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_deny_root" - } + "param-id": "var_auditd_space_left_action", + "values": [ + "cis_rhel10" ] }, { - "uuid": "33706cd5-7b41-4ced-9c92-20736743af64", - "control-id": "cis_rhel10_5-4.1.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_minimum_age_login_defs" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_set_min_life_existing" - } + "param-id": "var_authselect_profile", + "values": [ + "local" ] }, { - "uuid": "31c9f6e8-cd76-4a06-94cc-24a86ef5412a", - "control-id": "cis_rhel10_5-4.3.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary to create a new rule to check and remove nologin from /etc/shells.\nThe no_tmux_in_shells rule can be used as referece." - } + "param-id": "var_multiple_time_servers", + "values": [ + "rhel" ] }, { - "uuid": "b9f1d271-4d3f-42ee-a0ef-14d5026145f5", - "control-id": "cis_rhel10_6-3.1.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_audit_installed" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_audit-libs_installed" - } + "param-id": "var_pam_wheel_group_for_su", + "values": [ + "cis" ] }, { - "uuid": "e6e3813f-bb99-4a27-99dc-366be2ccc53d", - "control-id": "cis_rhel10_6-3.1.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "grub2_audit_argument" - } + "param-id": "var_password_hashing_algorithm", + "values": [ + "yescrypt" ] }, { - "uuid": "90235236-dfe6-4dc6-9f6e-0931a81387db", - "control-id": "cis_rhel10_6-3.1.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "grub2_audit_backlog_limit_argument" - } + "param-id": "var_password_hashing_algorithm_pam", + "values": [ + "yescrypt" ] }, { - "uuid": "b0f6655f-67a4-4388-8e50-8e4062e7bc1a", - "control-id": "cis_rhel10_6-3.1.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_auditd_enabled" - } + "param-id": "var_password_pam_dictcheck", + "values": [ + "1" ] }, { - "uuid": "8b395dba-783a-4abd-9abb-029a6246fed3", - "control-id": "cis_rhel10_6-3.2.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_retention_max_log_file" - } + "param-id": "var_password_pam_difok", + "values": [ + "2" ] }, { - "uuid": "cc52e041-50ee-4a97-8a2e-449405196301", - "control-id": "cis_rhel10_6-3.2.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_retention_max_log_file_action" - } + "param-id": "var_password_pam_maxrepeat", + "values": [ + "3" ] }, { - "uuid": "0ed6a79b-629a-49b9-aad8-c8fa007d33bf", - "control-id": "cis_rhel10_6-3.2.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_disk_error_action" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_disk_full_action" - } + "param-id": "var_password_pam_minclass", + "values": [ + "4" ] }, { - "uuid": "551aea90-afbd-4413-ab38-2b95f18ecd2b", - "control-id": "cis_rhel10_6-3.2.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_retention_action_mail_acct" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_retention_admin_space_left_action" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_retention_space_left_action" - } + "param-id": "var_password_pam_minlen", + "values": [ + "14" ] }, { - "uuid": "3d6942a8-8de6-4dd4-996e-ede0fd568ad0", - "control-id": "cis_rhel10_6-3.3.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_sysadmin_actions" - } + "param-id": "var_password_pam_remember", + "values": [ + "24" + ] + }, + { + "param-id": "var_password_pam_remember_control_flag", + "values": [ + "requisite_or_required" ] }, { - "uuid": "c694b721-313e-41d0-9541-fe6bedf81258", - "control-id": "cis_rhel10_6-3.3.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_suid_auid_privilege_function" - } + "param-id": "var_postfix_inet_interfaces", + "values": [ + "loopback-only" ] }, { - "uuid": "65ecf19f-53c2-479a-989c-86295a8563c8", - "control-id": "cis_rhel10_6-3.3.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_sudo_log_events" - } + "param-id": "var_screensaver_lock_delay", + "values": [ + "5_seconds" ] }, { - "uuid": "552c9c64-2bf6-44c5-b38f-9dfccb60edbf", - "control-id": "cis_rhel10_6-3.3.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_time_adjtimex" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_time_settimeofday" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_time_clock_settime" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_time_watch_localtime" - } + "param-id": "var_selinux_policy_name", + "values": [ + "targeted" ] }, { - "uuid": "72f29c94-6444-4d39-87ed-084beb84d3f5", - "control-id": "cis_rhel10_6-3.3.5", - "description": "These rules are not covering \"/etc/hostname\" and \"/etc/NetworkManager/\".", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_networkconfig_modification" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_networkconfig_modification_network_scripts" - } + "param-id": "var_selinux_state", + "values": [ + "enforcing" ] }, { - "uuid": "bb26e539-cc58-40fe-8312-2df0fbdb3955", - "control-id": "cis_rhel10_6-3.3.6", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_privileged_commands" - } + "param-id": "var_sshd_max_sessions", + "values": [ + "10" ] }, { - "uuid": "0b2c974a-8c53-4284-ad21-4fc2040f1fc4", - "control-id": "cis_rhel10_6-3.3.7", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_unsuccessful_file_modification_creat" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_unsuccessful_file_modification_ftruncate" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_unsuccessful_file_modification_open" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_unsuccessful_file_modification_openat" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_unsuccessful_file_modification_truncate" - } + "param-id": "var_sshd_set_keepalive", + "values": [ + "1" ] }, { - "uuid": "7ae335bf-4605-47fc-84a2-577035b2b7ff", - "control-id": "cis_rhel10_6-3.3.8", - "description": "Missing rules to check \"/etc/nsswitch.conf\", \"/etc/pam.conf\" and \"/etc/pam.d\"", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_group" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_gshadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_opasswd" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_passwd" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_shadow" - } + "param-id": "var_sshd_set_login_grace_time", + "values": [ + "60" ] }, { - "uuid": "dd3bdf0a-47b0-4f00-b97e-aa2f666ac886", - "control-id": "cis_rhel10_6-3.3.9", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_chmod" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_chown" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchmod" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchmodat" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchmodat2" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchown" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchownat" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fremovexattr" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fsetxattr" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_lchown" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_lremovexattr" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_lsetxattr" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_removexattr" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_setxattr" - } + "param-id": "var_sshd_set_maxstartups", + "values": [ + "10:30:60" + ] + }, + { + "param-id": "var_system_crypto_policy", + "values": [ + "default_policy" ] }, { - "uuid": "3d0f501a-6f22-431f-a390-a23145830f4e", - "control-id": "cis_rhel10_6-3.3.10", + "param-id": "var_user_initialization_files_regex", + "values": [ + "all_dotfiles" + ] + } + ], + "implemented-requirements": [ + { + "uuid": "cd817f67-10cb-4a45-85a1-9b6e9f47a093", + "control-id": "cis_rhel10_1-1.1.6", "description": "REPLACE_ME", "props": [ { @@ -22948,13 +22074,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_media_export" + "value": "kernel_module_overlayfs_disabled" } ] }, { - "uuid": "e6641570-9fa5-4f54-9a95-60fa730b7bdd", - "control-id": "cis_rhel10_6-3.3.11", + "uuid": "301c1c4d-e8be-48a7-8005-4ef28fad5db9", + "control-id": "cis_rhel10_1-1.1.7", "description": "REPLACE_ME", "props": [ { @@ -22965,23 +22091,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_session_events_utmp" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_session_events_btmp" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_session_events_wtmp" + "value": "kernel_module_squashfs_disabled" } ] }, { - "uuid": "7bf09430-ac22-4c7d-88c8-b05cb546d8f8", - "control-id": "cis_rhel10_6-3.3.12", + "uuid": "0dc91a3a-6f52-4397-8b4f-0a9ac771f3d2", + "control-id": "cis_rhel10_1-1.1.8", "description": "REPLACE_ME", "props": [ { @@ -22992,18 +22108,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_login_events_faillock" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_login_events_lastlog" + "value": "kernel_module_udf_disabled" } ] }, { - "uuid": "0db57dd1-1785-4a75-8ea3-7d9fdcc9d8eb", - "control-id": "cis_rhel10_6-3.3.13", + "uuid": "7d3534da-6b81-47b7-a5ff-8e0b4f80ec5d", + "control-id": "cis_rhel10_1-1.2.3.1", "description": "REPLACE_ME", "props": [ { @@ -23014,33 +22125,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_rename" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_renameat" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_renameat2" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_unlink" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_unlinkat" + "value": "partition_for_home" } ] }, { - "uuid": "17570a71-7f0b-44c9-a121-52527d33fdde", - "control-id": "cis_rhel10_6-3.3.14", + "uuid": "b0ac9ae5-893e-40c6-91af-d92f43c69cbb", + "control-id": "cis_rhel10_1-1.2.4.1", "description": "REPLACE_ME", "props": [ { @@ -23051,18 +22142,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_mac_modification_etc_selinux" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_mac_modification_usr_share" + "value": "partition_for_var" } ] }, { - "uuid": "ca6cd890-864a-4ce5-b8be-62c3c5e57d65", - "control-id": "cis_rhel10_6-3.3.15", + "uuid": "9b8215cb-465e-4d13-ab38-bcaccabb0eef", + "control-id": "cis_rhel10_1-1.2.5.1", "description": "REPLACE_ME", "props": [ { @@ -23073,13 +22159,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_execution_chcon" + "value": "partition_for_var_tmp" } ] }, { - "uuid": "424e8356-4b3d-4387-9170-0b3ef0811b17", - "control-id": "cis_rhel10_6-3.3.16", + "uuid": "17e4f54f-114f-4735-a421-4ab7cf0f2d87", + "control-id": "cis_rhel10_1-1.2.6.1", "description": "REPLACE_ME", "props": [ { @@ -23090,13 +22176,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_execution_setfacl" + "value": "partition_for_var_log" } ] }, { - "uuid": "c8052c22-ac88-465c-8887-024360de40c3", - "control-id": "cis_rhel10_6-3.3.17", + "uuid": "af6ae811-3089-4f5b-b9e7-3fbe8692e8b4", + "control-id": "cis_rhel10_1-1.2.7.1", "description": "REPLACE_ME", "props": [ { @@ -23107,30 +22193,26 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_execution_chacl" + "value": "partition_for_var_log_audit" } ] }, { - "uuid": "a8aa5f68-a538-4718-8fa3-2ca2a3c5090d", - "control-id": "cis_rhel10_6-3.3.18", + "uuid": "0f7348af-afab-45bb-8a79-b9a80a801a08", + "control-id": "cis_rhel10_1-2.1.3", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_privileged_commands_usermod" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "707991da-3012-408a-9ed1-583be62e6ad7", - "control-id": "cis_rhel10_6-3.3.19", + "uuid": "a32921ee-0fa4-4811-a451-07eb2e10b221", + "control-id": "cis_rhel10_1-3.1.5", "description": "REPLACE_ME", "props": [ { @@ -23141,33 +22223,26 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_delete" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_finit" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_init" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_query" - }, + "value": "selinux_state" + } + ] + }, + { + "uuid": "926295d8-c601-4399-87e9-0e80c2016c76", + "control-id": "cis_rhel10_1-3.1.6", + "description": "REPLACE_ME", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_privileged_commands_kmod" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "ed4cd31a-0bd4-4759-afc5-55492b38d8b5", - "control-id": "cis_rhel10_6-3.3.20", + "uuid": "ad1e56a7-0195-409f-af07-f9837e014c29", + "control-id": "cis_rhel10_1-5.3", "description": "REPLACE_ME", "props": [ { @@ -23178,13 +22253,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_immutable" + "value": "sysctl_fs_protected_symlinks" } ] }, { - "uuid": "51d69662-8260-4bac-9cbf-e44a71664e36", - "control-id": "cis_rhel10_6-3.3.21", + "uuid": "512efbe3-60b5-46e4-a53d-fd3e78e41b86", + "control-id": "cis_rhel10_1-8.6", "description": "REPLACE_ME", "props": [ { @@ -23196,8 +22271,8 @@ ] }, { - "uuid": "10b1c99e-2182-49d7-b85f-165f62cd178a", - "control-id": "cis_rhel10_6-3.4.1", + "uuid": "509c2dd5-3e5b-44ef-9ebc-b3958cdb8763", + "control-id": "cis_rhel10_2-1.3", "description": "REPLACE_ME", "props": [ { @@ -23208,14 +22283,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "directory_permissions_var_log_audit" + "value": "service_cockpit_disabled" } ] }, { - "uuid": "281e5237-83f8-49a4-a8e0-43b970f4c6df", - "control-id": "cis_rhel10_6-3.4.2", - "description": "REPLACE_ME", + "uuid": "c77a2959-bc4b-44cf-a0c1-92ae6ae4a3e9", + "control-id": "cis_rhel10_2-1.20", + "description": "Review the availability of xorg-x11-server-common package when the product is out.\nThe rule also configures correct run level to prevent unbootable system.", "props": [ { "name": "implementation-status", @@ -23225,13 +22300,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_var_log_audit" + "value": "package_gdm_removed" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "xwindows_runlevel_target" } ] }, { - "uuid": "e91959f8-469b-4d38-9bb4-11743433802a", - "control-id": "cis_rhel10_6-3.4.3", + "uuid": "2c21316c-a89d-4473-8674-90045d7fe822", + "control-id": "cis_rhel10_2-2.2", "description": "REPLACE_ME", "props": [ { @@ -23242,13 +22322,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_var_log_audit_stig" + "value": "package_openldap-clients_removed" } ] }, { - "uuid": "c06c9b78-8f72-415b-82e2-38eb5c6ad6ab", - "control-id": "cis_rhel10_6-3.4.4", + "uuid": "ed7f9227-feb9-4fb4-b372-15a2bfdc60e3", + "control-id": "cis_rhel10_5-1.8", "description": "REPLACE_ME", "props": [ { @@ -23259,13 +22339,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_group_ownership_var_log_audit" + "value": "sshd_disable_forwarding" } ] }, { - "uuid": "dbc59d3e-7861-4a3b-84a3-a32b2ba60474", - "control-id": "cis_rhel10_6-3.4.5", + "uuid": "3768a1d6-198c-454d-a112-7a26e04b8653", + "control-id": "cis_rhel10_5-1.9", "description": "REPLACE_ME", "props": [ { @@ -23276,13 +22356,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_audit_configuration" + "value": "sshd_disable_gssapi_auth" } ] }, { - "uuid": "6ba79eaa-7cc0-49e5-be2a-0a3b466d0b14", - "control-id": "cis_rhel10_6-3.4.6", + "uuid": "81fd2d99-6021-41da-b7b4-ce71839870ab", + "control-id": "cis_rhel10_5-2.4", "description": "REPLACE_ME", "props": [ { @@ -23293,13 +22373,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_audit_configuration" + "value": "sudo_require_authentication" } ] }, { - "uuid": "21c6332d-726a-4d9a-b86c-fde129462b1d", - "control-id": "cis_rhel10_6-3.4.7", + "uuid": "90d8e758-b827-42fa-8342-42b0cc54a68c", + "control-id": "cis_rhel10_5-4.1.2", "description": "REPLACE_ME", "props": [ { @@ -23310,13 +22390,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_audit_configuration" + "value": "accounts_minimum_age_login_defs" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_password_set_min_life_existing" } ] }, { - "uuid": "4940fb21-e81a-4c52-80f5-d252639f66bf", - "control-id": "cis_rhel10_6-3.4.8", + "uuid": "2c88cddb-512b-4210-9259-19f5e549b195", + "control-id": "cis_rhel10_5-4.3.1", "description": "REPLACE_ME", "props": [ { @@ -23327,13 +22412,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_audit_binaries" + "value": "no_nologin_in_shells" } ] }, { - "uuid": "2069c190-4446-4bcb-ade4-274689341ac4", - "control-id": "cis_rhel10_6-3.4.9", + "uuid": "a376744f-6822-4b9d-bb1e-c8435cfc86b1", + "control-id": "cis_rhel10_6-3.1.1", "description": "REPLACE_ME", "props": [ { @@ -23344,13 +22429,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_audit_binaries" + "value": "package_audit_installed" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "package_audit-libs_installed" } ] }, { - "uuid": "daa4d584-1232-4572-a710-eed3e1191134", - "control-id": "cis_rhel10_6-3.4.10", + "uuid": "0184c578-6a6e-4d0a-b81a-2a493ce9a45f", + "control-id": "cis_rhel10_6-3.1.2", "description": "REPLACE_ME", "props": [ { @@ -23361,27 +22451,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_audit_binaries" + "value": "grub2_audit_argument" } ] }, { - "uuid": "41bce247-5b27-4832-b651-7475071d967c", - "control-id": "cis_rhel10_7-1.14", + "uuid": "7763eafb-6af2-4e77-944b-60cfd2010d1c", + "control-id": "cis_rhel10_6-3.1.3", "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } - ] - }, - { - "uuid": "7d0eb9d8-3e78-4cc0-b98b-6ee41ba3bbf0", - "control-id": "reload_dconf_db", - "description": "This is a helper rule to reload Dconf database correctly.", "props": [ { "name": "implementation-status", @@ -23391,13 +22468,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_db_up_to_date" + "value": "grub2_audit_backlog_limit_argument" } ] }, { - "uuid": "67c31ce1-c27c-4c6c-b901-d8d8eb90e09a", - "control-id": "cis_rhel10_1-1.1.8", + "uuid": "44af9b91-8428-43ee-aa46-668ae692e828", + "control-id": "cis_rhel10_6-3.1.4", "description": "REPLACE_ME", "props": [ { @@ -23408,26 +22485,30 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_usb-storage_disabled" + "value": "service_auditd_enabled" } ] }, { - "uuid": "8f9721bb-138c-41fc-9e6b-e58d1d320b26", - "control-id": "cis_rhel10_1-1.1.9", + "uuid": "3005bad0-fe11-496d-87ea-034fc31d917d", + "control-id": "cis_rhel10_6-3.2.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "auditd_data_retention_max_log_file" } ] }, { - "uuid": "84f7b28d-10bb-430a-ac5b-8cf45d821600", - "control-id": "cis_rhel10_1-1.2.1.1", + "uuid": "dfe572c9-4951-4928-8fe0-cd3633d99529", + "control-id": "cis_rhel10_6-3.2.2", "description": "REPLACE_ME", "props": [ { @@ -23438,13 +22519,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_tmp" + "value": "auditd_data_retention_max_log_file_action" } ] }, { - "uuid": "268c2de9-cc92-42f3-9bb0-94dc48f28b73", - "control-id": "cis_rhel10_1-1.2.1.2", + "uuid": "d048c057-b8bd-41b9-8521-de6e890051ee", + "control-id": "cis_rhel10_6-3.2.3", "description": "REPLACE_ME", "props": [ { @@ -23455,13 +22536,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_nodev" + "value": "auditd_data_disk_error_action" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "auditd_data_disk_full_action" } ] }, { - "uuid": "e14244f0-4968-4172-9e5d-337b9c6b1755", - "control-id": "cis_rhel10_1-1.2.1.3", + "uuid": "cf8b9dac-92ca-4c63-b89a-f55e1ae107fa", + "control-id": "cis_rhel10_6-3.2.4", "description": "REPLACE_ME", "props": [ { @@ -23472,30 +22558,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_nosuid" - } - ] - }, - { - "uuid": "c1df7d81-2c2c-4a54-bcf2-c82f9949dc83", - "control-id": "cis_rhel10_1-1.2.1.4", - "description": "REPLACE_ME", - "props": [ + "value": "auditd_data_retention_action_mail_acct" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "auditd_data_retention_admin_space_left_action" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_noexec" + "value": "auditd_data_retention_space_left_action" } ] }, { - "uuid": "9a6220e3-2712-4396-882a-1782681216d3", - "control-id": "cis_rhel10_1-1.2.2.1", + "uuid": "f9692069-ffac-48fb-8f88-684aa11c8841", + "control-id": "cis_rhel10_6-3.3.1", "description": "REPLACE_ME", "props": [ { @@ -23506,13 +22585,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_dev_shm" + "value": "audit_rules_sysadmin_actions" } ] }, { - "uuid": "0a78986b-d2ce-4a11-a61b-fa7d3a1b20eb", - "control-id": "cis_rhel10_1-1.2.2.2", + "uuid": "c3d6c485-d8f6-48a7-b954-b2cbcc108e49", + "control-id": "cis_rhel10_6-3.3.2", "description": "REPLACE_ME", "props": [ { @@ -23523,13 +22602,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_nodev" + "value": "audit_rules_suid_auid_privilege_function" } ] }, { - "uuid": "394b0de4-2552-4f45-9a9a-a923d3146dd9", - "control-id": "cis_rhel10_1-1.2.2.3", + "uuid": "5ab14f52-a19d-47d9-86e9-85261029c6a2", + "control-id": "cis_rhel10_6-3.3.3", "description": "REPLACE_ME", "props": [ { @@ -23540,13 +22619,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_nosuid" + "value": "audit_sudo_log_events" } ] }, { - "uuid": "350ba021-b0e8-40e0-b698-9617554b00f0", - "control-id": "cis_rhel10_1-1.2.2.4", + "uuid": "75e9ad80-91e7-4172-bafd-aea62902c45f", + "control-id": "cis_rhel10_6-3.3.4", "description": "REPLACE_ME", "props": [ { @@ -23557,47 +22636,40 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_noexec" - } - ] - }, - { - "uuid": "d878e2c9-a8cd-4e0b-964e-4d9a0773473d", - "control-id": "cis_rhel10_1-1.2.3.2", - "description": "REPLACE_ME", - "props": [ + "value": "audit_rules_time_adjtimex" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "audit_rules_time_settimeofday" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_home_nodev" + "value": "audit_rules_time_clock_settime" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_time_watch_localtime" } ] }, { - "uuid": "f747447d-ade2-495f-b2a1-558cb22687de", - "control-id": "cis_rhel10_1-1.2.3.3", - "description": "REPLACE_ME", + "uuid": "9135a226-c00b-484b-928f-44e327ddb791", + "control-id": "cis_rhel10_6-3.3.5", + "description": "This requirement is covered by 6.3.3.6.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_home_nosuid" } ] }, { - "uuid": "19dd8d13-bb3a-4498-b139-4ed7367351d9", - "control-id": "cis_rhel10_1-1.2.4.2", + "uuid": "6d9bf8d2-8b66-4ffb-9e7c-71819f57e0df", + "control-id": "cis_rhel10_6-3.3.6", "description": "REPLACE_ME", "props": [ { @@ -23608,31 +22680,26 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_nodev" + "value": "audit_rules_networkconfig_modification" } ] }, { - "uuid": "9251640c-bf98-415f-bc43-29c6ff53d0e1", - "control-id": "cis_rhel10_1-1.2.4.3", - "description": "REPLACE_ME", + "uuid": "bb240730-b979-46ce-be84-8821d1f996bd", + "control-id": "cis_rhel10_6-3.3.7", + "description": "This requirement is partially covered by 6.3.3.6.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_nosuid" } ] }, { - "uuid": "45ebec68-be23-45d3-a3b1-87ee98c44445", - "control-id": "cis_rhel10_1-1.2.5.2", - "description": "REPLACE_ME", + "uuid": "e2d46538-89a9-45d4-9658-8c2e59e4fef6", + "control-id": "cis_rhel10_6-3.3.8", + "description": "This requirement is partially covered by 6.3.3.6.", "props": [ { "name": "implementation-status", @@ -23642,30 +22709,25 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_tmp_nodev" + "value": "audit_rules_networkconfig_modification_network_scripts" } ] }, { - "uuid": "583a26ee-8394-4bc3-9470-6a1e1abefb1a", - "control-id": "cis_rhel10_1-1.2.5.3", - "description": "REPLACE_ME", + "uuid": "50f811ae-a6d3-489a-98c7-ff8fb1b1212d", + "control-id": "cis_rhel10_6-3.3.9", + "description": "This requirement is covered by 6.3.3.6.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_tmp_nosuid" } ] }, { - "uuid": "236599ec-db09-4a54-a772-77d01248a2f6", - "control-id": "cis_rhel10_1-1.2.5.4", + "uuid": "430e07b6-b219-4a0e-bd7b-8dfdb011a2e9", + "control-id": "cis_rhel10_6-3.3.10", "description": "REPLACE_ME", "props": [ { @@ -23676,13 +22738,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_tmp_noexec" + "value": "audit_rules_privileged_commands" } ] }, { - "uuid": "e4ceba95-943f-450a-b551-2a91c5218a31", - "control-id": "cis_rhel10_1-1.2.6.2", + "uuid": "58eac820-05e3-456f-b901-d69ee17b041d", + "control-id": "cis_rhel10_6-3.3.11", "description": "REPLACE_ME", "props": [ { @@ -23693,47 +22755,33 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_nodev" - } - ] - }, - { - "uuid": "5586577c-3709-444e-88b6-1d8408b29b64", - "control-id": "cis_rhel10_1-1.2.6.3", - "description": "REPLACE_ME", - "props": [ + "value": "audit_rules_unsuccessful_file_modification_creat" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "audit_rules_unsuccessful_file_modification_ftruncate" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_nosuid" - } - ] - }, - { - "uuid": "983b646a-43bf-4107-921b-9a510c2a1ae6", - "control-id": "cis_rhel10_1-1.2.6.4", - "description": "REPLACE_ME", - "props": [ + "value": "audit_rules_unsuccessful_file_modification_open" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "audit_rules_unsuccessful_file_modification_openat" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_noexec" + "value": "audit_rules_unsuccessful_file_modification_truncate" } ] }, { - "uuid": "6dbd4b33-c3f2-44ac-908f-4a1169ce5a7e", - "control-id": "cis_rhel10_1-1.2.7.2", + "uuid": "af132724-37b0-4069-8d1b-17bc39ae5f6d", + "control-id": "cis_rhel10_6-3.3.12", "description": "REPLACE_ME", "props": [ { @@ -23744,13 +22792,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_audit_nodev" + "value": "audit_rules_usergroup_modification_group" } ] }, { - "uuid": "d3db2479-0c41-4e7b-9527-bace0a34a6f5", - "control-id": "cis_rhel10_1-1.2.7.3", + "uuid": "cdd7eaa3-e96f-4ce3-a1b3-9b1aca65f072", + "control-id": "cis_rhel10_6-3.3.13", "description": "REPLACE_ME", "props": [ { @@ -23761,13 +22809,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_audit_nosuid" + "value": "audit_rules_usergroup_modification_passwd" } ] }, { - "uuid": "df6f2a66-744a-4e80-b454-cabb40f5bd4a", - "control-id": "cis_rhel10_1-1.2.7.4", + "uuid": "2d4f41a6-e7f5-42ff-9c8a-2a38184d5cff", + "control-id": "cis_rhel10_6-3.3.14", "description": "REPLACE_ME", "props": [ { @@ -23778,26 +22826,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_audit_noexec" - } - ] - }, - { - "uuid": "2a47160c-7129-416f-bec5-0a1a81c17f77", - "control-id": "cis_rhel10_1-2.1.1", - "description": "REPLACE_ME", - "props": [ + "value": "audit_rules_usergroup_modification_gshadow" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "audit_rules_usergroup_modification_shadow" } ] }, { - "uuid": "3fb51377-567c-41d3-8cb8-fe6d5f1051c2", - "control-id": "cis_rhel10_1-2.1.2", + "uuid": "fc1ce29a-dbf3-4fee-b44b-f7a078c61c7f", + "control-id": "cis_rhel10_6-3.3.15", "description": "REPLACE_ME", "props": [ { @@ -23808,13 +22848,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_gpgcheck_globally_activated" + "value": "audit_rules_usergroup_modification_opasswd" } ] }, { - "uuid": "ce753121-bdde-4793-8560-72a42518dc46", - "control-id": "cis_rhel10_1-2.1.4", + "uuid": "d52cef00-8c15-4120-95b1-336f2bd8da9f", + "control-id": "cis_rhel10_6-3.3.16", "description": "REPLACE_ME", "props": [ { @@ -23826,8 +22866,8 @@ ] }, { - "uuid": "fef2fef8-75cb-4ea9-ba99-a0aa49235f03", - "control-id": "cis_rhel10_1-2.2.1", + "uuid": "d636ff8c-c43f-4c7f-a27e-49480573df83", + "control-id": "cis_rhel10_6-3.3.17", "description": "REPLACE_ME", "props": [ { @@ -23839,8 +22879,8 @@ ] }, { - "uuid": "9c14fdda-b5d2-4c44-a7dc-0ba66315304c", - "control-id": "cis_rhel10_1-3.1.1", + "uuid": "4132ec13-5acb-4088-8a26-83324f18bc15", + "control-id": "cis_rhel10_6-3.3.18", "description": "REPLACE_ME", "props": [ { @@ -23851,64 +22891,28 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_libselinux_installed" - } - ] - }, - { - "uuid": "1efddc3c-cd36-47b7-af55-9d2b1750913f", - "control-id": "cis_rhel10_1-3.1.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "audit_rules_dac_modification_chmod" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "grub2_enable_selinux" - } - ] - }, - { - "uuid": "a5d22477-0485-4382-b9f5-e4bb052b1886", - "control-id": "cis_rhel10_1-3.1.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "audit_rules_dac_modification_fchmod" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "selinux_policytype" - } - ] - }, - { - "uuid": "77377076-afc5-424b-ab4d-ede2210fff3d", - "control-id": "cis_rhel10_1-3.1.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "audit_rules_dac_modification_fchmodat" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "selinux_not_disabled" + "value": "audit_rules_dac_modification_fchmodat2" } ] }, { - "uuid": "0e0344da-5560-417c-b813-ad93692894c0", - "control-id": "cis_rhel10_1-3.1.7", + "uuid": "7317252b-a680-4bc6-8557-39ec9e210098", + "control-id": "cis_rhel10_6-3.3.19", "description": "REPLACE_ME", "props": [ { @@ -23919,91 +22923,71 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_mcstrans_removed" - } - ] - }, - { - "uuid": "079f8aef-7513-44f8-8963-bd0f8a20f2ad", - "control-id": "cis_rhel10_1-3.1.8", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "audit_rules_dac_modification_chown" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_setroubleshoot_removed" - } - ] - }, - { - "uuid": "357e9e1b-1623-4860-a28d-2b31632f34ac", - "control-id": "cis_rhel10_1-4.1", - "description": "There is no automated remediation for this rule and this is intentional.\nMore details in the rule description.", - "props": [ + "value": "audit_rules_dac_modification_fchown" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "audit_rules_dac_modification_fchownat" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "grub2_password" + "value": "audit_rules_dac_modification_lchown" } ] }, { - "uuid": "52a6682d-f7f9-40f1-8111-ab48c704cf9f", - "control-id": "cis_rhel10_1-4.2", + "uuid": "c92a9704-0726-40cd-855d-cb7578fd5cfd", + "control-id": "cis_rhel10_6-3.3.20", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "This requirement demands a deeper review of the rules." + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_grub2_cfg" + "value": "audit_rules_dac_modification_fremovexattr" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_grub2_cfg" + "value": "audit_rules_dac_modification_fsetxattr" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_grub2_cfg" + "value": "audit_rules_dac_modification_lremovexattr" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_user_cfg" + "value": "audit_rules_dac_modification_lsetxattr" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_user_cfg" + "value": "audit_rules_dac_modification_removexattr" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_user_cfg" + "value": "audit_rules_dac_modification_setxattr" } ] }, { - "uuid": "09e400f9-a92a-43fe-9fea-2e8769ca421f", - "control-id": "cis_rhel10_1-5.1", - "description": "Address Space Layout Randomization (ASLR)", + "uuid": "11952dfb-f842-4cc7-be1e-737cc4c19d41", + "control-id": "cis_rhel10_6-3.3.21", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -24013,13 +22997,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_kernel_randomize_va_space" + "value": "audit_rules_media_export" } ] }, { - "uuid": "e2854361-a896-4033-b0d3-a575d4384278", - "control-id": "cis_rhel10_1-5.2", + "uuid": "dda9a0e7-64f7-4e9a-bb54-107ebe32c63e", + "control-id": "cis_rhel10_6-3.4.1", "description": "REPLACE_ME", "props": [ { @@ -24030,13 +23014,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_kernel_yama_ptrace_scope" + "value": "directory_permissions_var_log_audit" } ] }, { - "uuid": "4d807955-466e-4fb5-8e57-1a0c86c173d8", - "control-id": "cis_rhel10_1-5.3", + "uuid": "771fcb16-07fc-4bb3-a141-d74fd7e3bd29", + "control-id": "cis_rhel10_6-3.4.2", "description": "REPLACE_ME", "props": [ { @@ -24047,13 +23031,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_backtraces" + "value": "file_permissions_var_log_audit" } ] }, { - "uuid": "6c9c3b07-9e73-4646-ba3c-f22d37c1ceb4", - "control-id": "cis_rhel10_1-5.4", + "uuid": "8e8cddfc-b152-4b66-9873-b57c88c9658a", + "control-id": "cis_rhel10_6-3.4.3", "description": "REPLACE_ME", "props": [ { @@ -24064,13 +23048,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_storage" + "value": "file_ownership_var_log_audit_stig" } ] }, { - "uuid": "9d19865d-c63c-489b-8615-d296e1a56741", - "control-id": "cis_rhel10_1-6.1", + "uuid": "28d109d2-2428-423e-a0f0-58d245d9de03", + "control-id": "cis_rhel10_6-3.4.4", "description": "REPLACE_ME", "props": [ { @@ -24081,13 +23065,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_crypto_policy" + "value": "file_group_ownership_var_log_audit" } ] }, { - "uuid": "dd2acf68-207c-4b94-9b29-e8a9e28c7476", - "control-id": "cis_rhel10_1-6.2", + "uuid": "a74c6142-8901-4cb8-9c24-19cbe28f7466", + "control-id": "cis_rhel10_6-3.4.5", "description": "REPLACE_ME", "props": [ { @@ -24098,77 +23082,81 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_ssh_crypto_policy" + "value": "file_permissions_audit_configuration" } ] }, { - "uuid": "c6b3e3ce-752b-4abc-ba21-dcd88802f693", - "control-id": "cis_rhel10_1-6.3", - "description": "This requirement is already satisfied by 1.6.1.", + "uuid": "c8edd9ef-2ead-448a-98ce-167126d41cb2", + "control-id": "cis_rhel10_6-3.4.6", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - } - ] - }, - { - "uuid": "c782d50d-1730-4c32-a7da-3d87c6737ae3", - "control-id": "cis_rhel10_1-6.4", - "description": "REPLACE_ME", - "props": [ + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary a new rule to ensure a module disabling weak MACs in\n/etc/crypto-policies/policies/modules/ so it can be used by update-crypto-policies command." + "value": "file_ownership_audit_configuration" } ] }, { - "uuid": "ee232940-0f51-4168-aa10-e1b79d2b382d", - "control-id": "cis_rhel10_1-6.5", + "uuid": "1c7949de-c8f5-4787-b9e1-7298e38f9333", + "control-id": "cis_rhel10_6-3.4.7", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary a new rule to ensure a module disabling CBC in\n/etc/crypto-policies/policies/modules/ so it can be used by update-crypto-policies command." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_groupownership_audit_configuration" } ] }, { - "uuid": "af947e91-593d-4fc8-a50d-db24a6f579a3", - "control-id": "cis_rhel10_1-6.6", + "uuid": "ee9646ac-381a-4514-b308-ce726bf69f7d", + "control-id": "cis_rhel10_6-3.4.8", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_audit_binaries" } ] }, { - "uuid": "eda1361a-8ffe-4468-90e0-8e46bbd49d65", - "control-id": "cis_rhel10_1-6.7", + "uuid": "0cd5f6a0-4003-4521-82fe-86fd8f282ada", + "control-id": "cis_rhel10_6-3.4.9", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_ownership_audit_binaries" } ] }, { - "uuid": "3b1fb7ce-1ca2-4265-9bd8-9d353eee3642", - "control-id": "cis_rhel10_1-7.1", + "uuid": "ea1aba03-70f5-42e9-9143-215f53c560dd", + "control-id": "cis_rhel10_6-3.4.10", "description": "REPLACE_ME", "props": [ { @@ -24179,14 +23167,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "banner_etc_motd_cis" + "value": "file_groupownership_audit_binaries" } ] }, { - "uuid": "033cc20c-339c-47f2-a487-b8077afd9e54", - "control-id": "cis_rhel10_1-7.2", - "description": "REPLACE_ME", + "uuid": "0a0eb696-6fc7-414b-8725-db98aa997222", + "control-id": "reload_dconf_db", + "description": "This is a helper rule to reload Dconf database correctly.", "props": [ { "name": "implementation-status", @@ -24196,13 +23184,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "banner_etc_issue_cis" + "value": "dconf_db_up_to_date" } ] }, { - "uuid": "33c39d14-cd2e-44a3-ac74-2a0d8bad6347", - "control-id": "cis_rhel10_1-7.3", + "uuid": "6f693159-6eec-4186-8bcd-8faab7c604d0", + "control-id": "cis_rhel10_1-1.1.9", "description": "REPLACE_ME", "props": [ { @@ -24213,13 +23201,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "banner_etc_issue_net_cis" + "value": "kernel_module_firewire-core_disabled" } ] }, { - "uuid": "553f3e6a-af2e-4242-8b4c-1a693318846c", - "control-id": "cis_rhel10_1-7.4", + "uuid": "cf77063b-4b3f-40ad-955b-63c01a1d2518", + "control-id": "cis_rhel10_1-1.2.1.1", "description": "REPLACE_ME", "props": [ { @@ -24230,23 +23218,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_motd" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_motd" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_motd" + "value": "partition_for_tmp" } ] }, { - "uuid": "ff894049-5fbc-4be0-a065-33a54a91e5cf", - "control-id": "cis_rhel10_1-7.5", + "uuid": "f685234b-bd7e-45c0-840d-dccb40fe239c", + "control-id": "cis_rhel10_1-1.2.1.2", "description": "REPLACE_ME", "props": [ { @@ -24257,23 +23235,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_issue" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_issue" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_issue" + "value": "mount_option_tmp_nodev" } ] }, { - "uuid": "535ccc93-9155-422f-9bc8-a7473a8f258a", - "control-id": "cis_rhel10_1-7.6", + "uuid": "96fe1a81-bff7-4731-ab33-40893caaa8b8", + "control-id": "cis_rhel10_1-1.2.1.3", "description": "REPLACE_ME", "props": [ { @@ -24284,23 +23252,30 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_issue_net" - }, + "value": "mount_option_tmp_nosuid" + } + ] + }, + { + "uuid": "3becf1a3-6be1-40b8-bfca-e3633f4785b4", + "control-id": "cis_rhel10_1-1.2.1.4", + "description": "REPLACE_ME", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_issue_net" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_issue_net" + "value": "mount_option_tmp_noexec" } ] }, { - "uuid": "fd0500ff-aabe-448a-a1ed-ff27d7277e2c", - "control-id": "cis_rhel10_1-8.2", + "uuid": "885c6f0e-c730-4519-b137-0a17fd8ee4fb", + "control-id": "cis_rhel10_1-1.2.2.1", "description": "REPLACE_ME", "props": [ { @@ -24311,18 +23286,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_banner_enabled" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_login_banner_text" + "value": "partition_for_dev_shm" } ] }, { - "uuid": "852aae40-62b7-4191-b3f9-6815a6486bef", - "control-id": "cis_rhel10_1-8.3", + "uuid": "015f0f1c-6d03-48c1-adc6-44f3dfca1855", + "control-id": "cis_rhel10_1-1.2.2.2", "description": "REPLACE_ME", "props": [ { @@ -24333,13 +23303,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_user_list" + "value": "mount_option_dev_shm_nodev" } ] }, { - "uuid": "67719e24-2ee6-4413-b7f4-1cb4ee7bd2f0", - "control-id": "cis_rhel10_1-8.4", + "uuid": "ee936e40-b4a0-496b-8869-d4a854bb39ba", + "control-id": "cis_rhel10_1-1.2.2.3", "description": "REPLACE_ME", "props": [ { @@ -24350,18 +23320,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_screensaver_idle_delay" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_screensaver_lock_delay" + "value": "mount_option_dev_shm_nosuid" } ] }, { - "uuid": "3649163b-b671-4e26-b899-24e85e4d7c9b", - "control-id": "cis_rhel10_1-8.5", + "uuid": "b2cc5113-4c62-4843-90bc-ed6f4a5364cb", + "control-id": "cis_rhel10_1-1.2.2.4", "description": "REPLACE_ME", "props": [ { @@ -24372,18 +23337,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_session_idle_user_locks" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_screensaver_user_locks" + "value": "mount_option_dev_shm_noexec" } ] }, { - "uuid": "cef293bd-43bd-4739-ac09-f0d44c0f24da", - "control-id": "cis_rhel10_1-8.6", + "uuid": "a3f673b9-2f06-44c9-a06d-d1bcb00de787", + "control-id": "cis_rhel10_1-1.2.3.2", "description": "REPLACE_ME", "props": [ { @@ -24394,18 +23354,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_automount" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_automount_open" + "value": "mount_option_home_nodev" } ] }, { - "uuid": "386f569e-600f-4f06-b8bf-2af855d91df0", - "control-id": "cis_rhel10_1-8.7", + "uuid": "d5516288-8924-488b-a67d-b5bae4e05de5", + "control-id": "cis_rhel10_1-1.2.3.3", "description": "REPLACE_ME", "props": [ { @@ -24416,18 +23371,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_automount" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_automount_open" + "value": "mount_option_home_nosuid" } ] }, { - "uuid": "371decf0-9b25-4bd0-a37d-4a8449560024", - "control-id": "cis_rhel10_1-8.8", + "uuid": "0d3ec028-fe55-4626-a42c-73cee8781c54", + "control-id": "cis_rhel10_1-1.2.4.2", "description": "REPLACE_ME", "props": [ { @@ -24438,13 +23388,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_autorun" + "value": "mount_option_var_nodev" } ] }, { - "uuid": "58e147ab-2321-4b0c-a750-167ef680cfd3", - "control-id": "cis_rhel10_1-8.9", + "uuid": "e39a38a8-83ae-45d0-8a07-70b8f0831d0d", + "control-id": "cis_rhel10_1-1.2.4.3", "description": "REPLACE_ME", "props": [ { @@ -24455,25 +23405,30 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_autorun" + "value": "mount_option_var_nosuid" } ] }, { - "uuid": "21566f72-b196-4f53-a4d8-924f88b54fb5", - "control-id": "cis_rhel10_1-8.10", - "description": "This was inherited from the RHEL 9 profile.\nHowever, it was reported that XDMCP is no\nlonger in RHEL 10.", + "uuid": "79887ebe-ed64-44a2-8115-5a003eed1d9b", + "control-id": "cis_rhel10_1-1.2.5.2", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "mount_option_var_tmp_nodev" } ] }, { - "uuid": "cb829f15-5aa9-477c-8bf9-d2efacdab87d", - "control-id": "cis_rhel10_2-1.1", + "uuid": "f67673d1-23c4-40b6-8f2e-a52ac1e42fac", + "control-id": "cis_rhel10_1-1.2.5.3", "description": "REPLACE_ME", "props": [ { @@ -24484,13 +23439,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_autofs_disabled" + "value": "mount_option_var_tmp_nosuid" } ] }, { - "uuid": "bc2c7d59-2c7a-44e8-bdb9-ce9ad9f2cf86", - "control-id": "cis_rhel10_2-1.2", + "uuid": "014ea74a-e308-40f7-bcaf-d6a5a1a994d5", + "control-id": "cis_rhel10_1-1.2.5.4", "description": "REPLACE_ME", "props": [ { @@ -24501,13 +23456,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_avahi-daemon_disabled" + "value": "mount_option_var_tmp_noexec" } ] }, { - "uuid": "bb27dfeb-e17c-4f04-8653-ddfd63de9d98", - "control-id": "cis_rhel10_2-1.3", + "uuid": "eb985ba2-65b2-4b7c-9146-ec6bde273741", + "control-id": "cis_rhel10_1-1.2.6.2", "description": "REPLACE_ME", "props": [ { @@ -24518,13 +23473,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_kea_removed" + "value": "mount_option_var_log_nodev" } ] }, { - "uuid": "bc4b1edf-4c10-4bf7-9b6b-814168ab5dbe", - "control-id": "cis_rhel10_2-1.4", + "uuid": "e1b97698-2acb-4558-b099-1f64134f61bf", + "control-id": "cis_rhel10_1-1.2.6.3", "description": "REPLACE_ME", "props": [ { @@ -24535,13 +23490,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_bind_removed" + "value": "mount_option_var_log_nosuid" } ] }, { - "uuid": "811bd010-e38e-4a2c-89f7-15ea7c853e91", - "control-id": "cis_rhel10_2-1.5", + "uuid": "f6ff539a-e522-416d-98cd-014ed9f0fea3", + "control-id": "cis_rhel10_1-1.2.6.4", "description": "REPLACE_ME", "props": [ { @@ -24552,13 +23507,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_dnsmasq_removed" + "value": "mount_option_var_log_noexec" } ] }, { - "uuid": "d4dfb04d-bb03-4337-8c38-c637fda734e3", - "control-id": "cis_rhel10_2-1.6", + "uuid": "eebde9e0-6419-4256-b4f9-54d34c84e4c6", + "control-id": "cis_rhel10_1-1.2.7.2", "description": "REPLACE_ME", "props": [ { @@ -24569,13 +23524,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_samba_removed" + "value": "mount_option_var_log_audit_nodev" } ] }, { - "uuid": "c7905533-a460-491e-b336-e4a2cb054595", - "control-id": "cis_rhel10_2-1.7", + "uuid": "56525b57-726f-4f10-87c6-3b7b7b65f742", + "control-id": "cis_rhel10_1-1.2.7.3", "description": "REPLACE_ME", "props": [ { @@ -24586,13 +23541,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_vsftpd_removed" + "value": "mount_option_var_log_audit_nosuid" } ] }, { - "uuid": "d5d0ac64-4afd-4816-840c-87dd1e2437c5", - "control-id": "cis_rhel10_2-1.8", + "uuid": "8021d943-b3bd-4a21-ab02-17c59e056937", + "control-id": "cis_rhel10_1-1.2.7.4", "description": "REPLACE_ME", "props": [ { @@ -24603,19 +23558,27 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_dovecot_removed" - }, + "value": "mount_option_var_log_audit_noexec" + } + ] + }, + { + "uuid": "9fe52ce3-406d-4bdc-a107-3350c133e874", + "control-id": "cis_rhel10_1-2.1.1", + "description": "REPLACE_ME", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_cyrus-imapd_removed" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "4ac118c8-dd3c-42de-ac5f-6811fd1882f2", - "control-id": "cis_rhel10_2-1.9", - "description": "Many of the libvirt packages used by Enterprise Linux virtualization are dependent on the\nnfs-utils package.", + "uuid": "edab5ea3-6617-443d-9b3a-b672abe0824e", + "control-id": "cis_rhel10_1-2.1.2", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -24625,25 +23588,39 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_nfs_disabled" + "value": "ensure_gpgcheck_globally_activated" } ] }, { - "uuid": "bbbb86be-f50b-427e-8a0c-be7546f064bf", - "control-id": "cis_rhel10_2-1.10", + "uuid": "09470a31-0b3b-42e0-a968-1ba4b2e4af2e", + "control-id": "cis_rhel10_1-2.1.4", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "781c4d74-5f90-4a51-80b7-d87b20d977b6", - "control-id": "cis_rhel10_2-1.11", + "uuid": "82cd61bd-bdac-432e-8b0e-4754938b546d", + "control-id": "cis_rhel10_1-2.2.1", + "description": "REPLACE_ME", + "props": [ + { + "name": "implementation-status", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "alternative", + "remarks": "REPLACE_ME" + } + ] + }, + { + "uuid": "5ee92c79-ad98-4fff-9a65-e99cb50f306a", + "control-id": "cis_rhel10_1-3.1.1", "description": "REPLACE_ME", "props": [ { @@ -24654,14 +23631,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_cups_disabled" + "value": "package_libselinux_installed" } ] }, { - "uuid": "c374286e-cb9f-402c-b14f-1e5209afc34b", - "control-id": "cis_rhel10_2-1.12", - "description": "Many of the libvirt packages used by Enterprise Linux virtualization, and the nfs-utils\npackage used for The Network File System (NFS), are dependent on the rpcbind package.", + "uuid": "241f4a15-54f1-46d7-9f44-f97228b536e6", + "control-id": "cis_rhel10_1-3.1.2", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -24671,13 +23648,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_rpcbind_disabled" + "value": "grub2_enable_selinux" } ] }, { - "uuid": "d2b5ed12-492d-4d0a-9d70-e66a7b0dd19d", - "control-id": "cis_rhel10_2-1.13", + "uuid": "5bc16dfa-be41-47b0-9477-2b4dd0f90c0a", + "control-id": "cis_rhel10_1-3.1.3", "description": "REPLACE_ME", "props": [ { @@ -24688,13 +23665,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_rsync_removed" + "value": "selinux_policytype" } ] }, { - "uuid": "f3f6320d-8ee5-47bd-88b5-83d10461e6ca", - "control-id": "cis_rhel10_2-1.14", + "uuid": "04abd3ce-3091-4331-8d9d-0a5ad40468cd", + "control-id": "cis_rhel10_1-3.1.4", "description": "REPLACE_ME", "props": [ { @@ -24705,13 +23682,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_net-snmp_removed" + "value": "selinux_not_disabled" } ] }, { - "uuid": "354670ca-4576-4420-a748-315bedaa0675", - "control-id": "cis_rhel10_2-1.15", + "uuid": "c6b8464d-08de-4ed3-b13b-a81e74e41e86", + "control-id": "cis_rhel10_1-3.1.7", "description": "REPLACE_ME", "props": [ { @@ -24722,13 +23699,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_telnet-server_removed" + "value": "package_mcstrans_removed" } ] }, { - "uuid": "65d3fea6-3853-44ca-8325-70b13e0c8268", - "control-id": "cis_rhel10_2-1.16", + "uuid": "c33d8819-e338-454b-aa49-c000c6eaa514", + "control-id": "cis_rhel10_1-3.1.8", "description": "REPLACE_ME", "props": [ { @@ -24739,14 +23716,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_tftp-server_removed" + "value": "package_setroubleshoot_removed" } ] }, { - "uuid": "b587d3fc-bac2-4fd0-b155-3ea4b852f80d", - "control-id": "cis_rhel10_2-1.17", - "description": "REPLACE_ME", + "uuid": "8935702d-0ee0-4be9-8903-876f74bdafcd", + "control-id": "cis_rhel10_1-4.1", + "description": "There is no automated remediation for this rule and this is intentional.\nMore details in the rule description.", "props": [ { "name": "implementation-status", @@ -24756,70 +23733,73 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_squid_removed" + "value": "grub2_password" } ] }, { - "uuid": "c84a68c8-1aa6-49ea-8619-0989f8b4ae44", - "control-id": "cis_rhel10_2-1.18", + "uuid": "15883a0e-b343-495d-889e-b8dfbd8e42bf", + "control-id": "cis_rhel10_1-4.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "alternative", + "remarks": "This requirement demands a deeper review of the rules." }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_httpd_removed" + "value": "file_groupowner_grub2_cfg" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_nginx_removed" - } - ] - }, - { - "uuid": "6b59ed98-84de-4fdd-987c-af6db9825d9d", - "control-id": "cis_rhel10_2-1.21", - "description": "The rule has_nonlocal_mta currently checks for services listening only on port 25,\nbut the policy checks also for ports 465 and 587", - "props": [ + "value": "file_owner_grub2_cfg" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "file_permissions_grub2_cfg" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "postfix_network_listening_disabled" + "value": "file_groupowner_user_cfg" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "has_nonlocal_mta" + "value": "file_owner_user_cfg" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_user_cfg" } ] }, { - "uuid": "ddb4bc53-7e63-4d9c-8ec2-2afc5fd2bce9", - "control-id": "cis_rhel10_2-1.22", + "uuid": "bef2b4c6-eec4-4b19-902c-7d853678a856", + "control-id": "cis_rhel10_1-5.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "disable_users_coredumps" } ] }, { - "uuid": "3f8dd0f1-cbef-44f9-b5bf-108caa119d9f", - "control-id": "cis_rhel10_2-2.1", + "uuid": "79046c17-4ee2-4d85-874e-3973a70c37a2", + "control-id": "cis_rhel10_1-5.2", "description": "REPLACE_ME", "props": [ { @@ -24830,25 +23810,30 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_ftp_removed" + "value": "sysctl_fs_protected_hardlinks" } ] }, { - "uuid": "b0a0f820-3786-4099-aac9-de10e9b50841", - "control-id": "cis_rhel10_2-2.3", + "uuid": "9bdab9ec-0983-47b7-932f-012064e87518", + "control-id": "cis_rhel10_1-5.4", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sysctl_fs_suid_dumpable" } ] }, { - "uuid": "8821f251-52ff-4896-b2ab-916d621c64b5", - "control-id": "cis_rhel10_2-2.4", + "uuid": "485f2cf8-2092-41b8-87ef-8f9874798fcc", + "control-id": "cis_rhel10_1-6.1", "description": "REPLACE_ME", "props": [ { @@ -24859,42 +23844,52 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_telnet_removed" + "value": "configure_crypto_policy" } ] }, { - "uuid": "a6428424-7f56-41c7-821a-491ef562a0ac", - "control-id": "cis_rhel10_2-2.5", + "uuid": "08f83c15-f246-4571-bc4f-dd1823441ba4", + "control-id": "cis_rhel10_1-6.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, + "value": "alternative", + "remarks": "It is necessary a new rule to ensure a module disabling sha1 in\n/etc/crypto-policies/policies/modules/ so it can be used by update-crypto-policies command." + } + ] + }, + { + "uuid": "9ba9c2c9-466b-4da3-a6a2-2fee85fa56f3", + "control-id": "cis_rhel10_1-6.3", + "description": "REPLACE_ME", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_tftp_removed" + "value": "alternative", + "remarks": "It is necessary a new rule to ensure a module disabling weak MACs in\n/etc/crypto-policies/policies/modules/ so it can be used by update-crypto-policies command." } ] }, { - "uuid": "45494e29-942a-4635-acf0-58698f40dcc8", - "control-id": "cis_rhel10_2-3.1", + "uuid": "86ce2768-9f7e-4653-b247-f81c4aba7ba1", + "control-id": "cis_rhel10_1-6.4", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "alternative", + "remarks": "It is necessary a new rule to ensure a module disabling CBC in\n/etc/crypto-policies/policies/modules/ so it can be used by update-crypto-policies command." } ] }, { - "uuid": "0664ab53-7363-41ab-94b9-290ca2c44065", - "control-id": "cis_rhel10_2-3.2", + "uuid": "c410f1c3-58a3-4fba-93cd-8cdbe75a65f3", + "control-id": "cis_rhel10_1-7.1", "description": "REPLACE_ME", "props": [ { @@ -24905,13 +23900,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "chronyd_specify_remote_server" + "value": "banner_etc_motd_cis" } ] }, { - "uuid": "0e8f50bf-957b-4fc6-af1e-ebfb5e44f090", - "control-id": "cis_rhel10_2-3.3", + "uuid": "d8676666-b050-4a8d-80ab-98cb9b9dec6f", + "control-id": "cis_rhel10_1-7.2", "description": "REPLACE_ME", "props": [ { @@ -24922,13 +23917,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "chronyd_run_as_chrony_user" + "value": "banner_etc_issue_cis" } ] }, { - "uuid": "06a2160e-619c-491c-a255-817267b66635", - "control-id": "cis_rhel10_2-4.1.1", + "uuid": "4255e0ab-0a39-494e-af05-f9f22752f375", + "control-id": "cis_rhel10_1-7.3", "description": "REPLACE_ME", "props": [ { @@ -24939,18 +23934,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_cron_installed" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_crond_enabled" + "value": "banner_etc_issue_net_cis" } ] }, { - "uuid": "f3ff839f-5191-4c14-9f47-90e472479af6", - "control-id": "cis_rhel10_2-4.1.2", + "uuid": "42220021-5ed6-472b-a7eb-3ab439700bca", + "control-id": "cis_rhel10_1-7.4", "description": "REPLACE_ME", "props": [ { @@ -24961,23 +23951,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_crontab" + "value": "file_groupowner_etc_motd" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_crontab" + "value": "file_owner_etc_motd" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_crontab" + "value": "file_permissions_etc_motd" } ] }, { - "uuid": "59374582-326f-47a3-b56f-ef0dce16c30f", - "control-id": "cis_rhel10_2-4.1.3", + "uuid": "96b0d550-ed2b-42d6-b8e9-72d6cfe6c8e0", + "control-id": "cis_rhel10_1-7.5", "description": "REPLACE_ME", "props": [ { @@ -24988,23 +23978,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_hourly" + "value": "file_groupowner_etc_issue" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_hourly" + "value": "file_owner_etc_issue" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_hourly" + "value": "file_permissions_etc_issue" } ] }, { - "uuid": "10851451-f75e-40e9-b4b4-3def9abd2a9a", - "control-id": "cis_rhel10_2-4.1.4", + "uuid": "fc3dd525-216d-4524-84fc-b94ef9e50179", + "control-id": "cis_rhel10_1-7.6", "description": "REPLACE_ME", "props": [ { @@ -25015,23 +24005,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_daily" + "value": "file_groupowner_etc_issue_net" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_daily" + "value": "file_owner_etc_issue_net" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_daily" + "value": "file_permissions_etc_issue_net" } ] }, { - "uuid": "41577944-a240-4d8f-9a7c-a0bfec6b00bd", - "control-id": "cis_rhel10_2-4.1.5", + "uuid": "954bbaac-38d7-46c1-83ef-832b21ab5c00", + "control-id": "cis_rhel10_1-8.1", "description": "REPLACE_ME", "props": [ { @@ -25042,23 +24032,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_weekly" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_weekly" + "value": "dconf_gnome_banner_enabled" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_weekly" + "value": "dconf_gnome_login_banner_text" } ] }, { - "uuid": "1d489e54-4e50-4ec8-aec8-1eb736b75321", - "control-id": "cis_rhel10_2-4.1.6", + "uuid": "3fb279d7-7f2a-45f2-9d2e-e6f369ca46d6", + "control-id": "cis_rhel10_1-8.2", "description": "REPLACE_ME", "props": [ { @@ -25069,23 +24054,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_monthly" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_monthly" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_monthly" + "value": "dconf_gnome_disable_user_list" } ] }, { - "uuid": "c12216b5-34d8-4f93-a1ef-8f731aaced12", - "control-id": "cis_rhel10_2-4.1.7", + "uuid": "fddc41a6-bc60-4962-b791-06e97352c10a", + "control-id": "cis_rhel10_1-8.3", "description": "REPLACE_ME", "props": [ { @@ -25096,23 +24071,28 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_d" + "value": "dconf_gnome_screensaver_idle_delay" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_d" + "value": "dconf_gnome_screensaver_lock_delay" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_d" + "value": "dconf_gnome_session_idle_user_locks" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "dconf_gnome_screensaver_user_locks" } ] }, { - "uuid": "b8d50377-33f8-4ad9-8383-1711baea086e", - "control-id": "cis_rhel10_2-4.1.8", + "uuid": "f56e49a0-f50c-44b4-941d-9e4efd80c04c", + "control-id": "cis_rhel10_1-8.4", "description": "REPLACE_ME", "props": [ { @@ -25123,78 +24103,86 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_cron_deny_not_exist" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_cron_allow_exists" + "value": "dconf_gnome_disable_automount" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_allow" - }, + "value": "dconf_gnome_disable_automount_open" + } + ] + }, + { + "uuid": "4c8331c1-bd29-4d95-b791-18b688f3d5b9", + "control-id": "cis_rhel10_1-8.5", + "description": "REPLACE_ME", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_allow" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_allow" + "value": "dconf_gnome_disable_autorun" } ] }, { - "uuid": "6c98e45a-f39b-4658-bd96-447530d01c7a", - "control-id": "cis_rhel10_2-4.2.1", - "description": "It is necessary to create a rule to ensure the existence of at.allow.\nfile_cron_allow_exists can be used as reference for a new templated rule.", + "uuid": "10e46413-fa89-42cf-b5b3-0f5dc2d2213b", + "control-id": "cis_rhel10_2-1.1", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_at_deny_not_exist" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_at_allow" - }, + "value": "service_autofs_disabled" + } + ] + }, + { + "uuid": "ad49f19f-42d1-4342-868b-fa94a96ae873", + "control-id": "cis_rhel10_2-1.2", + "description": "REPLACE_ME", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_at_allow" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_at_allow" + "value": "service_avahi-daemon_disabled" } ] }, { - "uuid": "7a7ed8a9-fc04-4a9e-bf08-bc6535fbb56b", - "control-id": "cis_rhel10_3-1.1", + "uuid": "16df9a3b-00e6-4dce-9553-fd038e32fdad", + "control-id": "cis_rhel10_2-1.4", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "package_kea_removed" } ] }, { - "uuid": "8b18cd61-8bea-48bb-9524-ef90ec086e07", - "control-id": "cis_rhel10_3-1.2", + "uuid": "db022856-6021-47ee-8c2a-bb0302eac5f4", + "control-id": "cis_rhel10_2-1.5", "description": "REPLACE_ME", "props": [ { @@ -25205,13 +24193,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "wireless_disable_interfaces" + "value": "package_bind_removed" } ] }, { - "uuid": "97b5eeed-88a6-4f14-bd62-cf865f6e6b54", - "control-id": "cis_rhel10_3-1.3", + "uuid": "c1159a47-5bd1-4967-b294-84bcb692c766", + "control-id": "cis_rhel10_2-1.6", "description": "REPLACE_ME", "props": [ { @@ -25222,13 +24210,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_bluetooth_disabled" + "value": "package_dnsmasq_removed" } ] }, { - "uuid": "d832993c-276e-47ee-944c-0cff19aabc9e", - "control-id": "cis_rhel10_3-3.1", + "uuid": "8c2619da-0e4f-46de-b61a-80b4f02dfef7", + "control-id": "cis_rhel10_2-1.7", "description": "REPLACE_ME", "props": [ { @@ -25239,18 +24227,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_ip_forward" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_forwarding" + "value": "package_vsftpd_removed" } ] }, { - "uuid": "4573d27f-e6a6-4621-a19b-762a49e81662", - "control-id": "cis_rhel10_3-3.2", + "uuid": "bb36fd80-2735-498a-b82c-b5dc399852c5", + "control-id": "cis_rhel10_2-1.8", "description": "REPLACE_ME", "props": [ { @@ -25261,19 +24244,19 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_send_redirects" + "value": "package_dovecot_removed" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_send_redirects" + "value": "package_cyrus-imapd_removed" } ] }, { - "uuid": "fe47f5c1-3b21-4541-beaf-2ef30b031e84", - "control-id": "cis_rhel10_3-3.3", - "description": "REPLACE_ME", + "uuid": "9782e88e-4dcd-4f34-8bfd-28a893d21d03", + "control-id": "cis_rhel10_2-1.9", + "description": "Many of the libvirt packages used by Enterprise Linux virtualization are dependent on the\nnfs-utils package.", "props": [ { "name": "implementation-status", @@ -25283,13 +24266,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses" + "value": "service_nfs_disabled" } ] }, { - "uuid": "2957fa21-3f6b-48a9-99f6-af83bf207a43", - "control-id": "cis_rhel10_3-3.4", + "uuid": "acc7fdf9-c2cd-4861-b9bb-bf49ee4f08bb", + "control-id": "cis_rhel10_2-1.10", "description": "REPLACE_ME", "props": [ { @@ -25300,14 +24283,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts" + "value": "service_cups_disabled" } ] }, { - "uuid": "26b9d2cb-c249-4d2a-afbd-a0cee5964ede", - "control-id": "cis_rhel10_3-3.5", - "description": "REPLACE_ME", + "uuid": "838def09-38c6-4ef2-8325-c8ca23ab5c80", + "control-id": "cis_rhel10_2-1.11", + "description": "Many of the libvirt packages used by Enterprise Linux virtualization, and the nfs-utils\npackage used for The Network File System (NFS), are dependent on the rpcbind package.", "props": [ { "name": "implementation-status", @@ -25317,28 +24300,30 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_accept_redirects" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_accept_redirects" - }, + "value": "service_rpcbind_disabled" + } + ] + }, + { + "uuid": "be31d7b7-3b5f-463e-bfad-9c82064907e2", + "control-id": "cis_rhel10_2-1.12", + "description": "REPLACE_ME", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_redirects" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_redirects" + "value": "package_rsync_removed" } ] }, { - "uuid": "821536ae-edad-4aa3-8fed-e3738ced48f3", - "control-id": "cis_rhel10_3-3.6", + "uuid": "fb14099d-796b-4c4d-919f-e1f08285952b", + "control-id": "cis_rhel10_2-1.13", "description": "REPLACE_ME", "props": [ { @@ -25349,18 +24334,30 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_secure_redirects" + "value": "package_samba_removed" + } + ] + }, + { + "uuid": "894114e0-6f95-4531-aa9d-dc019b5b7905", + "control-id": "cis_rhel10_2-1.14", + "description": "REPLACE_ME", + "props": [ + { + "name": "implementation-status", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_secure_redirects" + "value": "package_net-snmp_removed" } ] }, { - "uuid": "13e861e7-b2d2-4c50-9677-48a49cda95f7", - "control-id": "cis_rhel10_3-3.7", + "uuid": "297e3ab8-fa5c-4729-82a7-4ae7c9f94223", + "control-id": "cis_rhel10_2-1.15", "description": "REPLACE_ME", "props": [ { @@ -25371,18 +24368,30 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_rp_filter" + "value": "package_telnet-server_removed" + } + ] + }, + { + "uuid": "b7d3d434-02f9-498e-b87b-567e5f4d94f7", + "control-id": "cis_rhel10_2-1.16", + "description": "REPLACE_ME", + "props": [ + { + "name": "implementation-status", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_rp_filter" + "value": "package_tftp-server_removed" } ] }, { - "uuid": "525c35fe-6979-4278-96c8-696323155093", - "control-id": "cis_rhel10_3-3.8", + "uuid": "75efc298-461e-4402-a376-ebd841e59df2", + "control-id": "cis_rhel10_2-1.17", "description": "REPLACE_ME", "props": [ { @@ -25393,67 +24402,70 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_accept_source_route" - }, + "value": "package_squid_removed" + } + ] + }, + { + "uuid": "ee2bb4d0-79ec-45ea-a6c1-3ccf7a793f7d", + "control-id": "cis_rhel10_2-1.18", + "description": "REPLACE_ME", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_accept_source_route" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_source_route" + "value": "package_httpd_removed" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_source_route" + "value": "package_nginx_removed" } ] }, { - "uuid": "843d827c-9383-4c73-a500-8c829819388d", - "control-id": "cis_rhel10_3-3.9", - "description": "REPLACE_ME", + "uuid": "d361fa07-1acd-44e2-b0dc-805d3b7e6cf0", + "control-id": "cis_rhel10_2-1.21", + "description": "The rule has_nonlocal_mta currently checks for services listening only on port 25,\nbut the policy checks also for ports 465 and 587", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "partial" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_log_martians" + "value": "postfix_network_listening_disabled" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_log_martians" + "value": "has_nonlocal_mta" } ] }, { - "uuid": "ac103f3a-5d06-456e-96b5-85f7e588d267", - "control-id": "cis_rhel10_3-3.10", + "uuid": "ff61afed-7c47-4a9b-a59c-3d659e21bf8f", + "control-id": "cis_rhel10_2-1.22", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_tcp_syncookies" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "452cc9b4-d56f-4e2b-b3f7-a09f535a0ce6", - "control-id": "cis_rhel10_3-3.11", + "uuid": "0aaeee7e-38f5-4d21-8bd7-868fc347543a", + "control-id": "cis_rhel10_2-2.1", "description": "REPLACE_ME", "props": [ { @@ -25464,18 +24476,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_ra" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_ra" + "value": "package_ftp_removed" } ] }, { - "uuid": "5e8dc57f-0784-4182-8feb-78e34ca34513", - "control-id": "cis_rhel10_4-1.1", + "uuid": "3026efb7-360e-4fd7-bdd5-dd5b3a379c9e", + "control-id": "cis_rhel10_2-2.3", "description": "REPLACE_ME", "props": [ { @@ -25486,13 +24493,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_nftables_installed" + "value": "package_telnet_removed" } ] }, { - "uuid": "d73d1f79-135d-417d-bde6-4379094e7348", - "control-id": "cis_rhel10_4-1.2", + "uuid": "d08e8c68-942b-45c0-9ffc-269c78f9c056", + "control-id": "cis_rhel10_2-2.4", "description": "REPLACE_ME", "props": [ { @@ -25503,36 +24510,25 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_firewalld_enabled" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_firewalld_installed" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_nftables_disabled" + "value": "package_tftp_removed" } ] }, { - "uuid": "f506bc3f-221b-4892-807a-0ee77e477150", - "control-id": "cis_rhel10_4-2.1", + "uuid": "280a16b3-eaf2-49bb-9f08-532de0510633", + "control-id": "cis_rhel10_2-3.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "implemented" } ] }, { - "uuid": "8e3cd2a3-c011-48bc-9a12-7c2e4ee17a2c", - "control-id": "cis_rhel10_4-2.2", + "uuid": "d28223eb-7c1e-4c86-ae7f-27645369bfc0", + "control-id": "cis_rhel10_2-3.2", "description": "REPLACE_ME", "props": [ { @@ -25543,67 +24539,52 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "firewalld_loopback_traffic_trusted" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "firewalld_loopback_traffic_restricted" + "value": "chronyd_specify_remote_server" } ] }, { - "uuid": "7c35f0e3-ef44-489e-a6c3-a374f640772f", - "control-id": "cis_rhel10_4-3.1", - "description": "RHEL systems use firewalld for firewall management. Although nftables is the default\nback-end for firewalld, it is not recommended to use nftables directly when firewalld\nis in use. When using firewalld the base chains are installed by default.", + "uuid": "9db2b3be-8081-4e8b-ab05-459c90d41dd1", + "control-id": "cis_rhel10_2-3.3", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - } - ] - }, - { - "uuid": "e359953d-f69c-4a72-9078-45ab4a43bf4b", - "control-id": "cis_rhel10_4-3.2", - "description": "REPLACE_ME", - "props": [ + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "chronyd_run_as_chrony_user" } ] }, { - "uuid": "10f2acff-f293-46ac-9fff-8525503ef0bf", - "control-id": "cis_rhel10_4-3.3", - "description": "RHEL systems use firewalld for firewall management. Although nftables is the default\nback-end for firewalld, it is not recommended to use nftables directly when firewalld\nis in use.", + "uuid": "b3fe4d54-eed4-4402-a342-c2e45790c03b", + "control-id": "cis_rhel10_2-4.1.1", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - } - ] - }, - { - "uuid": "8e71ee57-457d-4ac4-8c09-4717c3ff123e", - "control-id": "cis_rhel10_4-3.4", - "description": "RHEL systems use firewalld for firewall management. Although nftables is the default\nback-end for firewalld, it is not recommended to use nftables directly when firewalld\nis in use.", - "props": [ + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "package_cron_installed" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "service_crond_enabled" } ] }, { - "uuid": "80255fd9-cd98-4251-813b-83f81e4236b7", - "control-id": "cis_rhel10_5-1.1", + "uuid": "9cfd8275-4f87-4c39-8f20-7111cc5dc0ac", + "control-id": "cis_rhel10_2-4.1.2", "description": "REPLACE_ME", "props": [ { @@ -25614,23 +24595,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_sshd_config" + "value": "file_groupowner_crontab" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_sshd_config" + "value": "file_owner_crontab" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_config" + "value": "file_permissions_crontab" } ] }, { - "uuid": "0705ff8a-5a59-4dd4-bd82-d814161550d0", - "control-id": "cis_rhel10_5-1.2", + "uuid": "aac69d4f-db24-4763-adfe-24010ffa9e91", + "control-id": "cis_rhel10_2-4.1.3", "description": "REPLACE_ME", "props": [ { @@ -25641,23 +24622,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_private_key" + "value": "file_groupowner_cron_hourly" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_private_key" + "value": "file_owner_cron_hourly" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_sshd_private_key" + "value": "file_permissions_cron_hourly" } ] }, { - "uuid": "3028dfde-cd67-4099-bf03-081e1794c984", - "control-id": "cis_rhel10_5-1.3", + "uuid": "8e122c84-5de0-4604-a28e-f27e3c836655", + "control-id": "cis_rhel10_2-4.1.4", "description": "REPLACE_ME", "props": [ { @@ -25668,107 +24649,91 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_pub_key" + "value": "file_groupowner_cron_daily" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_pub_key" + "value": "file_owner_cron_daily" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_sshd_pub_key" + "value": "file_permissions_cron_daily" } ] }, { - "uuid": "a16e5996-4387-47a4-a11d-5bd36390bde8", - "control-id": "cis_rhel10_5-1.4", + "uuid": "fd5a3f77-95e8-4a20-8ae2-f18558a32815", + "control-id": "cis_rhel10_2-4.1.5", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." - } - ] - }, - { - "uuid": "3042add3-431a-4458-b1fd-2c71c39b69ff", - "control-id": "cis_rhel10_5-1.5", - "description": "REPLACE_ME", - "props": [ + "value": "implemented" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." + "value": "file_groupowner_cron_weekly" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_kex" + "value": "file_owner_cron_weekly" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_cron_weekly" } ] }, { - "uuid": "05f82595-9bf5-44ed-a4fd-64daa9d5efdf", - "control-id": "cis_rhel10_5-1.6", + "uuid": "c3d9793c-5fb2-426d-8333-1f161a5bc97c", + "control-id": "cis_rhel10_2-4.1.6", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_macs" - } - ] - }, - { - "uuid": "c0c5eb05-2e36-43d1-95be-695a3f739151", - "control-id": "cis_rhel10_5-1.7", - "description": "REPLACE_ME", - "props": [ + "value": "file_groupowner_cron_monthly" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "file_owner_cron_monthly" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_limit_user_access" + "value": "file_permissions_cron_monthly" } ] }, { - "uuid": "b97b3f26-3e5b-4988-a5da-ad00ee957f05", - "control-id": "cis_rhel10_5-1.8", + "uuid": "b3eaba2e-19bb-4873-aa06-90e2922e53de", + "control-id": "cis_rhel10_2-4.1.7", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_enable_warning_banner_net" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "06ef28a1-5526-4477-b475-d3767dc4f5f6", - "control-id": "cis_rhel10_5-1.9", - "description": "The requirement gives an example of 45 seconds, but is flexible about the values. It is only\nnecessary to ensure there is a timeout configured in alignment to the site policy.", + "uuid": "284802db-3849-4dfa-862e-e7aa2d8b7364", + "control-id": "cis_rhel10_2-4.1.8", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -25778,70 +24743,69 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_idle_timeout" + "value": "file_groupowner_cron_d" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_keepalive" + "value": "file_owner_cron_d" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_cron_d" } ] }, { - "uuid": "bae9a1aa-d1d7-4aec-a7a4-d2cb1615a9a2", - "control-id": "cis_rhel10_5-1.12", - "description": "REPLACE_ME", + "uuid": "7a4c7441-de3d-4318-bd6b-1a199344e75d", + "control-id": "cis_rhel10_2-4.2.1", + "description": "It is necessary to create a rule to ensure the existence of at.allow.\nfile_cron_allow_exists can be used as reference for a new templated rule.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "partial" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "disable_host_auth" - } - ] - }, - { - "uuid": "168d6d8c-4a12-448e-9888-6c0827ff43c5", - "control-id": "cis_rhel10_5-1.13", - "description": "REPLACE_ME", - "props": [ + "value": "file_at_deny_not_exist" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "file_groupowner_at_allow" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_rhosts" + "value": "file_owner_at_allow" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_at_allow" } ] }, { - "uuid": "4d517221-735a-4639-9fee-3c9032286be9", - "control-id": "cis_rhel10_5-1.14", + "uuid": "a39f21a8-14a0-4972-8b0c-eef48667a64f", + "control-id": "cis_rhel10_3-1.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_login_grace_time" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "a3f8473b-21d0-485c-959b-6acfff863ee9", - "control-id": "cis_rhel10_5-1.15", - "description": "The CIS benchmark is not opinionated about which loglevel is selected here. Here, this\nprofile uses VERBOSE by default, as it allows for the capture of login and logout activity\nas well as key fingerprints.", + "uuid": "467dcb11-9120-4e79-b88b-9fc1e650f176", + "control-id": "cis_rhel10_3-1.2", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -25851,13 +24815,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_loglevel_verbose" + "value": "wireless_disable_interfaces" } ] }, { - "uuid": "ac52b6a4-3ece-4b2c-9e42-66978099ca25", - "control-id": "cis_rhel10_5-1.16", + "uuid": "eaf77709-fd25-47f6-82ae-78912dd3347d", + "control-id": "cis_rhel10_3-1.3", "description": "REPLACE_ME", "props": [ { @@ -25868,13 +24832,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_max_auth_tries" + "value": "service_bluetooth_disabled" } ] }, { - "uuid": "979715d0-abb6-4032-aaeb-e4df6533cc70", - "control-id": "cis_rhel10_5-1.17", + "uuid": "61f70a44-bfd7-4553-b06e-5f5c84cf00ca", + "control-id": "cis_rhel10_3-2.2", "description": "REPLACE_ME", "props": [ { @@ -25885,13 +24849,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_maxstartups" + "value": "kernel_module_can_disabled" } ] }, { - "uuid": "2e42eb5e-4a2f-458d-a36f-1253470af312", - "control-id": "cis_rhel10_5-1.18", + "uuid": "b90e9560-704d-4a1b-a2aa-2547a234d1a1", + "control-id": "cis_rhel10_3-2.4", "description": "REPLACE_ME", "props": [ { @@ -25902,13 +24866,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_max_sessions" + "value": "kernel_module_tipc_disabled" } ] }, { - "uuid": "fa21c80a-078f-479d-b717-e9649d7f44ac", - "control-id": "cis_rhel10_5-1.19", + "uuid": "6021b522-7cb7-4ce7-a248-5881051bc170", + "control-id": "cis_rhel10_4-1.1", "description": "REPLACE_ME", "props": [ { @@ -25919,30 +24883,26 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_empty_passwords" + "value": "package_firewalld_installed" } ] }, { - "uuid": "3128fc9c-ce3d-4990-aeac-b431933beee5", - "control-id": "cis_rhel10_5-1.20", + "uuid": "df1f1ff9-48ac-41f8-814b-182917747ba6", + "control-id": "cis_rhel10_4-1.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_root_login" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "25123045-2c26-44a9-9dc7-9c56d2dac4a0", - "control-id": "cis_rhel10_5-1.21", + "uuid": "8a455741-bd60-4508-9351-c37e2d33e220", + "control-id": "cis_rhel10_5-1.1", "description": "REPLACE_ME", "props": [ { @@ -25953,30 +24913,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_do_not_permit_user_env" - } - ] - }, - { - "uuid": "5e5dad77-00a1-4cfd-bb96-07dac8cee8ab", - "control-id": "cis_rhel10_5-1.22", - "description": "REPLACE_ME", - "props": [ + "value": "file_groupowner_sshd_config" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "file_owner_sshd_config" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_enable_pam" + "value": "file_permissions_sshd_config" } ] }, { - "uuid": "828ec9cb-2b9e-4b38-a83a-ef89d91659a7", - "control-id": "cis_rhel10_5-2.1", + "uuid": "f8e3af33-25f6-4342-a8fd-7ef95fd75620", + "control-id": "cis_rhel10_5-1.2", "description": "REPLACE_ME", "props": [ { @@ -25987,13 +24940,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_sudo_installed" + "value": "file_groupownership_sshd_private_key" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_ownership_sshd_private_key" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_sshd_private_key" } ] }, { - "uuid": "3408b92a-f76e-42cf-98bb-53cc5994c6f2", - "control-id": "cis_rhel10_5-2.2", + "uuid": "051ea0c6-066f-47fc-ac2d-d58464b0b665", + "control-id": "cis_rhel10_5-1.3", "description": "REPLACE_ME", "props": [ { @@ -26004,13 +24967,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_add_use_pty" + "value": "file_groupownership_sshd_pub_key" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_ownership_sshd_pub_key" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_sshd_pub_key" } ] }, { - "uuid": "cea1d9ba-e6e2-4090-aafa-c94f99875b8e", - "control-id": "cis_rhel10_5-2.3", + "uuid": "05e1a923-42a1-4461-9414-e9664a38e5be", + "control-id": "cis_rhel10_5-1.4", "description": "REPLACE_ME", "props": [ { @@ -26021,13 +24994,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_custom_logfile" + "value": "sshd_limit_user_access" } ] }, { - "uuid": "5187cf73-c23e-4976-93b8-5239b125f03b", - "control-id": "cis_rhel10_5-2.5", + "uuid": "e227f2b9-b7da-41e9-98cc-80bebb0ce9aa", + "control-id": "cis_rhel10_5-1.5", "description": "REPLACE_ME", "props": [ { @@ -26038,31 +25011,26 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_require_reauthentication" + "value": "sshd_enable_warning_banner_net" } ] }, { - "uuid": "4be75789-4c89-48c6-9bc0-7fa6b51ccfbe", - "control-id": "cis_rhel10_5-2.6", - "description": "REPLACE_ME", + "uuid": "c2a753c6-92a3-4306-893b-40c3be4116bf", + "control-id": "cis_rhel10_5-1.6", + "description": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_require_reauthentication" } ] }, { - "uuid": "15cbd733-3015-4663-a96b-a1336c53c13a", - "control-id": "cis_rhel10_5-2.7", - "description": "Members of \"wheel\" or GID 0 groups are checked by default if the group option is not set for\npam_wheel.so module. The recommendation states the group should be empty to reinforce the\nuse of \"sudo\" for privileged access. Therefore, members of these groups should be manually\nchecked or a different group should be informed.", + "uuid": "189f8e3e-331a-4da6-859c-d2d54cfbc5fe", + "control-id": "cis_rhel10_5-1.7", + "description": "The requirement gives an example of 45 seconds, but is flexible about the values. It is only\nnecessary to ensure there is a timeout configured in alignment to the site policy.", "props": [ { "name": "implementation-status", @@ -26072,75 +25040,88 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "use_pam_wheel_group_for_su" + "value": "sshd_set_idle_timeout" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_pam_wheel_group_empty" + "value": "sshd_set_keepalive" } ] }, { - "uuid": "1a42ac44-d7f4-463b-822e-cece2d5a0647", - "control-id": "cis_rhel10_5-3.1.1", + "uuid": "652752db-aa05-4e03-8cc3-3e2763e9c3f3", + "control-id": "cis_rhel10_5-1.10", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary a new rule to ensure PAM package is updated." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "disable_host_auth" } ] }, { - "uuid": "ae39f06e-1e4e-4161-83c9-92f2671c2b38", - "control-id": "cis_rhel10_5-3.1.2", + "uuid": "9bc55baf-3844-46d9-a4c5-2ac63b85fcb8", + "control-id": "cis_rhel10_5-1.11", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary a new rule to ensure authselect package is updated." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_disable_rhosts" } ] }, { - "uuid": "6c3404c2-ac6d-427c-af95-54dc70589b05", - "control-id": "cis_rhel10_5-3.1.3", + "uuid": "01ecd9a4-f692-4687-8028-22df9c398636", + "control-id": "cis_rhel10_5-1.12", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "alternative", - "remarks": "It is necessary a new rule to ensure libpwquality package is updated." + "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_pam_pwquality_installed" + "value": "sshd_use_strong_kex" } ] }, { - "uuid": "d5f1b4e5-39a0-464b-ab08-f4bb8cf72489", - "control-id": "cis_rhel10_5-3.2.1", - "description": "This requirement is hard to be automated without any specific requirement. The policy even\nstates that provided commands are examples, other custom settings might be in place and the\nsettings might be different depending on site policies. The other rules will already make\nsure there is a correct autheselect profile regardless of the existing settings. It is\nnecessary to better discuss with CIS Community.", + "uuid": "a54ab140-0b92-489d-9a3e-260a5a0bed5a", + "control-id": "cis_rhel10_5-1.13", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_set_login_grace_time" } ] }, { - "uuid": "7d508027-1a35-41b9-b252-390d81dedba5", - "control-id": "cis_rhel10_5-3.2.2", - "description": "This requirement is also indirectly satisfied by the requirement 5.3.3.1.", + "uuid": "a104024c-3395-401d-9ea3-cf0eb44f25d5", + "control-id": "cis_rhel10_5-1.14", + "description": "The CIS benchmark is not opinionated about which loglevel is selected here. Here, this\nprofile uses VERBOSE by default, as it allows for the capture of login and logout activity\nas well as key fingerprints.", "props": [ { "name": "implementation-status", @@ -26150,54 +25131,48 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_password_auth" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_system_auth" + "value": "sshd_set_loglevel_verbose" } ] }, { - "uuid": "46ffc732-0d37-466a-b6f6-cb9a661f5c29", - "control-id": "cis_rhel10_5-3.2.3", - "description": "This requirement is also indirectly satisfied by the requirement 5.3.3.2.", + "uuid": "6b538e02-eb56-49a9-89d1-dea0b9a93aef", + "control-id": "cis_rhel10_5-1.15", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "alternative", + "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_use_strong_macs" } ] }, { - "uuid": "5344b477-da32-47e2-a38f-191bb5ceea0b", - "control-id": "cis_rhel10_5-3.2.4", - "description": "The module is properly enabled by the rules mentioned in related_rules.\nRequirements in 5.3.3.3 use these rules.", + "uuid": "340164c1-5eb4-403a-8b0f-5ba36379b67a", + "control-id": "cis_rhel10_5-1.16", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - } - ] - }, - { - "uuid": "c4d598a0-a3dc-4f32-8a84-af0cf466d040", - "control-id": "cis_rhel10_5-3.2.5", - "description": "This module is always present by default. It is necessary to investigate if a new rule to\ncheck its existence needs to be created. But so far the rule no_empty_passwords, used in\n5.3.3.4 can ensure this requirement is attended.", - "props": [ + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "sshd_set_max_auth_tries" } ] }, { - "uuid": "4c299234-f473-4999-b885-5511c415a39f", - "control-id": "cis_rhel10_5-3.3.1.1", + "uuid": "c7cf2cdc-e3da-4ef2-9178-b2f49f0daea3", + "control-id": "cis_rhel10_5-1.17", "description": "REPLACE_ME", "props": [ { @@ -26208,14 +25183,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_deny" + "value": "sshd_set_maxstartups" } ] }, { - "uuid": "41fe36d7-3951-4a9f-860c-aeb7074a0478", - "control-id": "cis_rhel10_5-3.3.1.2", - "description": "The policy also accepts value 0, which means the locked accounts should be manually unlocked\nby an administrator. However, it also mentions that using value 0 can facilitate a DoS\nattack to legitimate users.", + "uuid": "57f4e08c-3930-4d49-aea5-3892ec576ad7", + "control-id": "cis_rhel10_5-1.18", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -26225,13 +25200,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_unlock_time" + "value": "sshd_set_max_sessions" } ] }, { - "uuid": "f0ec26c3-46c0-4fd1-b77e-a2a3bfdfdc7f", - "control-id": "cis_rhel10_5-3.3.2.1", + "uuid": "a76c45f6-3fe0-4638-84cc-1c2acb85c07d", + "control-id": "cis_rhel10_5-1.19", "description": "REPLACE_ME", "props": [ { @@ -26242,13 +25217,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_difok" + "value": "sshd_disable_empty_passwords" } ] }, { - "uuid": "f9b82f96-c246-49b9-adaa-c5a86e3ccab3", - "control-id": "cis_rhel10_5-3.3.2.2", + "uuid": "0986c112-c0a6-4808-81fd-f627f52e683e", + "control-id": "cis_rhel10_5-1.20", "description": "REPLACE_ME", "props": [ { @@ -26259,14 +25234,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_minlen" + "value": "sshd_disable_root_login" } ] }, { - "uuid": "07fb2783-3cce-4460-9a74-25ccece75c60", - "control-id": "cis_rhel10_5-3.3.2.3", - "description": "This requirement is expected to be manual. However, in previous versions of the policy\nit was already automated the configuration of \"minclass\" option. This posture was kept for\nRHEL 9 in this new version. Rules related to other options are informed in related_rules.\nIn short, minclass=4 alone can achieve the same result achieved by the combination of the\nother 4 options mentioned in the policy.", + "uuid": "9734b40d-e3a3-4437-bf1f-38b8f7c3f1d2", + "control-id": "cis_rhel10_5-1.21", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -26276,13 +25251,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_minclass" + "value": "sshd_do_not_permit_user_env" } ] }, { - "uuid": "4de0e11d-55da-4b67-9b23-91147082df3f", - "control-id": "cis_rhel10_5-3.3.2.4", + "uuid": "7f710025-b336-4d71-8fb6-4295e515a7f6", + "control-id": "cis_rhel10_5-1.22", "description": "REPLACE_ME", "props": [ { @@ -26293,26 +25268,30 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_maxrepeat" + "value": "sshd_enable_pam" } ] }, { - "uuid": "77ff4b18-edf3-4ece-9049-488d9a22d9e6", - "control-id": "cis_rhel10_5-3.3.2.5", + "uuid": "e779d8a4-ec62-4034-9980-413a5e5f7fb7", + "control-id": "cis_rhel10_5-2.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "planned", - "remarks": "A new templated rule and variable are necessary for the maxsequence option." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "package_sudo_installed" } ] }, { - "uuid": "e6af6b0a-17cc-45b8-a744-ed4dd2cc3db7", - "control-id": "cis_rhel10_5-3.3.2.6", + "uuid": "9ad8b5fb-aa41-4a0c-8161-4f21ef74aa86", + "control-id": "cis_rhel10_5-2.2", "description": "REPLACE_ME", "props": [ { @@ -26323,13 +25302,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_dictcheck" + "value": "sudo_add_use_pty" } ] }, { - "uuid": "655980e0-e526-4f29-b2cd-f6f4e0e92315", - "control-id": "cis_rhel10_5-3.3.2.7", + "uuid": "c53d041b-8a2b-496e-b15d-88e1b5a1bda7", + "control-id": "cis_rhel10_5-2.3", "description": "REPLACE_ME", "props": [ { @@ -26340,14 +25319,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_enforce_root" + "value": "sudo_custom_logfile" } ] }, { - "uuid": "98e0d38f-5347-40fc-bfc5-186547ec4eb6", - "control-id": "cis_rhel10_5-3.3.3.1", - "description": "Although mentioned in the section 5.3.3.3, there is no explicit requirement to configure\nretry option of pam_pwhistory. If come in the future, the rule accounts_password_pam_retry\ncan be used.", + "uuid": "ca160f54-0f60-4477-adee-e3984fc86896", + "control-id": "cis_rhel10_5-2.5", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -26357,44 +25336,31 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_pwhistory_remember_password_auth" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_pwhistory_remember_system_auth" + "value": "sudo_require_authentication" } ] }, { - "uuid": "3908011a-a42e-49c5-b876-d3e1e2b4b8bd", - "control-id": "cis_rhel10_5-3.3.3.2", + "uuid": "2c96fad7-b0bf-46cf-9071-187bd62c3164", + "control-id": "cis_rhel10_5-2.6", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "planned", - "remarks": "A new rule needs to be created to check and remediate the enforce_for_root option in\n/etc/security/pwhistory.conf. accounts_password_pam_enforce_root can be used as reference." - } - ] - }, - { - "uuid": "0b4bc25a-c7d4-4dc2-a27f-d3e009259432", - "control-id": "cis_rhel10_5-3.3.3.3", - "description": "In RHEL 9 pam_pwhistory is enabled via authselect feature, as required in 5.3.2.4. The\nfeature automatically set \"use_authok\" option. In any case, we don't have a rule to check\nthis option specifically.", - "props": [ + "value": "implemented" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "sudo_require_reauthentication" } ] }, { - "uuid": "983577d7-3d52-4745-820b-1aeb88df5161", - "control-id": "cis_rhel10_5-3.3.4.1", - "description": "The rule more specifically used in this requirement also satify the requirement 5.3.2.5.", + "uuid": "18854433-4452-4acb-98f5-107784bbc9db", + "control-id": "cis_rhel10_5-2.7", + "description": "Members of \"wheel\" or GID 0 groups are checked by default if the group option is not set for\npam_wheel.so module. The recommendation states the group should be empty to reinforce the\nuse of \"sudo\" for privileged access. Therefore, members of these groups should be manually\nchecked or a different group should be informed.", "props": [ { "name": "implementation-status", @@ -26404,27 +25370,31 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_empty_passwords" + "value": "use_pam_wheel_group_for_su" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "ensure_pam_wheel_group_empty" } ] }, { - "uuid": "3884becb-16be-4aa2-ad12-11c2dbb4a5aa", - "control-id": "cis_rhel10_5-3.3.4.2", - "description": "REPLACE_ME", + "uuid": "23a0d9b4-7803-4a44-9b95-92887f7b1745", + "control-id": "cis_rhel10_5-3.1.1", + "description": "This requirement is hard to be automated without any specific requirement. The policy even\nstates that provided commands are examples, other custom settings might be in place and the\nsettings might be different depending on site policies. The other rules will already make\nsure there is a correct autheselect profile regardless of the existing settings. It is\nnecessary to better discuss with CIS Community.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "Usage of pam_unix.so module together with \"remember\" option is deprecated and is not\nrecommened by this policy. Instead, it should be used remember option of pam_pwhistory\nmodule, as required in 5.3.3.3.1. See here for more details about pam_unix.so:\nhttps://bugzilla.redhat.com/show_bug.cgi?id=1778929\nA new rule needs to be created to remove the remember option from pam_unix module." + "value": "partial" } ] }, { - "uuid": "88494571-97a7-46b0-9c7b-6330a76dd254", - "control-id": "cis_rhel10_5-3.3.4.3", - "description": "Changes in logindefs mentioned in this requirement are more specifically covered by 5.4.1.4", + "uuid": "ea7bd3b6-468f-4356-9e3b-76efcc1d9102", + "control-id": "cis_rhel10_5-3.1.2", + "description": "This requirement is also indirectly satisfied by the requirement 5.3.2.1.", "props": [ { "name": "implementation-status", @@ -26434,29 +25404,34 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_systemauth" + "value": "account_password_pam_faillock_password_auth" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_passwordauth" + "value": "account_password_pam_faillock_system_auth" } ] }, { - "uuid": "ba8b16b2-79ba-4894-8f6d-8456caf31f11", - "control-id": "cis_rhel10_5-3.3.4.4", - "description": "In RHEL 9 pam_unix is enabled by default in all authselect profiles already with the\nuse_authtok option set. In any case, we don't have a rule to check this option specifically,\nlike in 5.3.3.3.3.", + "uuid": "e9282f79-2d22-4c02-9716-429d26a0d9f9", + "control-id": "cis_rhel10_5-3.1.3", + "description": "This requirement is also indirectly satisfied by the requirement 5.3.2.2.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "package_pam_pwquality_installed" } ] }, { - "uuid": "36bfdcef-1138-4fb0-811b-6dd2a11d151f", + "uuid": "9d97b272-7b19-48c8-bef4-d331cc6a9383", "control-id": "cis_rhel10_5-4.1.1", "description": "REPLACE_ME", "props": [ @@ -26478,7 +25453,7 @@ ] }, { - "uuid": "bd7dfa66-485f-4740-b84c-b0af73227024", + "uuid": "25486b19-a1ad-4303-9ddd-076464f4f66a", "control-id": "cis_rhel10_5-4.1.3", "description": "REPLACE_ME", "props": [ @@ -26500,7 +25475,7 @@ ] }, { - "uuid": "9196e70e-bbdc-4d55-932f-e1c378faabcf", + "uuid": "0b93ae1e-cbe7-4442-990b-48b699d7ea39", "control-id": "cis_rhel10_5-4.1.4", "description": "There's a \"new\" set of options in /etc/login.defs file to define the number of iterations\nperformed during the hashing process.", "props": [ @@ -26522,7 +25497,7 @@ ] }, { - "uuid": "684bc119-909e-4229-a876-55e5a9adeb7b", + "uuid": "5f5ab381-5224-49c0-a87a-1149aeae83ff", "control-id": "cis_rhel10_5-4.1.5", "description": "REPLACE_ME", "props": [ @@ -26544,7 +25519,7 @@ ] }, { - "uuid": "f4018032-2b29-451a-a6a0-60499dc9de6d", + "uuid": "16164c0b-dd15-48c8-9b61-bb868d8a77d7", "control-id": "cis_rhel10_5-4.1.6", "description": "REPLACE_ME", "props": [ @@ -26561,7 +25536,7 @@ ] }, { - "uuid": "dbcf49a3-d60b-42b5-809f-f70cf7b45602", + "uuid": "a9dc2fd1-0fb9-4691-9486-0a997f82a385", "control-id": "cis_rhel10_5-4.2.1", "description": "REPLACE_ME", "props": [ @@ -26578,7 +25553,7 @@ ] }, { - "uuid": "1af24409-869c-4277-acfc-1a0286c1ed10", + "uuid": "4e85b7f7-cc49-4500-88ad-7400c9fd4f33", "control-id": "cis_rhel10_5-4.2.2", "description": "The rule confirms the primary group for root, but doesn't check if any other user are also\nusing GID 0. New rule is necessary.\nThere is assessment but no automated remediation for this rule and this sounds reasonable.", "props": [ @@ -26595,20 +25570,24 @@ ] }, { - "uuid": "a105ce3c-f53a-4fe2-b900-4977c2647451", + "uuid": "ba65d77a-f916-4d31-a11c-68f91a4643ed", "control-id": "cis_rhel10_5-4.2.3", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "New rule is necessary." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "groups_no_zero_gid_except_root" } ] }, { - "uuid": "1104e437-d6f9-4789-a2b5-8c0cccecd321", + "uuid": "5d8601c4-17a3-4c58-ac44-9d633858602d", "control-id": "cis_rhel10_5-4.2.4", "description": "REPLACE_ME", "props": [ @@ -26625,7 +25604,7 @@ ] }, { - "uuid": "56d675fc-cf40-4e5d-9729-7a2b14d47bba", + "uuid": "6a7239f0-8d4e-4b22-907f-e35d8310ac77", "control-id": "cis_rhel10_5-4.2.5", "description": "REPLACE_ME", "props": [ @@ -26647,20 +25626,24 @@ ] }, { - "uuid": "d2b32875-7190-4afe-a780-c179cfa1e4e5", + "uuid": "cbec8816-7f8a-47bc-bb2d-1cf0667f88b5", "control-id": "cis_rhel10_5-4.2.6", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "There is no rule to ensure umask in /root/.bash_profile and /root/.bashrc. A new rule have\nto be created. It can be based on accounts_umask_interactive_users." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_umask_root" } ] }, { - "uuid": "f256ac04-3392-41f1-9745-2c635e687f79", + "uuid": "10a303c7-ef2c-42a1-9bde-057dad116b4e", "control-id": "cis_rhel10_5-4.2.7", "description": "REPLACE_ME", "props": [ @@ -26682,20 +25665,19 @@ ] }, { - "uuid": "44471902-2512-4154-b692-0203d182f5bf", + "uuid": "dead2fc2-d723-4349-b512-978bd4aec9ac", "control-id": "cis_rhel10_5-4.2.8", - "description": "REPLACE_ME", + "description": "New rule is necessary.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "New rule is necessary." + "value": "implemented" } ] }, { - "uuid": "516ae99c-e60d-4efc-b5cb-c451128db8f1", + "uuid": "3c5c96c3-24d8-441d-829a-c98e4085b489", "control-id": "cis_rhel10_5-4.3.2", "description": "REPLACE_ME", "props": [ @@ -26712,7 +25694,7 @@ ] }, { - "uuid": "8277cff0-f7de-4ed1-9850-f939a8bdf0e2", + "uuid": "63dd70a9-9bde-483e-9e45-01d126aa137c", "control-id": "cis_rhel10_5-4.3.3", "description": "REPLACE_ME", "props": [ @@ -26739,7 +25721,7 @@ ] }, { - "uuid": "f122a8fc-a9fe-4894-adc9-21606f74866d", + "uuid": "80d6d72d-0239-47af-8586-be0951a61408", "control-id": "cis_rhel10_6-1.1", "description": "REPLACE_ME", "props": [ @@ -26761,7 +25743,7 @@ ] }, { - "uuid": "d9c81a6a-7f9c-4b6e-a855-4d7d2cb0b5bf", + "uuid": "4f394df4-4d93-433d-bdbf-a0aab1ef436e", "control-id": "cis_rhel10_6-1.2", "description": "REPLACE_ME", "props": [ @@ -26778,7 +25760,7 @@ ] }, { - "uuid": "b3cd9333-36db-45ee-97cc-d85aa1a0b22e", + "uuid": "7568751b-090f-4de2-90b7-7b02456915ca", "control-id": "cis_rhel10_6-1.3", "description": "REPLACE_ME", "props": [ @@ -26795,7 +25777,7 @@ ] }, { - "uuid": "f77231cf-233b-424f-b95d-52088268f6b4", + "uuid": "e02cb021-880d-49fc-88ea-860b598c247d", "control-id": "cis_rhel10_6-2.1.1", "description": "REPLACE_ME", "props": [ @@ -26812,7 +25794,7 @@ ] }, { - "uuid": "4e7ee106-9840-43c7-8fee-0a44bbc5861a", + "uuid": "bdb2d699-c5e5-445c-9b36-f93bac4ff418", "control-id": "cis_rhel10_6-2.1.2", "description": "REPLACE_ME", "props": [ @@ -26825,7 +25807,7 @@ ] }, { - "uuid": "f0cd8de9-4529-452d-84b9-51c22f2fd09b", + "uuid": "78f03a6a-7681-4a34-abd5-277d5f67db7c", "control-id": "cis_rhel10_6-2.1.3", "description": "REPLACE_ME", "props": [ @@ -26838,7 +25820,7 @@ ] }, { - "uuid": "d0b76f5a-cc3b-48b1-a7c7-7d5d4f794d88", + "uuid": "d6f79747-f75b-4009-b5dc-e19d22791fdd", "control-id": "cis_rhel10_6-2.1.4", "description": "REPLACE_ME", "props": [ @@ -26851,51 +25833,55 @@ ] }, { - "uuid": "27b32574-bedf-4529-8e6e-d875a6734d7f", - "control-id": "cis_rhel10_6-2.2.1.1", + "uuid": "3024c196-8be0-4f38-9cd3-fef0af66a5ff", + "control-id": "cis_rhel10_6-2.2.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_systemd-journal-remote_installed" + "value": "alternative", + "remarks": "This rule conflicts with 6.2.3.3. More investigation is needed to properly solve this." } ] }, { - "uuid": "743cbb23-321c-4618-ba68-ab22cb7f0d26", - "control-id": "cis_rhel10_6-2.2.1.2", + "uuid": "8f479eae-a70d-47e0-91b8-3d82a00bab04", + "control-id": "cis_rhel10_6-2.2.3", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "journald_compress" } ] }, { - "uuid": "4ec173f1-6759-4f6f-8a76-d905f7a6c5bb", - "control-id": "cis_rhel10_6-2.2.1.3", + "uuid": "f9ed519f-6990-4be3-a450-092602b49ff1", + "control-id": "cis_rhel10_6-2.2.4", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "New templated rule is necessary." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "journald_storage" } ] }, { - "uuid": "4afab158-536a-4167-ba3f-208780fa73a1", - "control-id": "cis_rhel10_6-2.2.1.4", + "uuid": "2d69dfb1-f3c3-4315-bc63-73d129083a97", + "control-id": "cis_rhel10_6-2.2.1.1", "description": "REPLACE_ME", "props": [ { @@ -26906,43 +25892,39 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "socket_systemd-journal-remote_disabled" + "value": "package_systemd-journal-remote_installed" } ] }, { - "uuid": "0ac9c3b4-353f-4d9b-9786-c6c5c0efc13b", - "control-id": "cis_rhel10_6-2.2.2", + "uuid": "19431e21-53d9-49c7-9674-3eeb252f06cf", + "control-id": "cis_rhel10_6-2.2.1.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "alternative", - "remarks": "This rule conflicts with 6.2.3.3. More investigation is needed to properly solve this." + "remarks": "REPLACE_ME" } ] }, { - "uuid": "229d9491-2d3c-42b9-8151-727bbf04c12c", - "control-id": "cis_rhel10_6-2.2.3", + "uuid": "10c1e5e3-d706-4a26-b09f-8227ef49eb8d", + "control-id": "cis_rhel10_6-2.2.1.3", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_compress" + "value": "alternative", + "remarks": "New templated rule is necessary." } ] }, { - "uuid": "36fc797a-f198-4a8b-ac26-dcaefcb022a3", - "control-id": "cis_rhel10_6-2.2.4", + "uuid": "7ed4dadc-40ba-4178-bd33-04cecf8f06aa", + "control-id": "cis_rhel10_6-2.2.1.4", "description": "REPLACE_ME", "props": [ { @@ -26953,12 +25935,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_storage" + "value": "socket_systemd-journal-remote_disabled" } ] }, { - "uuid": "e8e5c5c4-ef96-48da-8063-43f5e74541f6", + "uuid": "3c780a37-9c62-4f88-8c0d-b89333555556", "control-id": "cis_rhel10_6-2.3.1", "description": "REPLACE_ME", "props": [ @@ -26970,7 +25952,7 @@ ] }, { - "uuid": "8f887ebf-6467-45db-8f82-c641eb517a7e", + "uuid": "bb29721c-fbcd-45dd-b21a-00f15f02f941", "control-id": "cis_rhel10_6-2.3.2", "description": "REPLACE_ME", "props": [ @@ -26982,7 +25964,7 @@ ] }, { - "uuid": "ca05cee0-a8d6-45b2-86b6-27fc1756008e", + "uuid": "b9b72de1-4775-4a52-b173-f0fe53b405d0", "control-id": "cis_rhel10_6-2.3.3", "description": "REPLACE_ME", "props": [ @@ -26994,7 +25976,7 @@ ] }, { - "uuid": "56a31fb1-5090-4f88-8bf4-597fd26667ed", + "uuid": "686644ee-3c49-42da-ace7-28e5388d1a18", "control-id": "cis_rhel10_6-2.3.4", "description": "REPLACE_ME", "props": [ @@ -27006,7 +25988,7 @@ ] }, { - "uuid": "4740b925-b793-412d-aa0b-e52b5ee3648d", + "uuid": "6a121291-7862-4a0d-a4b7-665169424364", "control-id": "cis_rhel10_6-2.3.5", "description": "REPLACE_ME", "props": [ @@ -27019,7 +26001,7 @@ ] }, { - "uuid": "f1bc7939-846e-4fe6-9511-ba10db8911c4", + "uuid": "7e3a9a54-aab4-4d03-b287-f65fb3674cd1", "control-id": "cis_rhel10_6-2.3.6", "description": "REPLACE_ME", "props": [ @@ -27032,7 +26014,7 @@ ] }, { - "uuid": "aebb475e-cf9e-4136-b216-807fd7d8a79a", + "uuid": "e09e6df5-7918-4058-bb4d-e2d65e5044bb", "control-id": "cis_rhel10_6-2.3.7", "description": "REPLACE_ME", "props": [ @@ -27044,7 +26026,7 @@ ] }, { - "uuid": "0b5b0917-1cd8-4df7-b61c-d93ea0295a9d", + "uuid": "40507a63-d956-49c8-85b7-deb67d10b04a", "control-id": "cis_rhel10_6-2.3.8", "description": "REPLACE_ME", "props": [ @@ -27057,7 +26039,7 @@ ] }, { - "uuid": "da9d60b1-a09c-49b8-86ed-643c982dba3f", + "uuid": "e250a39b-9996-45ab-9d4f-b8889606eda8", "control-id": "cis_rhel10_6-2.4.1", "description": "It is not harmful to run these rules even if rsyslog is not installed or active.", "props": [ @@ -27084,7 +26066,7 @@ ] }, { - "uuid": "198d9dfd-e0b5-4e15-8457-309d79bee97c", + "uuid": "48444b1b-e2a4-4a79-93e4-bedf2d640312", "control-id": "cis_rhel10_7-1.1", "description": "REPLACE_ME", "props": [ @@ -27111,7 +26093,7 @@ ] }, { - "uuid": "97af6349-8a10-4d16-bf38-4a76df3f7399", + "uuid": "a94e9bf2-f1e6-4ec3-a196-0fa4c693f072", "control-id": "cis_rhel10_7-1.2", "description": "REPLACE_ME", "props": [ @@ -27138,7 +26120,7 @@ ] }, { - "uuid": "11987de9-49b0-4d12-bd50-cc94f9cbe374", + "uuid": "ccb9a14d-4cca-4ee3-b4be-03aec2b40b29", "control-id": "cis_rhel10_7-1.3", "description": "REPLACE_ME", "props": [ @@ -27165,7 +26147,7 @@ ] }, { - "uuid": "3d03cc0d-07c1-46df-a01d-b4841cdbecdd", + "uuid": "f1f9ea55-e258-4558-996a-7d9b78fb5a79", "control-id": "cis_rhel10_7-1.4", "description": "REPLACE_ME", "props": [ @@ -27192,7 +26174,7 @@ ] }, { - "uuid": "4714f0a7-17d4-4ec4-b1cb-04ba886ad259", + "uuid": "c2162f04-498b-4676-8ba1-c0b53a3c8ed6", "control-id": "cis_rhel10_7-1.5", "description": "REPLACE_ME", "props": [ @@ -27219,7 +26201,7 @@ ] }, { - "uuid": "92c2f907-7980-4c05-97a8-2681afa55e25", + "uuid": "1ba15a11-c94f-45bc-ba85-93835dbb220c", "control-id": "cis_rhel10_7-1.6", "description": "REPLACE_ME", "props": [ @@ -27246,7 +26228,7 @@ ] }, { - "uuid": "d7c97b4e-03f5-4bf4-b5af-08753443e997", + "uuid": "8779b69a-5501-4f45-b347-8e9c9cd2d763", "control-id": "cis_rhel10_7-1.7", "description": "REPLACE_ME", "props": [ @@ -27273,7 +26255,7 @@ ] }, { - "uuid": "70e69b20-813b-4b94-a2d2-35c7419fe8a3", + "uuid": "cf7b9cad-017d-40e1-9cd3-ddde07de6492", "control-id": "cis_rhel10_7-1.8", "description": "REPLACE_ME", "props": [ @@ -27300,7 +26282,7 @@ ] }, { - "uuid": "2f8dec47-eb25-4a4a-b6fa-eea0fafa26e1", + "uuid": "d5e0c42a-e73c-4446-87e2-39f3c8343989", "control-id": "cis_rhel10_7-1.9", "description": "REPLACE_ME", "props": [ @@ -27327,14 +26309,14 @@ ] }, { - "uuid": "345630bb-4cac-4f12-a167-397cd438b331", + "uuid": "d14085c5-4d60-422e-b934-71a612630116", "control-id": "cis_rhel10_7-1.10", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "implemented" }, { "name": "Rule_Id", @@ -27344,7 +26326,7 @@ ] }, { - "uuid": "b969a878-9617-454d-86a9-c5f1de8484ff", + "uuid": "0f2afe75-27e5-4a5f-b689-c6af5421d39d", "control-id": "cis_rhel10_7-1.11", "description": "REPLACE_ME", "props": [ @@ -27366,7 +26348,7 @@ ] }, { - "uuid": "20ee93c2-1e4f-4e09-8d57-e187c1841d93", + "uuid": "7d33e00b-9cc6-4985-a50d-1ae47a61c436", "control-id": "cis_rhel10_7-1.12", "description": "REPLACE_ME", "props": [ @@ -27388,7 +26370,7 @@ ] }, { - "uuid": "c3fbbbc9-e51e-4fea-b23e-3477f54a4ec5", + "uuid": "deeb6737-6c6b-4239-983d-374d6d0f0795", "control-id": "cis_rhel10_7-1.13", "description": "REPLACE_ME", "props": [ @@ -27401,7 +26383,7 @@ ] }, { - "uuid": "65894d21-f5e9-43ac-b2a2-68a29054e898", + "uuid": "b0245d5f-cc28-43e8-bbc0-4a264c7d2632", "control-id": "cis_rhel10_7-2.1", "description": "REPLACE_ME", "props": [ @@ -27418,7 +26400,7 @@ ] }, { - "uuid": "7918607c-1e3a-4ffa-b668-5d06b81a8348", + "uuid": "6e99ac83-a505-4530-9aa2-5cb172916f79", "control-id": "cis_rhel10_7-2.2", "description": "REPLACE_ME", "props": [ @@ -27435,7 +26417,7 @@ ] }, { - "uuid": "83d9ace1-7ce0-476d-b7d2-8eddda2756d7", + "uuid": "0fd26994-f21f-4685-a9fa-e69770091ba0", "control-id": "cis_rhel10_7-2.3", "description": "REPLACE_ME", "props": [ @@ -27452,7 +26434,7 @@ ] }, { - "uuid": "46438caa-1602-4368-93a1-ef24b090bb87", + "uuid": "7c61e02b-6af3-4e68-b612-f5c8787e0f09", "control-id": "cis_rhel10_7-2.4", "description": "REPLACE_ME", "props": [ @@ -27469,7 +26451,7 @@ ] }, { - "uuid": "8cefb8d4-9e46-400b-80a2-056b561b41c1", + "uuid": "98ec4a04-98e4-40c1-ae93-fc0d26758a19", "control-id": "cis_rhel10_7-2.5", "description": "REPLACE_ME", "props": [ @@ -27486,7 +26468,7 @@ ] }, { - "uuid": "2687587e-871c-4459-962a-2ec7ff082385", + "uuid": "decf75b0-601d-40b1-af8c-ccdb72a994e2", "control-id": "cis_rhel10_7-2.6", "description": "REPLACE_ME", "props": [ @@ -27503,7 +26485,7 @@ ] }, { - "uuid": "fb916461-4bbb-416e-b363-10af1d27a4b0", + "uuid": "b294aa5f-c141-437a-92fe-d41d4478e0ec", "control-id": "cis_rhel10_7-2.7", "description": "REPLACE_ME", "props": [ @@ -27520,7 +26502,7 @@ ] }, { - "uuid": "13a1d264-c651-4e4d-b4c3-9e81d3fca74e", + "uuid": "cd474fb8-3590-467b-98a0-440501722914", "control-id": "cis_rhel10_7-2.8", "description": "REPLACE_ME", "props": [ @@ -27547,7 +26529,7 @@ ] }, { - "uuid": "ae04e358-3447-41b0-8d94-99819f2c2193", + "uuid": "b000168e-c832-422e-a2b5-e74feeda707a", "control-id": "cis_rhel10_7-2.9", "description": "Missing a rule to check that .bash_history is mode 0600 or more restrictive.", "props": [ diff --git a/component-definitions/rhel10/rhel10-cis_rhel10-l2_workstation/component-definition.json b/component-definitions/rhel10/rhel10-cis_rhel10-l2_workstation/component-definition.json index 52f99bc86..56c7eb89b 100644 --- a/component-definitions/rhel10/rhel10-cis_rhel10-l2_workstation/component-definition.json +++ b/component-definitions/rhel10/rhel10-cis_rhel10-l2_workstation/component-definition.json @@ -3,8 +3,8 @@ "uuid": "9025707c-c78d-4c60-a2df-d0a822467a29", "metadata": { "title": "Component definition for rhel10", - "last-modified": "2025-09-12T14:58:18.054567+08:00", - "version": "1.0", + "last-modified": "2025-09-16T19:16:57.431217+00:00", + "version": "1.1", "oscal-version": "1.1.3" }, "components": [ @@ -131,7 +131,7 @@ { "name": "Parameter_Value_Alternatives_5", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", + "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel10': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", "remarks": "rule_set_000" }, { @@ -149,7 +149,7 @@ { "name": "Parameter_Value_Alternatives_6", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", + "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel10': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", "remarks": "rule_set_000" }, { @@ -515,5305 +515,5593 @@ { "name": "Parameter_Id_27", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_account_disable_post_pw_expiration", + "value": "sysctl_net_ipv6_conf_default_forwarding_value", "remarks": "rule_set_000" }, { "name": "Parameter_Description_27", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The number of days to wait after a password expires, until the account will be permanently disabled.", + "value": "Toggle IPv6 default Forwarding", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_27", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'0': '0', 180: 180, 30: 30, 35: 35, 40: 40, 45: 45, 60: 60, 90: 90, 'default': 35}", + "value": "{'default': '0', 'disabled': '0', 'enabled': 1}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_28", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_maximum_age_login_defs", + "value": "var_account_disable_post_pw_expiration", "remarks": "rule_set_000" }, { "name": "Parameter_Description_28", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Maximum age of password in days", + "value": "The number of days to wait after a password expires, until the account will be permanently disabled.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_28", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{365: 365, 120: 120, 180: 180, 90: 90, 60: 60, 45: 45, 'default': 60}", + "value": "{'0': '0', 180: 180, 30: 30, 35: 35, 40: 40, 45: 45, 60: 60, 90: 90, 'default': 35}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_29", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_minimum_age_login_defs", + "value": "var_accounts_maximum_age_login_defs", "remarks": "rule_set_000" }, { "name": "Parameter_Description_29", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Minimum age of password in days", + "value": "Maximum age of password in days", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_29", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'0': '0', 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 'default': 7}", + "value": "{365: 365, 120: 120, 180: 180, 90: 90, 60: 60, 45: 45, 'default': 60}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_30", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_password_warn_age_login_defs", + "value": "var_accounts_minimum_age_login_defs", "remarks": "rule_set_000" }, { "name": "Parameter_Description_30", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The number of days' warning given before a password expires.", + "value": "Minimum age of password in days", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_30", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'0': '0', 14: 14, 10: 10, 7: 7, 'default': 7}", + "value": "{'0': '0', 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 'default': 7}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_31", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_passwords_pam_faillock_deny", + "value": "var_accounts_password_warn_age_login_defs", "remarks": "rule_set_000" }, { "name": "Parameter_Description_31", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Number of failed login attempts before account lockout", + "value": "The number of days' warning given before a password expires.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_31", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{10: 10, 3: 3, 4: 4, 5: 5, 6: 6, 8: 8, 'default': 3}", + "value": "{'0': '0', 14: 14, 10: 10, 7: 7, 'default': 7}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_32", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_passwords_pam_faillock_dir", + "value": "var_accounts_passwords_pam_faillock_deny", "remarks": "rule_set_000" }, { "name": "Parameter_Description_32", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The directory where the user files with the failure records are kept", + "value": "Number of failed login attempts before account lockout", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_32", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'ol8': '/var/log/faillock', 'default': '/var/log/faillock', 'run': '/var/run/faillock'}", + "value": "{10: 10, 3: 3, 4: 4, 5: 5, 6: 6, 8: 8, 'default': 3}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_33", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_passwords_pam_faillock_unlock_time", + "value": "var_accounts_passwords_pam_faillock_dir", "remarks": "rule_set_000" }, { "name": "Parameter_Description_33", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Seconds before automatic unlocking or permanently locking after excessive failed logins", + "value": "The directory where the user files with the failure records are kept", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_33", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{1800: 1800, 3600: 3600, 600: 600, 604800: 604800, 86400: 86400, 900: 900, 300: 300, 'default': 0, 'never': 0}", + "value": "{'ol8': '/var/log/faillock', 'default': '/var/log/faillock', 'run': '/var/run/faillock'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_34", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_tmout", + "value": "var_accounts_passwords_pam_faillock_unlock_time", "remarks": "rule_set_000" }, { "name": "Parameter_Description_34", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "In an interactive shell, the value is interpreted as the number of seconds to wait for input after issuing the primary prompt. Bash terminates after waiting for that number of seconds if input does not arrive.", + "value": "Seconds before automatic unlocking or permanently locking after excessive failed logins", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_34", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'30_min': 1800, '10_min': 600, '15_min': 900, '5_min': 300, 'default': 600}", + "value": "{1800: 1800, 3600: 3600, 600: 600, 604800: 604800, 86400: 86400, 900: 900, 300: 300, 'default': 0, 'never': 0}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_35", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_user_umask", + "value": "var_accounts_tmout", "remarks": "rule_set_000" }, { "name": "Parameter_Description_35", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enter default user umask", + "value": "In an interactive shell, the value is interpreted as the number of seconds to wait for input after issuing the primary prompt. Bash terminates after waiting for that number of seconds if input does not arrive.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_35", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'007': '007', '022': '022', '027': '027', '077': '077', 'default': '027'}", + "value": "{'30_min': 1800, '10_min': 600, '15_min': 900, '5_min': 300, 'default': 600}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_36", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_auditd_action_mail_acct", + "value": "var_accounts_user_umask", "remarks": "rule_set_000" }, { "name": "Parameter_Description_36", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The setting for action_mail_acct in /etc/audit/auditd.conf", + "value": "Enter default user umask", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_36", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'admin': 'admin', 'default': 'root', 'root': 'root'}", + "value": "{'007': '007', '022': '022', '027': '027', '077': '077', 'default': '027'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_auditd_admin_space_left_action", + "value": "var_auditd_action_mail_acct", "remarks": "rule_set_000" }, { "name": "Parameter_Description_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The setting for admin_space_left_action in /etc/audit/auditd.conf", + "value": "The setting for action_mail_acct in /etc/audit/auditd.conf", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt'}", + "value": "{'admin': 'admin', 'default': 'root', 'root': 'root'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_auditd_disk_error_action", + "value": "var_auditd_admin_space_left_action", "remarks": "rule_set_000" }, { "name": "Parameter_Description_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "'The setting for disk_error_action in /etc/audit/auditd.conf, if multiple values are allowed write them separated by pipes as in \"syslog|single|halt\", for remediations the first value will be taken'", + "value": "The setting for admin_space_left_action in /etc/audit/auditd.conf", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", + "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt', 'cis_rhel10': 'single|halt'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_auditd_disk_full_action", + "value": "var_auditd_disk_error_action", "remarks": "rule_set_000" }, { "name": "Parameter_Description_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "'The setting for disk_full_action in /etc/audit/auditd.conf, if multiple values are allowed write them separated by pipes as in \"syslog|single|halt\", for remediations the first value will be taken'", + "value": "'The setting for disk_error_action in /etc/audit/auditd.conf, if multiple values are allowed write them separated by pipes as in \"syslog|single|halt\", for remediations the first value will be taken'", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_rhel10': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_40", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_auditd_max_log_file", + "value": "var_auditd_disk_full_action", "remarks": "rule_set_000" }, { "name": "Parameter_Description_40", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The setting for max_log_file in /etc/audit/auditd.conf", + "value": "'The setting for disk_full_action in /etc/audit/auditd.conf, if multiple values are allowed write them separated by pipes as in \"syslog|single|halt\", for remediations the first value will be taken'", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_40", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{1: 1, 10: 10, 20: 20, 5: 5, 6: 6, 'default': 6}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_rhel10': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_41", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_auditd_max_log_file_action", + "value": "var_auditd_max_log_file", "remarks": "rule_set_000" }, { "name": "Parameter_Description_41", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The setting for max_log_file_action in /etc/audit/auditd.conf. The following options are available:
ignore - audit daemon does nothing.
syslog - audit daemon will issue a warning to syslog.
suspend - audit daemon will stop writing records to the disk.
rotate - audit daemon will rotate logs in the same convention used by logrotate.
keep_logs - similar to rotate but prevents audit logs to be overwritten. May trigger space_left_action if volume is full.", + "value": "The setting for max_log_file in /etc/audit/auditd.conf", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_41", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'rotate', 'keep_logs': 'keep_logs', 'rotate': 'rotate', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore'}", + "value": "{1: 1, 10: 10, 20: 20, 5: 5, 6: 6, 'default': 6}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_42", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_auditd_space_left_action", + "value": "var_auditd_max_log_file_action", "remarks": "rule_set_000" }, { "name": "Parameter_Description_42", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The setting for space_left_action in /etc/audit/auditd.conf", + "value": "The setting for max_log_file_action in /etc/audit/auditd.conf. The following options are available:
ignore - audit daemon does nothing.
syslog - audit daemon will issue a warning to syslog.
suspend - audit daemon will stop writing records to the disk.
rotate - audit daemon will rotate logs in the same convention used by logrotate.
keep_logs - similar to rotate but prevents audit logs to be overwritten. May trigger space_left_action if volume is full.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_42", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt'}", + "value": "{'default': 'rotate', 'keep_logs': 'keep_logs', 'rotate': 'rotate', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_43", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_authselect_profile", + "value": "var_auditd_space_left_action", "remarks": "rule_set_000" }, { "name": "Parameter_Description_43", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the authselect profile to select", + "value": "The setting for space_left_action in /etc/audit/auditd.conf", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_43", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'local': 'local', 'default': 'minimal', 'minimal': 'minimal', 'sssd': 'sssd'}", + "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt', 'cis_rhel10': 'email|exec|single|halt'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_44", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_multiple_time_servers", + "value": "var_authselect_profile", "remarks": "rule_set_000" }, { "name": "Parameter_Description_44", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The list of vendor-approved time servers", + "value": "Specify the authselect profile to select", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_44", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'generic': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'stig': '0.us.pool.ntp.mil', 'fedora': '0.fedora.pool.ntp.org,1.fedora.pool.ntp.org,2.fedora.pool.ntp.org,3.fedora.pool.ntp.org', 'rhel': '0.rhel.pool.ntp.org,1.rhel.pool.ntp.org,2.rhel.pool.ntp.org,3.rhel.pool.ntp.org', 'ol': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'suse': '0.suse.pool.ntp.org,1.suse.pool.ntp.org,2.suse.pool.ntp.org,3.suse.pool.ntp.org', 'alinux': '0.ntp.cloud.aliyuncs.com,1.ntp.aliyun.com,2.ntp1.aliyun.com,3.ntp1.cloud.aliyuncs.com', 'amazon': '0.rhel.pool.ntp.org,1.rhel.pool.ntp.org,2.rhel.pool.ntp.org,3.rhel.pool.ntp.org', 'ubuntu': '0.ubuntu.pool.ntp.org,1.ubuntu.pool.ntp.org,2.ubuntu.pool.ntp.org,3.ubuntu.pool.ntp.org', 'almalinux': '0.almalinux.pool.ntp.org,1.almalinux.pool.ntp.org,2.almalinux.pool.ntp.org,3.almalinux.pool.ntp.org', 'debian': '0.debian.pool.ntp.org,1.debian.pool.ntp.org,2.debian.pool.ntp.org,3.debian.pool.ntp.org', 'nist': 'time.nist.gov,time-a-g.nist.gov,time-b-g.nist.gov,time-c-g.nist.gov'}", + "value": "{'local': 'local', 'default': 'minimal', 'minimal': 'minimal', 'sssd': 'sssd'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_45", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_pam_wheel_group_for_su", + "value": "var_multiple_time_servers", "remarks": "rule_set_000" }, { "name": "Parameter_Description_45", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "pam_wheel module has a parameter called group, which controls which groups can access the su command. This variable holds the valid value for the parameter.", + "value": "The list of vendor-approved time servers", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_45", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'sugroup', 'cis': 'sugroup'}", + "value": "{'default': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'generic': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'stig': '0.us.pool.ntp.mil', 'fedora': '0.fedora.pool.ntp.org,1.fedora.pool.ntp.org,2.fedora.pool.ntp.org,3.fedora.pool.ntp.org', 'rhel': '0.rhel.pool.ntp.org,1.rhel.pool.ntp.org,2.rhel.pool.ntp.org,3.rhel.pool.ntp.org', 'ol': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'suse': '0.suse.pool.ntp.org,1.suse.pool.ntp.org,2.suse.pool.ntp.org,3.suse.pool.ntp.org', 'alinux': '0.ntp.cloud.aliyuncs.com,1.ntp.aliyun.com,2.ntp1.aliyun.com,3.ntp1.cloud.aliyuncs.com', 'amazon': '0.rhel.pool.ntp.org,1.rhel.pool.ntp.org,2.rhel.pool.ntp.org,3.rhel.pool.ntp.org', 'ubuntu': '0.ubuntu.pool.ntp.org,1.ubuntu.pool.ntp.org,2.ubuntu.pool.ntp.org,3.ubuntu.pool.ntp.org', 'almalinux': '0.almalinux.pool.ntp.org,1.almalinux.pool.ntp.org,2.almalinux.pool.ntp.org,3.almalinux.pool.ntp.org', 'debian': '0.debian.pool.ntp.org,1.debian.pool.ntp.org,2.debian.pool.ntp.org,3.debian.pool.ntp.org', 'nist': 'time.nist.gov,time-a-g.nist.gov,time-b-g.nist.gov,time-c-g.nist.gov'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_46", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_hashing_algorithm", + "value": "var_pam_wheel_group_for_su", "remarks": "rule_set_000" }, { "name": "Parameter_Description_46", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the system default encryption algorithm for encrypting passwords. Defines the value set as ENCRYPT_METHOD in /etc/login.defs.", + "value": "pam_wheel module has a parameter called group, which controls which groups can access the su command. This variable holds the valid value for the parameter.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_46", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'SHA512', 'SHA512': 'SHA512', 'SHA256': 'SHA256', 'yescrypt': 'YESCRYPT', 'cis_ubuntu2404': 'SHA512|YESCRYPT'}", + "value": "{'default': 'sugroup', 'cis': 'sugroup'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_47", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_hashing_algorithm_pam", + "value": "var_password_hashing_algorithm", "remarks": "rule_set_000" }, { "name": "Parameter_Description_47", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the system default encryption algorithm for encrypting passwords. Defines the hashing algorithm to be used in pam_unix.so.", + "value": "Specify the system default encryption algorithm for encrypting passwords. Defines the value set as ENCRYPT_METHOD in /etc/login.defs.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_47", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'sha512', 'sha512': 'sha512', 'yescrypt': 'yescrypt'}", + "value": "{'default': 'SHA512', 'SHA512': 'SHA512', 'SHA256': 'SHA256', 'yescrypt': 'YESCRYPT', 'cis_ubuntu2404': 'SHA512|YESCRYPT'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_48", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_dictcheck", + "value": "var_password_hashing_algorithm_pam", "remarks": "rule_set_000" }, { "name": "Parameter_Description_48", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Prevent the use of dictionary words for passwords.", + "value": "Specify the system default encryption algorithm for encrypting passwords. Defines the hashing algorithm to be used in pam_unix.so.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_48", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{1: 1, 'default': 1}", + "value": "{'default': 'sha512', 'sha512': 'sha512', 'yescrypt': 'yescrypt'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_49", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_difok", + "value": "var_password_pam_dictcheck", "remarks": "rule_set_000" }, { "name": "Parameter_Description_49", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Minimum number of characters not present in old password", + "value": "Prevent the use of dictionary words for passwords.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_49", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{15: 15, 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 8: 8, 'default': 8}", + "value": "{1: 1, 'default': 1}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_50", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_maxrepeat", + "value": "var_password_pam_difok", "remarks": "rule_set_000" }, { "name": "Parameter_Description_50", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Maximum Number of Consecutive Repeating Characters in a Password", + "value": "Minimum number of characters not present in old password", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_50", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{1: 1, 2: 2, 3: 3, 'default': 3}", + "value": "{15: 15, 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 8: 8, 'default': 8}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_51", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_minclass", + "value": "var_password_pam_maxrepeat", "remarks": "rule_set_000" }, { "name": "Parameter_Description_51", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Minimum number of categories of characters that must exist in a password", + "value": "Maximum Number of Consecutive Repeating Characters in a Password", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_51", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{1: 1, 2: 2, 3: 3, 4: 4, 'default': 3}", + "value": "{1: 1, 2: 2, 3: 3, 'default': 3}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_52", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_minlen", + "value": "var_password_pam_minclass", "remarks": "rule_set_000" }, { "name": "Parameter_Description_52", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Minimum number of characters in password", + "value": "Minimum number of categories of characters that must exist in a password", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_52", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{10: 10, 12: 12, 14: 14, 15: 15, 17: 17, 18: 18, 20: 20, 6: 6, 7: 7, 8: 8, 'default': 15}", + "value": "{1: 1, 2: 2, 3: 3, 4: 4, 'default': 3}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_53", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_remember", + "value": "var_password_pam_minlen", "remarks": "rule_set_000" }, { "name": "Parameter_Description_53", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Prevent password re-use using password history lookup", + "value": "Minimum number of characters in password", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_53", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'0': '0', 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 8: 8, 9: 9, 24: 24, 'default': 5}", + "value": "{10: 10, 12: 12, 14: 14, 15: 15, 17: 17, 18: 18, 20: 20, 6: 6, 7: 7, 8: 8, 'default': 15}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_54", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_remember_control_flag", + "value": "var_password_pam_remember", "remarks": "rule_set_000" }, { "name": "Parameter_Description_54", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "'Specify the control flag required for password remember requirement. If multiple values are allowed write them separated by commas as in \"required,requisite\", for remediations the first value will be taken'", + "value": "Prevent password re-use using password history lookup", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_54", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'required': 'required', 'optional': 'optional', 'requisite': 'requisite', 'sufficient': 'sufficient', 'binding': 'binding', 'ol8': 'required,requisite', 'requisite_or_required': 'requisite,required', 'default': 'requisite'}", + "value": "{'0': '0', 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 8: 8, 9: 9, 24: 24, 'default': 5}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_55", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_postfix_inet_interfaces", + "value": "var_password_pam_remember_control_flag", "remarks": "rule_set_000" }, { "name": "Parameter_Description_55", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The setting for inet_interfaces in /etc/postfix/main.cf", + "value": "'Specify the control flag required for password remember requirement. If multiple values are allowed write them separated by commas as in \"required,requisite\", for remediations the first value will be taken'", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_55", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'loopback-only': 'loopback-only', 'default': 'loopback-only', 'localhost': 'localhost'}", + "value": "{'required': 'required', 'optional': 'optional', 'requisite': 'requisite', 'sufficient': 'sufficient', 'binding': 'binding', 'ol8': 'required,requisite', 'requisite_or_required': 'requisite,required', 'default': 'requisite'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_56", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_screensaver_lock_delay", + "value": "var_postfix_inet_interfaces", "remarks": "rule_set_000" }, { "name": "Parameter_Description_56", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Choose allowed duration (in seconds) after a screensaver becomes active before displaying an authentication prompt", + "value": "The setting for inet_interfaces in /etc/postfix/main.cf", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_56", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'10_seconds': 10, '5_seconds': 5, 'default': '0', 'immediate': '0'}", + "value": "{'loopback-only': 'loopback-only', 'default': 'loopback-only', 'localhost': 'localhost'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_57", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_selinux_policy_name", + "value": "var_screensaver_lock_delay", "remarks": "rule_set_000" }, { "name": "Parameter_Description_57", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Type of policy in use. Possible values are:
targeted - Only targeted network daemons are protected.
strict - Full SELinux protection.
mls - Multiple levels of security", + "value": "Choose allowed duration (in seconds) after a screensaver becomes active before displaying an authentication prompt", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_57", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'targeted', 'mls': 'mls', 'targeted': 'targeted'}", + "value": "{'10_seconds': 10, '5_seconds': 5, 'default': '0', 'immediate': '0'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_58", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_selinux_state", + "value": "var_selinux_policy_name", "remarks": "rule_set_000" }, { "name": "Parameter_Description_58", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "enforcing - SELinux security policy is enforced.
permissive - SELinux prints warnings instead of enforcing.
disabled - SELinux is fully disabled.", + "value": "Type of policy in use. Possible values are:
targeted - Only targeted network daemons are protected.
strict - Full SELinux protection.
mls - Multiple levels of security", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_58", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'enforcing', 'disabled': 'disabled', 'enforcing': 'enforcing', 'permissive': 'permissive'}", + "value": "{'default': 'targeted', 'mls': 'mls', 'targeted': 'targeted'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_59", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_sshd_max_sessions", + "value": "var_selinux_state", "remarks": "rule_set_000" }, { "name": "Parameter_Description_59", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the maximum number of open sessions permitted.", + "value": "enforcing - SELinux security policy is enforced.
permissive - SELinux prints warnings instead of enforcing.
disabled - SELinux is fully disabled.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_59", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{10: 10, 4: 4, 3: 3, 2: 2, 1: 1, 0: 0, 'default': 10}", + "value": "{'default': 'enforcing', 'disabled': 'disabled', 'enforcing': 'enforcing', 'permissive': 'permissive'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_60", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_sshd_set_keepalive", + "value": "var_sshd_max_sessions", "remarks": "rule_set_000" }, { "name": "Parameter_Description_60", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the maximum number of idle message counts before session is terminated.", + "value": "Specify the maximum number of open sessions permitted.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_60", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{10: 10, 3: 3, 5: 5, 0: 0, 1: 1, 'default': 0}", + "value": "{10: 10, 4: 4, 3: 3, 2: 2, 1: 1, 0: 0, 'default': 10}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_61", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_sshd_set_login_grace_time", + "value": "var_sshd_set_keepalive", "remarks": "rule_set_000" }, { "name": "Parameter_Description_61", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure parameters for how long the servers stays connected before the user has successfully logged in", + "value": "Specify the maximum number of idle message counts before session is terminated.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_61", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 60, 60: 60}", + "value": "{10: 10, 3: 3, 5: 5, 0: 0, 1: 1, 'default': 0}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_62", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_sshd_set_maxstartups", + "value": "var_sshd_set_login_grace_time", "remarks": "rule_set_000" }, { "name": "Parameter_Description_62", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure parameters for maximum concurrent unauthenticated connections to the SSH daemon.", + "value": "Configure parameters for how long the servers stays connected before the user has successfully logged in", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_62", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': '10:30:100', '10:30:60': '10:30:60'}", + "value": "{'default': 60, 60: 60}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_63", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_system_crypto_policy", + "value": "var_sshd_set_maxstartups", "remarks": "rule_set_000" }, { "name": "Parameter_Description_63", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the crypto policy for the system.", + "value": "Configure parameters for maximum concurrent unauthenticated connections to the SSH daemon.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_63", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': '10:30:100', '10:30:60': '10:30:60'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_64", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_user_initialization_files_regex", + "value": "var_system_crypto_policy", "remarks": "rule_set_000" }, { "name": "Parameter_Description_64", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "'A regular expression describing a list of file names for files that are sourced at login time for interactive users'", + "value": "Specify the crypto policy for the system.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_64", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Id_65", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "var_user_initialization_files_regex", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Description_65", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "'A regular expression describing a list of file names for files that are sourced at login time for interactive users'", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Value_Alternatives_65", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'default': '^(\\\\.bashrc|\\\\.zshrc|\\\\.cshrc|\\\\.profile|\\\\.bash_login|\\\\.bash_profile)$', 'all_dotfiles': '^\\\\.[\\\\w\\\\- ]+$'}", "remarks": "rule_set_000" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_tmp", + "value": "kernel_module_cramfs_disabled", "remarks": "rule_set_001" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /tmp Located On Separate Partition", + "value": "Disable Mounting of cramfs", "remarks": "rule_set_001" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_nodev", + "value": "kernel_module_freevxfs_disabled", "remarks": "rule_set_002" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /tmp", + "value": "Disable Mounting of freevxfs", "remarks": "rule_set_002" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_nosuid", + "value": "kernel_module_hfs_disabled", "remarks": "rule_set_003" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /tmp", + "value": "Disable Mounting of hfs", "remarks": "rule_set_003" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_noexec", + "value": "kernel_module_hfsplus_disabled", "remarks": "rule_set_004" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /tmp", + "value": "Disable Mounting of hfsplus", "remarks": "rule_set_004" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_dev_shm", + "value": "kernel_module_jffs2_disabled", "remarks": "rule_set_005" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /dev/shm is configured", + "value": "Disable Mounting of jffs2", "remarks": "rule_set_005" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_nodev", + "value": "partition_for_tmp", "remarks": "rule_set_006" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /dev/shm", + "value": "Ensure /tmp Located On Separate Partition", "remarks": "rule_set_006" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_nosuid", + "value": "mount_option_tmp_nodev", "remarks": "rule_set_007" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /dev/shm", + "value": "Add nodev Option to /tmp", "remarks": "rule_set_007" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_noexec", + "value": "mount_option_tmp_nosuid", "remarks": "rule_set_008" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /dev/shm", + "value": "Add nosuid Option to /tmp", "remarks": "rule_set_008" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_home_nodev", + "value": "mount_option_tmp_noexec", "remarks": "rule_set_009" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /home", + "value": "Add noexec Option to /tmp", "remarks": "rule_set_009" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_home_nosuid", + "value": "partition_for_dev_shm", "remarks": "rule_set_010" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /home", + "value": "Ensure /dev/shm is configured", "remarks": "rule_set_010" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_nodev", + "value": "mount_option_dev_shm_nodev", "remarks": "rule_set_011" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /var", + "value": "Add nodev Option to /dev/shm", "remarks": "rule_set_011" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_nosuid", + "value": "mount_option_dev_shm_nosuid", "remarks": "rule_set_012" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /var", + "value": "Add nosuid Option to /dev/shm", "remarks": "rule_set_012" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_tmp_nodev", + "value": "mount_option_dev_shm_noexec", "remarks": "rule_set_013" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /var/tmp", + "value": "Add noexec Option to /dev/shm", "remarks": "rule_set_013" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_tmp_nosuid", + "value": "mount_option_home_nodev", "remarks": "rule_set_014" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /var/tmp", + "value": "Add nodev Option to /home", "remarks": "rule_set_014" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_tmp_noexec", + "value": "mount_option_home_nosuid", "remarks": "rule_set_015" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /var/tmp", + "value": "Add nosuid Option to /home", "remarks": "rule_set_015" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_nodev", + "value": "mount_option_var_nodev", "remarks": "rule_set_016" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /var/log", + "value": "Add nodev Option to /var", "remarks": "rule_set_016" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_nosuid", + "value": "mount_option_var_nosuid", "remarks": "rule_set_017" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /var/log", + "value": "Add nosuid Option to /var", "remarks": "rule_set_017" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_noexec", + "value": "mount_option_var_tmp_nodev", "remarks": "rule_set_018" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /var/log", + "value": "Add nodev Option to /var/tmp", "remarks": "rule_set_018" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_audit_nodev", + "value": "mount_option_var_tmp_nosuid", "remarks": "rule_set_019" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /var/log/audit", + "value": "Add nosuid Option to /var/tmp", "remarks": "rule_set_019" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_audit_nosuid", + "value": "mount_option_var_tmp_noexec", "remarks": "rule_set_020" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /var/log/audit", + "value": "Add noexec Option to /var/tmp", "remarks": "rule_set_020" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_audit_noexec", + "value": "mount_option_var_log_nodev", "remarks": "rule_set_021" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /var/log/audit", + "value": "Add nodev Option to /var/log", "remarks": "rule_set_021" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_gpgcheck_globally_activated", + "value": "mount_option_var_log_nosuid", "remarks": "rule_set_022" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure gpgcheck Enabled In Main dnf Configuration", + "value": "Add nosuid Option to /var/log", "remarks": "rule_set_022" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_libselinux_installed", + "value": "mount_option_var_log_noexec", "remarks": "rule_set_023" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install libselinux Package", + "value": "Add noexec Option to /var/log", "remarks": "rule_set_023" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "grub2_enable_selinux", + "value": "mount_option_var_log_audit_nodev", "remarks": "rule_set_024" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure SELinux Not Disabled in /etc/default/grub", + "value": "Add nodev Option to /var/log/audit", "remarks": "rule_set_024" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "selinux_policytype", + "value": "mount_option_var_log_audit_nosuid", "remarks": "rule_set_025" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure SELinux Policy", + "value": "Add nosuid Option to /var/log/audit", "remarks": "rule_set_025" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "selinux_not_disabled", + "value": "mount_option_var_log_audit_noexec", "remarks": "rule_set_026" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure SELinux is Not Disabled", + "value": "Add noexec Option to /var/log/audit", "remarks": "rule_set_026" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_mcstrans_removed", + "value": "ensure_gpgcheck_globally_activated", "remarks": "rule_set_027" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall mcstrans Package", + "value": "Ensure gpgcheck Enabled In Main dnf Configuration", "remarks": "rule_set_027" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "grub2_password", + "value": "package_libselinux_installed", "remarks": "rule_set_028" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Boot Loader Password in grub2", + "value": "Install libselinux Package", "remarks": "rule_set_028" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_grub2_cfg", + "value": "grub2_enable_selinux", "remarks": "rule_set_029" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/grub.cfg Group Ownership", + "value": "Ensure SELinux Not Disabled in /etc/default/grub", "remarks": "rule_set_029" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_grub2_cfg", + "value": "selinux_policytype", "remarks": "rule_set_030" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/grub.cfg User Ownership", + "value": "Configure SELinux Policy", "remarks": "rule_set_030" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_grub2_cfg", + "value": "selinux_not_disabled", "remarks": "rule_set_031" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/grub.cfg Permissions", + "value": "Ensure SELinux is Not Disabled", "remarks": "rule_set_031" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_user_cfg", + "value": "package_mcstrans_removed", "remarks": "rule_set_032" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/user.cfg Group Ownership", + "value": "Uninstall mcstrans Package", "remarks": "rule_set_032" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_user_cfg", + "value": "grub2_password", "remarks": "rule_set_033" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/user.cfg User Ownership", + "value": "Set Boot Loader Password in grub2", "remarks": "rule_set_033" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_user_cfg", + "value": "file_groupowner_grub2_cfg", "remarks": "rule_set_034" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/user.cfg Permissions", + "value": "Verify /boot/grub2/grub.cfg Group Ownership", "remarks": "rule_set_034" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_kernel_randomize_va_space", + "value": "file_owner_grub2_cfg", "remarks": "rule_set_035" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Randomized Layout of Virtual Address Space", + "value": "Verify /boot/grub2/grub.cfg User Ownership", "remarks": "rule_set_035" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_kernel_yama_ptrace_scope", + "value": "file_permissions_grub2_cfg", "remarks": "rule_set_036" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Restrict usage of ptrace to descendant processes", + "value": "Verify /boot/grub2/grub.cfg Permissions", "remarks": "rule_set_036" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_backtraces", + "value": "file_groupowner_user_cfg", "remarks": "rule_set_037" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable core dump backtraces", + "value": "Verify /boot/grub2/user.cfg Group Ownership", "remarks": "rule_set_037" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_storage", + "value": "file_owner_user_cfg", "remarks": "rule_set_038" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable storing core dump", + "value": "Verify /boot/grub2/user.cfg User Ownership", "remarks": "rule_set_038" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_crypto_policy", + "value": "file_permissions_user_cfg", "remarks": "rule_set_039" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure System Cryptography Policy", + "value": "Verify /boot/grub2/user.cfg Permissions", "remarks": "rule_set_039" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_ssh_crypto_policy", + "value": "disable_users_coredumps", "remarks": "rule_set_040" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure SSH to use System Crypto Policy", + "value": "Disable Core Dumps for All Users", "remarks": "rule_set_040" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "banner_etc_motd_cis", + "value": "sysctl_fs_protected_hardlinks", "remarks": "rule_set_041" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Message Of The Day Is Configured Properly", + "value": "Enable Kernel Parameter to Enforce DAC on Hardlinks", "remarks": "rule_set_041" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "banner_etc_issue_cis", + "value": "sysctl_fs_suid_dumpable", "remarks": "rule_set_042" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Local Login Warning Banner Is Configured Properly", + "value": "Disable Core Dumps for SUID programs", "remarks": "rule_set_042" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "banner_etc_issue_net_cis", + "value": "sysctl_kernel_dmesg_restrict", "remarks": "rule_set_043" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Remote Login Warning Banner Is Configured Properly", + "value": "Restrict Access to Kernel Message Buffer", "remarks": "rule_set_043" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_motd", + "value": "sysctl_kernel_kptr_restrict", "remarks": "rule_set_044" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Ownership of Message of the Day Banner", + "value": "Restrict Exposed Kernel Pointer Addresses Access", "remarks": "rule_set_044" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_motd", + "value": "sysctl_kernel_yama_ptrace_scope", "remarks": "rule_set_045" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify ownership of Message of the Day Banner", + "value": "Restrict usage of ptrace to descendant processes", "remarks": "rule_set_045" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_motd", + "value": "sysctl_kernel_randomize_va_space", "remarks": "rule_set_046" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify permissions on Message of the Day Banner", + "value": "Enable Randomized Layout of Virtual Address Space", "remarks": "rule_set_046" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_issue", + "value": "coredump_disable_backtraces", "remarks": "rule_set_047" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Ownership of System Login Banner", + "value": "Disable core dump backtraces", "remarks": "rule_set_047" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_issue", + "value": "coredump_disable_storage", "remarks": "rule_set_048" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify ownership of System Login Banner", + "value": "Disable storing core dump", "remarks": "rule_set_048" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_issue", + "value": "configure_crypto_policy", "remarks": "rule_set_049" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify permissions on System Login Banner", + "value": "Configure System Cryptography Policy", "remarks": "rule_set_049" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_issue_net", + "value": "banner_etc_motd_cis", "remarks": "rule_set_050" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Ownership of System Login Banner for Remote Connections", + "value": "Ensure Message Of The Day Is Configured Properly", "remarks": "rule_set_050" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_issue_net", + "value": "banner_etc_issue_cis", "remarks": "rule_set_051" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify ownership of System Login Banner for Remote Connections", + "value": "Ensure Local Login Warning Banner Is Configured Properly", "remarks": "rule_set_051" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_issue_net", + "value": "banner_etc_issue_net_cis", "remarks": "rule_set_052" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify permissions on System Login Banner for Remote Connections", + "value": "Ensure Remote Login Warning Banner Is Configured Properly", "remarks": "rule_set_052" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_banner_enabled", + "value": "file_groupowner_etc_motd", "remarks": "rule_set_053" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable GNOME3 Login Warning Banner", + "value": "Verify Group Ownership of Message of the Day Banner", "remarks": "rule_set_053" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_login_banner_text", + "value": "file_owner_etc_motd", "remarks": "rule_set_054" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set the GNOME3 Login Warning Banner Text", + "value": "Verify ownership of Message of the Day Banner", "remarks": "rule_set_054" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_user_list", + "value": "file_permissions_etc_motd", "remarks": "rule_set_055" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable the GNOME3 Login User List", + "value": "Verify permissions on Message of the Day Banner", "remarks": "rule_set_055" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_screensaver_idle_delay", + "value": "file_groupowner_etc_issue", "remarks": "rule_set_056" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set GNOME3 Screensaver Inactivity Timeout", + "value": "Verify Group Ownership of System Login Banner", "remarks": "rule_set_056" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_screensaver_lock_delay", + "value": "file_owner_etc_issue", "remarks": "rule_set_057" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set GNOME3 Screensaver Lock Delay After Activation Period", + "value": "Verify ownership of System Login Banner", "remarks": "rule_set_057" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_session_idle_user_locks", + "value": "file_permissions_etc_issue", "remarks": "rule_set_058" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Users Cannot Change GNOME3 Session Idle Settings", + "value": "Verify permissions on System Login Banner", "remarks": "rule_set_058" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_screensaver_user_locks", + "value": "file_groupowner_etc_issue_net", "remarks": "rule_set_059" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Users Cannot Change GNOME3 Screensaver Settings", + "value": "Verify Group Ownership of System Login Banner for Remote Connections", "remarks": "rule_set_059" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_autorun", + "value": "file_owner_etc_issue_net", "remarks": "rule_set_060" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable GNOME3 Automount running", + "value": "Verify ownership of System Login Banner for Remote Connections", "remarks": "rule_set_060" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_kea_removed", + "value": "file_permissions_etc_issue_net", "remarks": "rule_set_061" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall kea Package", + "value": "Verify permissions on System Login Banner for Remote Connections", "remarks": "rule_set_061" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_bind_removed", + "value": "dconf_gnome_banner_enabled", "remarks": "rule_set_062" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall bind Package", + "value": "Enable GNOME3 Login Warning Banner", "remarks": "rule_set_062" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_dnsmasq_removed", + "value": "dconf_gnome_login_banner_text", "remarks": "rule_set_063" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall dnsmasq Package", + "value": "Set the GNOME3 Login Warning Banner Text", "remarks": "rule_set_063" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_samba_removed", + "value": "dconf_gnome_disable_user_list", "remarks": "rule_set_064" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall Samba Package", + "value": "Disable the GNOME3 Login User List", "remarks": "rule_set_064" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_vsftpd_removed", + "value": "dconf_gnome_screensaver_idle_delay", "remarks": "rule_set_065" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall vsftpd Package", + "value": "Set GNOME3 Screensaver Inactivity Timeout", "remarks": "rule_set_065" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_dovecot_removed", + "value": "dconf_gnome_screensaver_lock_delay", "remarks": "rule_set_066" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall dovecot Package", + "value": "Set GNOME3 Screensaver Lock Delay After Activation Period", "remarks": "rule_set_066" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_cyrus-imapd_removed", + "value": "dconf_gnome_session_idle_user_locks", "remarks": "rule_set_067" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall cyrus-imapd Package", + "value": "Ensure Users Cannot Change GNOME3 Session Idle Settings", "remarks": "rule_set_067" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_nfs_disabled", + "value": "dconf_gnome_screensaver_user_locks", "remarks": "rule_set_068" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Network File System (nfs)", + "value": "Ensure Users Cannot Change GNOME3 Screensaver Settings", "remarks": "rule_set_068" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_rpcbind_disabled", + "value": "dconf_gnome_disable_autorun", "remarks": "rule_set_069" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable rpcbind Service", + "value": "Disable GNOME3 Automount running", "remarks": "rule_set_069" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_rsync_removed", + "value": "package_kea_removed", "remarks": "rule_set_070" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall rsync Package", + "value": "Uninstall kea Package", "remarks": "rule_set_070" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_net-snmp_removed", + "value": "package_bind_removed", "remarks": "rule_set_071" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall net-snmp Package", + "value": "Uninstall bind Package", "remarks": "rule_set_071" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_telnet-server_removed", + "value": "package_dnsmasq_removed", "remarks": "rule_set_072" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall telnet-server Package", + "value": "Uninstall dnsmasq Package", "remarks": "rule_set_072" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_tftp-server_removed", + "value": "package_vsftpd_removed", "remarks": "rule_set_073" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall tftp-server Package", + "value": "Uninstall vsftpd Package", "remarks": "rule_set_073" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_squid_removed", + "value": "package_dovecot_removed", "remarks": "rule_set_074" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall squid Package", + "value": "Uninstall dovecot Package", "remarks": "rule_set_074" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_httpd_removed", + "value": "package_cyrus-imapd_removed", "remarks": "rule_set_075" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall httpd Package", + "value": "Uninstall cyrus-imapd Package", "remarks": "rule_set_075" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_nginx_removed", + "value": "service_nfs_disabled", "remarks": "rule_set_076" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall nginx Package", + "value": "Disable Network File System (nfs)", "remarks": "rule_set_076" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "postfix_network_listening_disabled", + "value": "service_rpcbind_disabled", "remarks": "rule_set_077" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Postfix Network Listening", + "value": "Disable rpcbind Service", "remarks": "rule_set_077" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "has_nonlocal_mta", + "value": "package_rsync_removed", "remarks": "rule_set_078" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Mail Transfer Agent is not Listening on any non-loopback Address", + "value": "Uninstall rsync Package", "remarks": "rule_set_078" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_ftp_removed", + "value": "package_samba_removed", "remarks": "rule_set_079" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Remove ftp Package", + "value": "Uninstall Samba Package", "remarks": "rule_set_079" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_telnet_removed", + "value": "package_net-snmp_removed", "remarks": "rule_set_080" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Remove telnet Clients", + "value": "Uninstall net-snmp Package", "remarks": "rule_set_080" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_tftp_removed", + "value": "package_telnet-server_removed", "remarks": "rule_set_081" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Remove tftp Daemon", + "value": "Uninstall telnet-server Package", "remarks": "rule_set_081" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "chronyd_specify_remote_server", + "value": "package_tftp-server_removed", "remarks": "rule_set_082" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "A remote time server for Chrony is configured", + "value": "Uninstall tftp-server Package", "remarks": "rule_set_082" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "chronyd_run_as_chrony_user", + "value": "package_squid_removed", "remarks": "rule_set_083" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that chronyd is running under chrony user account", + "value": "Uninstall squid Package", "remarks": "rule_set_083" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_cron_installed", + "value": "package_httpd_removed", "remarks": "rule_set_084" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install the cron service", + "value": "Uninstall httpd Package", "remarks": "rule_set_084" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_crond_enabled", + "value": "package_nginx_removed", "remarks": "rule_set_085" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable cron Service", + "value": "Uninstall nginx Package", "remarks": "rule_set_085" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_crontab", + "value": "postfix_network_listening_disabled", "remarks": "rule_set_086" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns Crontab", + "value": "Disable Postfix Network Listening", "remarks": "rule_set_086" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_crontab", + "value": "has_nonlocal_mta", "remarks": "rule_set_087" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on crontab", + "value": "Ensure Mail Transfer Agent is not Listening on any non-loopback Address", "remarks": "rule_set_087" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_crontab", + "value": "package_ftp_removed", "remarks": "rule_set_088" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on crontab", + "value": "Remove ftp Package", "remarks": "rule_set_088" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_hourly", + "value": "package_telnet_removed", "remarks": "rule_set_089" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns cron.hourly", + "value": "Remove telnet Clients", "remarks": "rule_set_089" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_hourly", + "value": "package_tftp_removed", "remarks": "rule_set_090" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on cron.hourly", + "value": "Remove tftp Daemon", "remarks": "rule_set_090" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_hourly", + "value": "chronyd_specify_remote_server", "remarks": "rule_set_091" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on cron.hourly", + "value": "A remote time server for Chrony is configured", "remarks": "rule_set_091" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_daily", + "value": "chronyd_run_as_chrony_user", "remarks": "rule_set_092" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns cron.daily", + "value": "Ensure that chronyd is running under chrony user account", "remarks": "rule_set_092" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_daily", + "value": "package_cron_installed", "remarks": "rule_set_093" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on cron.daily", + "value": "Install the cron service", "remarks": "rule_set_093" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_daily", + "value": "service_crond_enabled", "remarks": "rule_set_094" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on cron.daily", + "value": "Enable cron Service", "remarks": "rule_set_094" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_weekly", + "value": "file_groupowner_crontab", "remarks": "rule_set_095" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns cron.weekly", + "value": "Verify Group Who Owns Crontab", "remarks": "rule_set_095" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_weekly", + "value": "file_owner_crontab", "remarks": "rule_set_096" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on cron.weekly", + "value": "Verify Owner on crontab", "remarks": "rule_set_096" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_weekly", + "value": "file_permissions_crontab", "remarks": "rule_set_097" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on cron.weekly", + "value": "Verify Permissions on crontab", "remarks": "rule_set_097" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_monthly", + "value": "file_groupowner_cron_hourly", "remarks": "rule_set_098" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns cron.monthly", + "value": "Verify Group Who Owns cron.hourly", "remarks": "rule_set_098" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_monthly", + "value": "file_owner_cron_hourly", "remarks": "rule_set_099" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on cron.monthly", + "value": "Verify Owner on cron.hourly", "remarks": "rule_set_099" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_monthly", + "value": "file_permissions_cron_hourly", "remarks": "rule_set_100" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on cron.monthly", + "value": "Verify Permissions on cron.hourly", "remarks": "rule_set_100" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_d", + "value": "file_groupowner_cron_daily", "remarks": "rule_set_101" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns cron.d", + "value": "Verify Group Who Owns cron.daily", "remarks": "rule_set_101" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_d", + "value": "file_owner_cron_daily", "remarks": "rule_set_102" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on cron.d", + "value": "Verify Owner on cron.daily", "remarks": "rule_set_102" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_d", + "value": "file_permissions_cron_daily", "remarks": "rule_set_103" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on cron.d", + "value": "Verify Permissions on cron.daily", "remarks": "rule_set_103" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_cron_deny_not_exist", + "value": "file_groupowner_cron_weekly", "remarks": "rule_set_104" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that /etc/cron.deny does not exist", + "value": "Verify Group Who Owns cron.weekly", "remarks": "rule_set_104" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_cron_allow_exists", + "value": "file_owner_cron_weekly", "remarks": "rule_set_105" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that /etc/cron.allow exists", + "value": "Verify Owner on cron.weekly", "remarks": "rule_set_105" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_allow", + "value": "file_permissions_cron_weekly", "remarks": "rule_set_106" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns /etc/cron.allow file", + "value": "Verify Permissions on cron.weekly", "remarks": "rule_set_106" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_allow", + "value": "file_groupowner_cron_monthly", "remarks": "rule_set_107" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns /etc/cron.allow file", + "value": "Verify Group Who Owns cron.monthly", "remarks": "rule_set_107" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_allow", + "value": "file_owner_cron_monthly", "remarks": "rule_set_108" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on /etc/cron.allow file", + "value": "Verify Owner on cron.monthly", "remarks": "rule_set_108" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_at_deny_not_exist", + "value": "file_permissions_cron_monthly", "remarks": "rule_set_109" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that /etc/at.deny does not exist", + "value": "Verify Permissions on cron.monthly", "remarks": "rule_set_109" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_at_allow", + "value": "file_groupowner_cron_d", "remarks": "rule_set_110" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns /etc/at.allow file", + "value": "Verify Group Who Owns cron.d", "remarks": "rule_set_110" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_at_allow", + "value": "file_owner_cron_d", "remarks": "rule_set_111" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns /etc/at.allow file", + "value": "Verify Owner on cron.d", "remarks": "rule_set_111" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_at_allow", + "value": "file_permissions_cron_d", "remarks": "rule_set_112" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on /etc/at.allow file", + "value": "Verify Permissions on cron.d", "remarks": "rule_set_112" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_ip_forward", + "value": "file_cron_deny_not_exist", "remarks": "rule_set_113" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for IP Forwarding on IPv4 Interfaces", + "value": "Ensure that /etc/cron.deny does not exist", "remarks": "rule_set_113" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_forwarding", + "value": "file_cron_allow_exists", "remarks": "rule_set_114" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for IPv6 Forwarding", + "value": "Ensure that /etc/cron.allow exists", "remarks": "rule_set_114" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_send_redirects", + "value": "file_groupowner_cron_allow", "remarks": "rule_set_115" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces", + "value": "Verify Group Who Owns /etc/cron.allow file", "remarks": "rule_set_115" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_send_redirects", + "value": "file_owner_cron_allow", "remarks": "rule_set_116" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces by Default", + "value": "Verify User Who Owns /etc/cron.allow file", "remarks": "rule_set_116" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses", + "value": "file_permissions_cron_allow", "remarks": "rule_set_117" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Ignore Bogus ICMP Error Responses on IPv4 Interfaces", + "value": "Verify Permissions on /etc/cron.allow file", "remarks": "rule_set_117" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts", + "value": "file_at_deny_not_exist", "remarks": "rule_set_118" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Ignore ICMP Broadcast Echo Requests on IPv4 Interfaces", + "value": "Ensure that /etc/at.deny does not exist", "remarks": "rule_set_118" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_accept_redirects", + "value": "file_groupowner_at_allow", "remarks": "rule_set_119" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Accepting ICMP Redirects for All IPv4 Interfaces", + "value": "Verify Group Who Owns /etc/at.allow file", "remarks": "rule_set_119" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_accept_redirects", + "value": "file_owner_at_allow", "remarks": "rule_set_120" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 Interfaces", + "value": "Verify User Who Owns /etc/at.allow file", "remarks": "rule_set_120" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_redirects", + "value": "file_permissions_at_allow", "remarks": "rule_set_121" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Accepting ICMP Redirects for All IPv6 Interfaces", + "value": "Verify Permissions on /etc/at.allow file", "remarks": "rule_set_121" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_redirects", + "value": "kernel_module_atm_disabled", "remarks": "rule_set_122" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces", + "value": "Disable ATM Support", "remarks": "rule_set_122" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_secure_redirects", + "value": "kernel_module_can_disabled", "remarks": "rule_set_123" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces", + "value": "Disable CAN Support", "remarks": "rule_set_123" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_secure_redirects", + "value": "kernel_module_dccp_disabled", "remarks": "rule_set_124" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Kernel Parameter for Accepting Secure Redirects By Default", + "value": "Disable DCCP Support", "remarks": "rule_set_124" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_rp_filter", + "value": "kernel_module_tipc_disabled", "remarks": "rule_set_125" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces", + "value": "Disable TIPC Support", "remarks": "rule_set_125" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_rp_filter", + "value": "kernel_module_rds_disabled", "remarks": "rule_set_126" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces by Default", + "value": "Disable RDS Support", "remarks": "rule_set_126" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_accept_source_route", + "value": "kernel_module_sctp_disabled", "remarks": "rule_set_127" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces", + "value": "Disable SCTP Support", "remarks": "rule_set_127" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_accept_source_route", + "value": "sysctl_net_ipv4_ip_forward", "remarks": "rule_set_128" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces by Default", + "value": "Disable Kernel Parameter for IP Forwarding on IPv4 Interfaces", "remarks": "rule_set_128" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_source_route", + "value": "sysctl_net_ipv4_conf_all_forwarding", "remarks": "rule_set_129" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces", + "value": "Disable Kernel Parameter for IPv4 Forwarding on all IPv4 Interfaces", "remarks": "rule_set_129" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_source_route", + "value": "sysctl_net_ipv4_conf_all_send_redirects", "remarks": "rule_set_130" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces by Default", + "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces", "remarks": "rule_set_130" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_log_martians", + "value": "sysctl_net_ipv4_conf_default_send_redirects", "remarks": "rule_set_131" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces", + "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces by Default", "remarks": "rule_set_131" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_log_martians", + "value": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses", "remarks": "rule_set_132" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Paremeter to Log Martian Packets on all IPv4 Interfaces by Default", + "value": "Enable Kernel Parameter to Ignore Bogus ICMP Error Responses on IPv4 Interfaces", "remarks": "rule_set_132" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_tcp_syncookies", + "value": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts", "remarks": "rule_set_133" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces", + "value": "Enable Kernel Parameter to Ignore ICMP Broadcast Echo Requests on IPv4 Interfaces", "remarks": "rule_set_133" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_ra", + "value": "sysctl_net_ipv4_conf_all_accept_redirects", "remarks": "rule_set_134" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Accepting Router Advertisements on All IPv6 Interfaces", + "value": "Disable Accepting ICMP Redirects for All IPv4 Interfaces", "remarks": "rule_set_134" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_ra", + "value": "sysctl_net_ipv4_conf_default_accept_redirects", "remarks": "rule_set_135" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Accepting Router Advertisements on all IPv6 Interfaces by Default", + "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 Interfaces", "remarks": "rule_set_135" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_nftables_installed", + "value": "sysctl_net_ipv4_conf_all_secure_redirects", "remarks": "rule_set_136" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install nftables Package", + "value": "Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces", "remarks": "rule_set_136" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_firewalld_enabled", + "value": "sysctl_net_ipv4_conf_default_secure_redirects", "remarks": "rule_set_137" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify firewalld Enabled", + "value": "Configure Kernel Parameter for Accepting Secure Redirects By Default", "remarks": "rule_set_137" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_firewalld_installed", + "value": "sysctl_net_ipv4_conf_all_rp_filter", "remarks": "rule_set_138" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install firewalld Package", + "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces", "remarks": "rule_set_138" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_nftables_disabled", + "value": "sysctl_net_ipv4_conf_default_rp_filter", "remarks": "rule_set_139" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify nftables Service is Disabled", + "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces by Default", "remarks": "rule_set_139" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "firewalld_loopback_traffic_trusted", + "value": "sysctl_net_ipv4_conf_all_accept_source_route", "remarks": "rule_set_140" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Firewalld to Trust Loopback Traffic", + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces", "remarks": "rule_set_140" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "firewalld_loopback_traffic_restricted", + "value": "sysctl_net_ipv4_conf_default_accept_source_route", "remarks": "rule_set_141" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Firewalld to Restrict Loopback Traffic", + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces by Default", "remarks": "rule_set_141" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_sshd_config", + "value": "sysctl_net_ipv4_conf_all_log_martians", "remarks": "rule_set_142" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns SSH Server config file", + "value": "Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces", "remarks": "rule_set_142" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_sshd_config", + "value": "sysctl_net_ipv4_conf_default_log_martians", "remarks": "rule_set_143" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on SSH Server config file", + "value": "Enable Kernel Paremeter to Log Martian Packets on all IPv4 Interfaces by Default", "remarks": "rule_set_143" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_config", + "value": "sysctl_net_ipv4_tcp_syncookies", "remarks": "rule_set_144" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on SSH Server config file", + "value": "Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces", "remarks": "rule_set_144" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_private_key", + "value": "sysctl_net_ipv6_conf_all_forwarding", "remarks": "rule_set_145" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on SSH Server Private *_key Key Files", + "value": "Disable Kernel Parameter for IPv6 Forwarding", "remarks": "rule_set_145" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_private_key", + "value": "sysctl_net_ipv6_conf_default_forwarding", "remarks": "rule_set_146" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Ownership on SSH Server Private *_key Key Files", + "value": "Disable Kernel Parameter for IPv6 Forwarding by default", "remarks": "rule_set_146" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_sshd_private_key", + "value": "sysctl_net_ipv6_conf_all_accept_redirects", "remarks": "rule_set_147" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Ownership on SSH Server Private *_key Key Files", + "value": "Disable Accepting ICMP Redirects for All IPv6 Interfaces", "remarks": "rule_set_147" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_pub_key", + "value": "sysctl_net_ipv6_conf_default_accept_redirects", "remarks": "rule_set_148" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on SSH Server Public *.pub Key Files", + "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces", "remarks": "rule_set_148" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_pub_key", + "value": "sysctl_net_ipv6_conf_all_accept_source_route", "remarks": "rule_set_149" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Ownership on SSH Server Public *.pub Key Files", + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces", "remarks": "rule_set_149" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_sshd_pub_key", + "value": "sysctl_net_ipv6_conf_default_accept_source_route", "remarks": "rule_set_150" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Ownership on SSH Server Public *.pub Key Files", + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces by Default", "remarks": "rule_set_150" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_kex", + "value": "sysctl_net_ipv6_conf_all_accept_ra", "remarks": "rule_set_151" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Use Only Strong Key Exchange algorithms", + "value": "Configure Accepting Router Advertisements on All IPv6 Interfaces", "remarks": "rule_set_151" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_macs", + "value": "sysctl_net_ipv6_conf_default_accept_ra", "remarks": "rule_set_152" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Use Only Strong MACs", + "value": "Disable Accepting Router Advertisements on all IPv6 Interfaces by Default", "remarks": "rule_set_152" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_limit_user_access", + "value": "package_firewalld_installed", "remarks": "rule_set_153" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Limit Users' SSH Access", + "value": "Install firewalld Package", "remarks": "rule_set_153" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_enable_warning_banner_net", + "value": "service_firewalld_enabled", "remarks": "rule_set_154" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable SSH Warning Banner", + "value": "Verify firewalld Enabled", "remarks": "rule_set_154" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_idle_timeout", + "value": "firewalld_loopback_traffic_trusted", "remarks": "rule_set_155" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set SSH Client Alive Interval", + "value": "Configure Firewalld to Trust Loopback Traffic", "remarks": "rule_set_155" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_keepalive", + "value": "firewalld_loopback_traffic_restricted", "remarks": "rule_set_156" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set SSH Client Alive Count Max", + "value": "Configure Firewalld to Restrict Loopback Traffic", "remarks": "rule_set_156" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_gssapi_auth", + "value": "file_groupowner_sshd_config", "remarks": "rule_set_157" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable GSSAPI Authentication", + "value": "Verify Group Who Owns SSH Server config file", "remarks": "rule_set_157" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "disable_host_auth", + "value": "file_owner_sshd_config", "remarks": "rule_set_158" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Host-Based Authentication", + "value": "Verify Owner on SSH Server config file", "remarks": "rule_set_158" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_rhosts", + "value": "file_permissions_sshd_config", "remarks": "rule_set_159" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable SSH Support for .rhosts Files", + "value": "Verify Permissions on SSH Server config file", "remarks": "rule_set_159" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_login_grace_time", + "value": "file_groupownership_sshd_private_key", "remarks": "rule_set_160" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure SSH LoginGraceTime is configured", + "value": "Verify Group Ownership on SSH Server Private *_key Key Files", "remarks": "rule_set_160" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_loglevel_verbose", + "value": "file_ownership_sshd_private_key", "remarks": "rule_set_161" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set SSH Daemon LogLevel to VERBOSE", + "value": "Verify Ownership on SSH Server Private *_key Key Files", "remarks": "rule_set_161" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_max_auth_tries", + "value": "file_permissions_sshd_private_key", "remarks": "rule_set_162" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set SSH authentication attempt limit", + "value": "Verify Permissions on SSH Server Private *_key Key Files", "remarks": "rule_set_162" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_maxstartups", + "value": "file_groupownership_sshd_pub_key", "remarks": "rule_set_163" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure SSH MaxStartups is configured", + "value": "Verify Group Ownership on SSH Server Public *.pub Key Files", "remarks": "rule_set_163" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_max_sessions", + "value": "file_ownership_sshd_pub_key", "remarks": "rule_set_164" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set SSH MaxSessions limit", + "value": "Verify Ownership on SSH Server Public *.pub Key Files", "remarks": "rule_set_164" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_empty_passwords", + "value": "file_permissions_sshd_pub_key", "remarks": "rule_set_165" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable SSH Access via Empty Passwords", + "value": "Verify Permissions on SSH Server Public *.pub Key Files", "remarks": "rule_set_165" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_root_login", + "value": "sshd_limit_user_access", "remarks": "rule_set_166" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable SSH Root Login", + "value": "Limit Users' SSH Access", "remarks": "rule_set_166" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_do_not_permit_user_env", + "value": "sshd_enable_warning_banner_net", "remarks": "rule_set_167" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Do Not Allow SSH Environment Options", + "value": "Enable SSH Warning Banner", "remarks": "rule_set_167" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_enable_pam", + "value": "sshd_set_idle_timeout", "remarks": "rule_set_168" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable PAM", + "value": "Set SSH Client Alive Interval", "remarks": "rule_set_168" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_sudo_installed", + "value": "sshd_set_keepalive", "remarks": "rule_set_169" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install sudo Package", + "value": "Set SSH Client Alive Count Max", "remarks": "rule_set_169" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_add_use_pty", + "value": "sshd_disable_forwarding", "remarks": "rule_set_170" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Only Users Logged In To Real tty Can Execute Sudo - sudo use_pty", + "value": "Disable SSH Forwarding", "remarks": "rule_set_170" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_custom_logfile", + "value": "sshd_disable_gssapi_auth", "remarks": "rule_set_171" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Sudo Logfile Exists - sudo logfile", + "value": "Disable GSSAPI Authentication", "remarks": "rule_set_171" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_require_reauthentication", + "value": "disable_host_auth", "remarks": "rule_set_172" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Require Re-Authentication When Using the sudo Command", + "value": "Disable Host-Based Authentication", "remarks": "rule_set_172" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "use_pam_wheel_group_for_su", + "value": "sshd_disable_rhosts", "remarks": "rule_set_173" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enforce Usage of pam_wheel with Group Parameter for su Authentication", + "value": "Disable SSH Support for .rhosts Files", "remarks": "rule_set_173" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_pam_wheel_group_empty", + "value": "sshd_use_strong_kex", "remarks": "rule_set_174" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure the Group Used by pam_wheel.so Module Exists on System and is Empty", + "value": "Use Only Strong Key Exchange algorithms", "remarks": "rule_set_174" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_pam_pwquality_installed", + "value": "sshd_set_login_grace_time", "remarks": "rule_set_175" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install pam_pwquality Package", + "value": "Ensure SSH LoginGraceTime is configured", "remarks": "rule_set_175" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_password_auth", + "value": "sshd_set_loglevel_verbose", "remarks": "rule_set_176" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth File.", + "value": "Set SSH Daemon LogLevel to VERBOSE", "remarks": "rule_set_176" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_system_auth", + "value": "sshd_use_strong_macs", "remarks": "rule_set_177" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth File.", + "value": "Use Only Strong MACs", "remarks": "rule_set_177" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_deny", + "value": "sshd_set_max_auth_tries", "remarks": "rule_set_178" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Lock Accounts After Failed Password Attempts", + "value": "Set SSH authentication attempt limit", "remarks": "rule_set_178" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_unlock_time", + "value": "sshd_set_maxstartups", "remarks": "rule_set_179" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Lockout Time for Failed Password Attempts", + "value": "Ensure SSH MaxStartups is configured", "remarks": "rule_set_179" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_difok", + "value": "sshd_set_max_sessions", "remarks": "rule_set_180" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure PAM Enforces Password Requirements - Minimum Different Characters", + "value": "Set SSH MaxSessions limit", "remarks": "rule_set_180" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_minlen", + "value": "sshd_disable_empty_passwords", "remarks": "rule_set_181" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure PAM Enforces Password Requirements - Minimum Length", + "value": "Disable SSH Access via Empty Passwords", "remarks": "rule_set_181" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_minclass", + "value": "sshd_disable_root_login", "remarks": "rule_set_182" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure PAM Enforces Password Requirements - Minimum Different Categories", + "value": "Disable SSH Root Login", "remarks": "rule_set_182" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_maxrepeat", + "value": "sshd_do_not_permit_user_env", "remarks": "rule_set_183" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Password Maximum Consecutive Repeating Characters", + "value": "Do Not Allow SSH Environment Options", "remarks": "rule_set_183" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_dictcheck", + "value": "sshd_enable_pam", "remarks": "rule_set_184" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure PAM Enforces Password Requirements - Prevent the Use of Dictionary Words", + "value": "Enable PAM", "remarks": "rule_set_184" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_enforce_root", + "value": "package_sudo_installed", "remarks": "rule_set_185" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure PAM Enforces Password Requirements - Enforce for root User", + "value": "Install sudo Package", "remarks": "rule_set_185" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_pwhistory_remember_password_auth", + "value": "sudo_add_use_pty", "remarks": "rule_set_186" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Limit Password Reuse: password-auth", + "value": "Ensure Only Users Logged In To Real tty Can Execute Sudo - sudo use_pty", "remarks": "rule_set_186" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_pwhistory_remember_system_auth", + "value": "sudo_custom_logfile", "remarks": "rule_set_187" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Limit Password Reuse: system-auth", + "value": "Ensure Sudo Logfile Exists - sudo logfile", "remarks": "rule_set_187" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_empty_passwords", + "value": "sudo_require_authentication", "remarks": "rule_set_188" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Prevent Login to Accounts With Empty Password", + "value": "Ensure Users Re-Authenticate for Privilege Escalation - sudo", "remarks": "rule_set_188" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_systemauth", + "value": "sudo_require_reauthentication", "remarks": "rule_set_189" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set PAM''s Password Hashing Algorithm", + "value": "Require Re-Authentication When Using the sudo Command", "remarks": "rule_set_189" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_passwordauth", + "value": "use_pam_wheel_group_for_su", "remarks": "rule_set_190" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set PAM''s Password Hashing Algorithm - password-auth", + "value": "Enforce Usage of pam_wheel with Group Parameter for su Authentication", "remarks": "rule_set_190" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_maximum_age_login_defs", + "value": "ensure_pam_wheel_group_empty", "remarks": "rule_set_191" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Password Maximum Age", + "value": "Ensure the Group Used by pam_wheel.so Module Exists on System and is Empty", "remarks": "rule_set_191" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_set_max_life_existing", + "value": "account_password_pam_faillock_password_auth", "remarks": "rule_set_192" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Existing Passwords Maximum Age", + "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth File.", "remarks": "rule_set_192" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_warn_age_login_defs", + "value": "account_password_pam_faillock_system_auth", "remarks": "rule_set_193" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Password Warning Age", + "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth File.", "remarks": "rule_set_193" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_set_warn_age_existing", + "value": "package_pam_pwquality_installed", "remarks": "rule_set_194" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Existing Passwords Warning Age", + "value": "Install pam_pwquality Package", "remarks": "rule_set_194" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_libuserconf", + "value": "accounts_passwords_pam_faillock_deny", "remarks": "rule_set_195" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Password Hashing Algorithm in /etc/libuser.conf", + "value": "Lock Accounts After Failed Password Attempts", "remarks": "rule_set_195" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_logindefs", + "value": "accounts_passwords_pam_faillock_unlock_time", "remarks": "rule_set_196" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Password Hashing Algorithm in /etc/login.defs", + "value": "Set Lockout Time for Failed Password Attempts", "remarks": "rule_set_196" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_disable_post_pw_expiration", + "value": "accounts_password_pam_difok", "remarks": "rule_set_197" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Account Expiration Following Inactivity", + "value": "Ensure PAM Enforces Password Requirements - Minimum Different Characters", "remarks": "rule_set_197" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_set_post_pw_existing", + "value": "accounts_password_pam_minlen", "remarks": "rule_set_198" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set existing passwords a period of inactivity before they been locked", + "value": "Ensure PAM Enforces Password Requirements - Minimum Length", "remarks": "rule_set_198" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_last_change_is_in_past", + "value": "accounts_password_pam_minclass", "remarks": "rule_set_199" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure all users last password change date is in the past", + "value": "Ensure PAM Enforces Password Requirements - Minimum Different Categories", "remarks": "rule_set_199" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_no_uid_except_zero", + "value": "accounts_password_pam_maxrepeat", "remarks": "rule_set_200" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Only Root Has UID 0", + "value": "Set Password Maximum Consecutive Repeating Characters", "remarks": "rule_set_200" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_root_gid_zero", + "value": "accounts_password_pam_dictcheck", "remarks": "rule_set_201" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Root Has A Primary GID 0", + "value": "Ensure PAM Enforces Password Requirements - Prevent the Use of Dictionary Words", "remarks": "rule_set_201" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_root_password_configured", + "value": "accounts_password_pam_enforce_root", "remarks": "rule_set_202" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Authentication Required for Single User Mode", + "value": "Ensure PAM Enforces Password Requirements - Enforce for root User", "remarks": "rule_set_202" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_root_path_dirs_no_write", + "value": "accounts_password_pam_pwhistory_remember_password_auth", "remarks": "rule_set_203" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that Root's Path Does Not Include World or Group-Writable Directories", + "value": "Limit Password Reuse: password-auth", "remarks": "rule_set_203" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "root_path_no_dot", + "value": "accounts_password_pam_pwhistory_remember_system_auth", "remarks": "rule_set_204" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that Root's Path Does Not Include Relative Paths or Null Directories", + "value": "Limit Password Reuse: system-auth", "remarks": "rule_set_204" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_password_auth_for_systemaccounts", + "value": "no_empty_passwords", "remarks": "rule_set_205" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that System Accounts Are Locked", + "value": "Prevent Login to Accounts With Empty Password", "remarks": "rule_set_205" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_shelllogin_for_systemaccounts", + "value": "set_password_hashing_algorithm_systemauth", "remarks": "rule_set_206" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that System Accounts Do Not Run a Shell Upon Login", + "value": "Set PAM''s Password Hashing Algorithm", "remarks": "rule_set_206" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_tmout", + "value": "set_password_hashing_algorithm_passwordauth", "remarks": "rule_set_207" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Interactive Session Timeout", + "value": "Set PAM''s Password Hashing Algorithm - password-auth", "remarks": "rule_set_207" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_umask_etc_bashrc", + "value": "accounts_maximum_age_login_defs", "remarks": "rule_set_208" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure the Default Bash Umask is Set Correctly", + "value": "Set Password Maximum Age", "remarks": "rule_set_208" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_umask_etc_login_defs", + "value": "accounts_password_set_max_life_existing", "remarks": "rule_set_209" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure the Default Umask is Set Correctly in login.defs", + "value": "Set Existing Passwords Maximum Age", "remarks": "rule_set_209" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_umask_etc_profile", + "value": "accounts_password_warn_age_login_defs", "remarks": "rule_set_210" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure the Default Umask is Set Correctly in /etc/profile", + "value": "Set Password Warning Age", "remarks": "rule_set_210" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_aide_installed", + "value": "accounts_password_set_warn_age_existing", "remarks": "rule_set_211" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install AIDE", + "value": "Set Existing Passwords Warning Age", "remarks": "rule_set_211" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "aide_build_database", + "value": "set_password_hashing_algorithm_libuserconf", "remarks": "rule_set_212" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Build and Test AIDE Database", + "value": "Set Password Hashing Algorithm in /etc/libuser.conf", "remarks": "rule_set_212" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "aide_periodic_cron_checking", + "value": "set_password_hashing_algorithm_logindefs", "remarks": "rule_set_213" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Periodic Execution of AIDE", + "value": "Set Password Hashing Algorithm in /etc/login.defs", "remarks": "rule_set_213" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "aide_check_audit_tools", + "value": "account_disable_post_pw_expiration", "remarks": "rule_set_214" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure AIDE to Verify the Audit Tools", + "value": "Set Account Expiration Following Inactivity", "remarks": "rule_set_214" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_systemd-journald_enabled", + "value": "accounts_set_post_pw_existing", "remarks": "rule_set_215" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable systemd-journald Service", + "value": "Set existing passwords a period of inactivity before they been locked", "remarks": "rule_set_215" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_systemd-journal-remote_installed", + "value": "accounts_password_last_change_is_in_past", "remarks": "rule_set_216" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install systemd-journal-remote Package", + "value": "Ensure all users last password change date is in the past", "remarks": "rule_set_216" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "socket_systemd-journal-remote_disabled", + "value": "accounts_no_uid_except_zero", "remarks": "rule_set_217" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable systemd-journal-remote Socket", + "value": "Verify Only Root Has UID 0", "remarks": "rule_set_217" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_compress", + "value": "accounts_root_gid_zero", "remarks": "rule_set_218" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure journald is configured to compress large log files", + "value": "Verify Root Has A Primary GID 0", "remarks": "rule_set_218" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_storage", + "value": "groups_no_zero_gid_except_root", "remarks": "rule_set_219" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure journald is configured to write log files to persistent disk", + "value": "Verify Only Group Root Has GID 0", "remarks": "rule_set_219" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "rsyslog_files_groupownership", + "value": "ensure_root_password_configured", "remarks": "rule_set_220" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Log Files Are Owned By Appropriate Group", + "value": "Ensure Authentication Required for Single User Mode", "remarks": "rule_set_220" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "rsyslog_files_ownership", + "value": "accounts_root_path_dirs_no_write", "remarks": "rule_set_221" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Log Files Are Owned By Appropriate User", + "value": "Ensure that Root's Path Does Not Include World or Group-Writable Directories", "remarks": "rule_set_221" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "rsyslog_files_permissions", + "value": "root_path_no_dot", "remarks": "rule_set_222" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure System Log Files Have Correct Permissions", + "value": "Ensure that Root's Path Does Not Include Relative Paths or Null Directories", "remarks": "rule_set_222" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_passwd", + "value": "accounts_umask_root", "remarks": "rule_set_223" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns passwd File", + "value": "Ensure the Root Bash Umask is Set Correctly", "remarks": "rule_set_223" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_passwd", + "value": "no_password_auth_for_systemaccounts", "remarks": "rule_set_224" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns passwd File", + "value": "Ensure that System Accounts Are Locked", "remarks": "rule_set_224" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_passwd", + "value": "no_shelllogin_for_systemaccounts", "remarks": "rule_set_225" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on passwd File", + "value": "Ensure that System Accounts Do Not Run a Shell Upon Login", "remarks": "rule_set_225" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_passwd", + "value": "accounts_tmout", "remarks": "rule_set_226" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns Backup passwd File", + "value": "Set Interactive Session Timeout", "remarks": "rule_set_226" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_passwd", + "value": "accounts_umask_etc_bashrc", "remarks": "rule_set_227" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns Backup passwd File", + "value": "Ensure the Default Bash Umask is Set Correctly", "remarks": "rule_set_227" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_passwd", + "value": "accounts_umask_etc_login_defs", "remarks": "rule_set_228" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on Backup passwd File", + "value": "Ensure the Default Umask is Set Correctly in login.defs", "remarks": "rule_set_228" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_group", + "value": "accounts_umask_etc_profile", "remarks": "rule_set_229" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns group File", + "value": "Ensure the Default Umask is Set Correctly in /etc/profile", "remarks": "rule_set_229" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_group", + "value": "package_aide_installed", "remarks": "rule_set_230" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns group File", + "value": "Install AIDE", "remarks": "rule_set_230" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_group", + "value": "aide_build_database", "remarks": "rule_set_231" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on group File", + "value": "Build and Test AIDE Database", "remarks": "rule_set_231" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_group", + "value": "aide_periodic_cron_checking", "remarks": "rule_set_232" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns Backup group File", + "value": "Configure Periodic Execution of AIDE", "remarks": "rule_set_232" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_group", + "value": "aide_check_audit_tools", "remarks": "rule_set_233" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns Backup group File", + "value": "Configure AIDE to Verify the Audit Tools", "remarks": "rule_set_233" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_group", + "value": "service_systemd-journald_enabled", "remarks": "rule_set_234" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on Backup group File", + "value": "Enable systemd-journald Service", "remarks": "rule_set_234" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_shadow", + "value": "journald_compress", "remarks": "rule_set_235" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns shadow File", + "value": "Ensure journald is configured to compress large log files", "remarks": "rule_set_235" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_shadow", + "value": "journald_storage", "remarks": "rule_set_236" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns shadow File", + "value": "Ensure journald is configured to write log files to persistent disk", "remarks": "rule_set_236" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_shadow", + "value": "package_systemd-journal-remote_installed", "remarks": "rule_set_237" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on shadow File", + "value": "Install systemd-journal-remote Package", "remarks": "rule_set_237" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_shadow", + "value": "socket_systemd-journal-remote_disabled", "remarks": "rule_set_238" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns Backup shadow File", + "value": "Disable systemd-journal-remote Socket", "remarks": "rule_set_238" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_shadow", + "value": "rsyslog_files_groupownership", "remarks": "rule_set_239" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns Backup shadow File", + "value": "Ensure Log Files Are Owned By Appropriate Group", "remarks": "rule_set_239" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_shadow", + "value": "rsyslog_files_ownership", "remarks": "rule_set_240" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on Backup shadow File", + "value": "Ensure Log Files Are Owned By Appropriate User", "remarks": "rule_set_240" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_gshadow", + "value": "rsyslog_files_permissions", "remarks": "rule_set_241" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns gshadow File", + "value": "Ensure System Log Files Have Correct Permissions", "remarks": "rule_set_241" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_gshadow", + "value": "file_groupowner_etc_passwd", "remarks": "rule_set_242" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns gshadow File", + "value": "Verify Group Who Owns passwd File", "remarks": "rule_set_242" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_gshadow", + "value": "file_owner_etc_passwd", "remarks": "rule_set_243" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on gshadow File", + "value": "Verify User Who Owns passwd File", "remarks": "rule_set_243" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_gshadow", + "value": "file_permissions_etc_passwd", "remarks": "rule_set_244" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns Backup gshadow File", + "value": "Verify Permissions on passwd File", "remarks": "rule_set_244" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_gshadow", + "value": "file_groupowner_backup_etc_passwd", "remarks": "rule_set_245" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns Backup gshadow File", + "value": "Verify Group Who Owns Backup passwd File", "remarks": "rule_set_245" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_gshadow", + "value": "file_owner_backup_etc_passwd", "remarks": "rule_set_246" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on Backup gshadow File", + "value": "Verify User Who Owns Backup passwd File", "remarks": "rule_set_246" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_shells", + "value": "file_permissions_backup_etc_passwd", "remarks": "rule_set_247" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns /etc/shells File", + "value": "Verify Permissions on Backup passwd File", "remarks": "rule_set_247" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_shells", + "value": "file_groupowner_etc_group", "remarks": "rule_set_248" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Who Owns /etc/shells File", + "value": "Verify Group Who Owns group File", "remarks": "rule_set_248" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_shells", + "value": "file_owner_etc_group", "remarks": "rule_set_249" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on /etc/shells File", + "value": "Verify User Who Owns group File", "remarks": "rule_set_249" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_etc_security_opasswd", + "value": "file_permissions_etc_group", "remarks": "rule_set_250" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions and Ownership of Old Passwords File", + "value": "Verify Permissions on group File", "remarks": "rule_set_250" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_unauthorized_world_writable", + "value": "file_groupowner_backup_etc_group", "remarks": "rule_set_251" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure No World-Writable Files Exist", + "value": "Verify Group Who Owns Backup group File", "remarks": "rule_set_251" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dir_perms_world_writable_sticky_bits", + "value": "file_owner_backup_etc_group", "remarks": "rule_set_252" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify that All World-Writable Directories Have Sticky Bits Set", + "value": "Verify User Who Owns Backup group File", "remarks": "rule_set_252" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_files_unowned_by_user", + "value": "file_permissions_backup_etc_group", "remarks": "rule_set_253" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Files Are Owned by a User", + "value": "Verify Permissions on Backup group File", "remarks": "rule_set_253" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_ungroupowned", + "value": "file_owner_etc_shadow", "remarks": "rule_set_254" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Files Are Owned by a Group", + "value": "Verify User Who Owns shadow File", "remarks": "rule_set_254" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_all_shadowed", + "value": "file_groupowner_etc_shadow", "remarks": "rule_set_255" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify All Account Password Hashes are Shadowed", + "value": "Verify Group Who Owns shadow File", "remarks": "rule_set_255" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_empty_passwords_etc_shadow", + "value": "file_permissions_etc_shadow", "remarks": "rule_set_256" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure There Are No Accounts With Blank or Null Passwords", + "value": "Verify Permissions on shadow File", "remarks": "rule_set_256" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "gid_passwd_group_same", + "value": "file_groupowner_backup_etc_shadow", "remarks": "rule_set_257" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "All GIDs referenced in /etc/passwd must be defined in /etc/group", + "value": "Verify User Who Owns Backup shadow File", "remarks": "rule_set_257" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_unique_id", + "value": "file_owner_backup_etc_shadow", "remarks": "rule_set_258" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Accounts on the System Have Unique User IDs", + "value": "Verify Group Who Owns Backup shadow File", "remarks": "rule_set_258" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "group_unique_id", + "value": "file_permissions_backup_etc_shadow", "remarks": "rule_set_259" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Groups on the System Have Unique Group ID", + "value": "Verify Permissions on Backup shadow File", "remarks": "rule_set_259" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_unique_name", + "value": "file_groupowner_etc_gshadow", "remarks": "rule_set_260" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Accounts on the System Have Unique Names", + "value": "Verify Group Who Owns gshadow File", "remarks": "rule_set_260" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "group_unique_name", + "value": "file_owner_etc_gshadow", "remarks": "rule_set_261" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Groups on the System Have Unique Group Names", + "value": "Verify User Who Owns gshadow File", "remarks": "rule_set_261" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_user_interactive_home_directory_exists", + "value": "file_permissions_etc_gshadow", "remarks": "rule_set_262" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "All Interactive Users Home Directories Must Exist", + "value": "Verify Permissions on gshadow File", "remarks": "rule_set_262" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_home_directories", + "value": "file_groupowner_backup_etc_gshadow", "remarks": "rule_set_263" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "All Interactive User Home Directories Must Be Owned By The Primary User", + "value": "Verify Group Who Owns Backup gshadow File", "remarks": "rule_set_263" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_home_directories", + "value": "file_owner_backup_etc_gshadow", "remarks": "rule_set_264" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "All Interactive User Home Directories Must Have mode 0750 Or Less Permissive", + "value": "Verify User Who Owns Backup gshadow File", "remarks": "rule_set_264" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_user_dot_group_ownership", + "value": "file_permissions_backup_etc_gshadow", "remarks": "rule_set_265" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "User Initialization Files Must Be Group-Owned By The Primary Group", + "value": "Verify Permissions on Backup gshadow File", "remarks": "rule_set_265" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_user_dot_user_ownership", + "value": "file_groupowner_etc_shells", "remarks": "rule_set_266" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "User Initialization Files Must Be Owned By the Primary User", + "value": "Verify Group Who Owns /etc/shells File", "remarks": "rule_set_266" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_user_dot_no_world_writable_programs", + "value": "file_owner_etc_shells", "remarks": "rule_set_267" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "User Initialization Files Must Not Run World-Writable Programs", + "value": "Verify Who Owns /etc/shells File", "remarks": "rule_set_267" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permission_user_init_files", + "value": "file_permissions_etc_shells", "remarks": "rule_set_268" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All User Initialization Files Have Mode 0740 Or Less Permissive", + "value": "Verify Permissions on /etc/shells File", "remarks": "rule_set_268" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_forward_files", + "value": "file_etc_security_opasswd", "remarks": "rule_set_269" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify No .forward Files Exist", + "value": "Verify Permissions and Ownership of Old Passwords File", "remarks": "rule_set_269" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_netrc_files", + "value": "file_permissions_unauthorized_world_writable", "remarks": "rule_set_270" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify No netrc Files Exist", + "value": "Ensure No World-Writable Files Exist", "remarks": "rule_set_270" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_squashfs_disabled", + "value": "dir_perms_world_writable_sticky_bits", "remarks": "rule_set_271" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Mounting of squashfs", + "value": "Verify that All World-Writable Directories Have Sticky Bits Set", "remarks": "rule_set_271" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_udf_disabled", + "value": "no_files_unowned_by_user", "remarks": "rule_set_272" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Mounting of udf", + "value": "Ensure All Files Are Owned by a User", "remarks": "rule_set_272" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_usb-storage_disabled", + "value": "file_permissions_ungroupowned", "remarks": "rule_set_273" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Modprobe Loading of USB Storage Driver", + "value": "Ensure All Files Are Owned by a Group", "remarks": "rule_set_273" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_home", + "value": "accounts_password_all_shadowed", "remarks": "rule_set_274" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /home Located On Separate Partition", + "value": "Verify All Account Password Hashes are Shadowed", "remarks": "rule_set_274" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_var", + "value": "no_empty_passwords_etc_shadow", "remarks": "rule_set_275" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /var Located On Separate Partition", + "value": "Ensure There Are No Accounts With Blank or Null Passwords", "remarks": "rule_set_275" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_var_tmp", + "value": "gid_passwd_group_same", "remarks": "rule_set_276" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /var/tmp Located On Separate Partition", + "value": "All GIDs referenced in /etc/passwd must be defined in /etc/group", "remarks": "rule_set_276" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_var_log", + "value": "account_unique_id", "remarks": "rule_set_277" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /var/log Located On Separate Partition", + "value": "Ensure All Accounts on the System Have Unique User IDs", "remarks": "rule_set_277" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_var_log_audit", + "value": "group_unique_id", "remarks": "rule_set_278" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /var/log/audit Located On Separate Partition", + "value": "Ensure All Groups on the System Have Unique Group ID", "remarks": "rule_set_278" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "selinux_state", + "value": "account_unique_name", "remarks": "rule_set_279" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure SELinux State is Enforcing", + "value": "Ensure All Accounts on the System Have Unique Names", "remarks": "rule_set_279" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_automount", + "value": "group_unique_name", "remarks": "rule_set_280" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable GNOME3 Automounting", + "value": "Ensure All Groups on the System Have Unique Group Names", "remarks": "rule_set_280" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_automount_open", + "value": "accounts_user_interactive_home_directory_exists", "remarks": "rule_set_281" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable GNOME3 Automount Opening", + "value": "All Interactive Users Home Directories Must Exist", "remarks": "rule_set_281" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_autofs_disabled", + "value": "file_ownership_home_directories", "remarks": "rule_set_282" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable the Automounter", + "value": "All Interactive User Home Directories Must Be Owned By The Primary User", "remarks": "rule_set_282" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_avahi-daemon_disabled", + "value": "file_permissions_home_directories", "remarks": "rule_set_283" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Avahi Server Software", + "value": "All Interactive User Home Directories Must Have mode 0750 Or Less Permissive", "remarks": "rule_set_283" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_openldap-clients_removed", + "value": "accounts_user_dot_group_ownership", "remarks": "rule_set_284" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure LDAP client is not installed", + "value": "User Initialization Files Must Be Group-Owned By The Primary Group", "remarks": "rule_set_284" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_bluetooth_disabled", + "value": "accounts_user_dot_user_ownership", "remarks": "rule_set_285" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Bluetooth Service", + "value": "User Initialization Files Must Be Owned By the Primary User", "remarks": "rule_set_285" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_tipc_disabled", + "value": "accounts_user_dot_no_world_writable_programs", "remarks": "rule_set_286" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable TIPC Support", + "value": "User Initialization Files Must Not Run World-Writable Programs", "remarks": "rule_set_286" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_sctp_disabled", + "value": "file_permission_user_init_files", "remarks": "rule_set_287" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable SCTP Support", + "value": "Ensure All User Initialization Files Have Mode 0740 Or Less Permissive", "remarks": "rule_set_287" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_require_authentication", + "value": "no_forward_files", "remarks": "rule_set_288" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Users Re-Authenticate for Privilege Escalation - sudo", + "value": "Verify No .forward Files Exist", "remarks": "rule_set_288" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_deny_root", + "value": "no_netrc_files", "remarks": "rule_set_289" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure the root Account for Failed Password Attempts", + "value": "Verify No netrc Files Exist", "remarks": "rule_set_289" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_minimum_age_login_defs", + "value": "kernel_module_overlayfs_disabled", "remarks": "rule_set_290" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Password Minimum Age", + "value": "Ensure overlayfs kernel module is not available", "remarks": "rule_set_290" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_set_min_life_existing", + "value": "kernel_module_squashfs_disabled", "remarks": "rule_set_291" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Existing Passwords Minimum Age", + "value": "Disable Mounting of squashfs", "remarks": "rule_set_291" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_audit_installed", + "value": "kernel_module_udf_disabled", "remarks": "rule_set_292" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure the audit Subsystem is Installed", + "value": "Disable Mounting of udf", "remarks": "rule_set_292" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_audit-libs_installed", + "value": "kernel_module_firewire-core_disabled", "remarks": "rule_set_293" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure the audit-libs package as a part of audit Subsystem is Installed", + "value": "Disable IEEE 1394 (FireWire) Support", "remarks": "rule_set_293" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "grub2_audit_argument", + "value": "kernel_module_usb-storage_disabled", "remarks": "rule_set_294" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Auditing for Processes Which Start Prior to the Audit Daemon", + "value": "Disable Modprobe Loading of USB Storage Driver", "remarks": "rule_set_294" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "grub2_audit_backlog_limit_argument", + "value": "partition_for_home", "remarks": "rule_set_295" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Extend Audit Backlog Limit for the Audit Daemon", + "value": "Ensure /home Located On Separate Partition", "remarks": "rule_set_295" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_auditd_enabled", + "value": "partition_for_var", "remarks": "rule_set_296" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable auditd Service", + "value": "Ensure /var Located On Separate Partition", "remarks": "rule_set_296" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_retention_max_log_file", + "value": "partition_for_var_tmp", "remarks": "rule_set_297" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure auditd Max Log File Size", + "value": "Ensure /var/tmp Located On Separate Partition", "remarks": "rule_set_297" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_retention_max_log_file_action", + "value": "partition_for_var_log", "remarks": "rule_set_298" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure auditd max_log_file_action Upon Reaching Maximum Log Size", + "value": "Ensure /var/log Located On Separate Partition", "remarks": "rule_set_298" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_disk_error_action", + "value": "partition_for_var_log_audit", "remarks": "rule_set_299" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure auditd Disk Error Action on Disk Error", + "value": "Ensure /var/log/audit Located On Separate Partition", "remarks": "rule_set_299" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_disk_full_action", + "value": "selinux_state", "remarks": "rule_set_300" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure auditd Disk Full Action when Disk Space Is Full", + "value": "Ensure SELinux State is Enforcing", "remarks": "rule_set_300" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_retention_action_mail_acct", + "value": "sysctl_fs_protected_symlinks", "remarks": "rule_set_301" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure auditd mail_acct Action on Low Disk Space", + "value": "Enable Kernel Parameter to Enforce DAC on Symlinks", "remarks": "rule_set_301" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_retention_admin_space_left_action", + "value": "dconf_gnome_disable_automount", "remarks": "rule_set_302" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure auditd admin_space_left Action on Low Disk Space", + "value": "Disable GNOME3 Automounting", "remarks": "rule_set_302" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_retention_space_left_action", + "value": "dconf_gnome_disable_automount_open", "remarks": "rule_set_303" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure auditd space_left Action on Low Disk Space", + "value": "Disable GNOME3 Automount Opening", "remarks": "rule_set_303" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_sysadmin_actions", + "value": "service_autofs_disabled", "remarks": "rule_set_304" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects System Administrator Actions", + "value": "Disable the Automounter", "remarks": "rule_set_304" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_suid_auid_privilege_function", + "value": "service_avahi-daemon_disabled", "remarks": "rule_set_305" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events When Executables Are Run As Another User", + "value": "Disable Avahi Server Software", "remarks": "rule_set_305" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_sudo_log_events", + "value": "service_cockpit_disabled", "remarks": "rule_set_306" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Attempts to perform maintenance activities", + "value": "Disable Cockpit Management Server", "remarks": "rule_set_306" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_time_adjtimex", + "value": "package_openldap-clients_removed", "remarks": "rule_set_307" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record attempts to alter time through adjtimex", + "value": "Ensure LDAP client is not installed", "remarks": "rule_set_307" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_time_settimeofday", + "value": "service_bluetooth_disabled", "remarks": "rule_set_308" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record attempts to alter time through settimeofday", + "value": "Disable Bluetooth Service", "remarks": "rule_set_308" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_time_clock_settime", + "value": "accounts_passwords_pam_faillock_deny_root", "remarks": "rule_set_309" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Attempts to Alter Time Through clock_settime", + "value": "Configure the root Account for Failed Password Attempts", "remarks": "rule_set_309" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_time_watch_localtime", + "value": "accounts_minimum_age_login_defs", "remarks": "rule_set_310" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Attempts to Alter the localtime File", + "value": "Set Password Minimum Age", "remarks": "rule_set_310" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_networkconfig_modification", + "value": "accounts_password_set_min_life_existing", "remarks": "rule_set_311" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Network Environment", + "value": "Set Existing Passwords Minimum Age", "remarks": "rule_set_311" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_networkconfig_modification_network_scripts", + "value": "no_nologin_in_shells", "remarks": "rule_set_312" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Network Environment", + "value": "Ensure nologin Shell is Not Listed in /etc/shells", "remarks": "rule_set_312" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_privileged_commands", + "value": "package_audit_installed", "remarks": "rule_set_313" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on the Use of Privileged Commands", + "value": "Ensure the audit Subsystem is Installed", "remarks": "rule_set_313" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_unsuccessful_file_modification_creat", + "value": "package_audit-libs_installed", "remarks": "rule_set_314" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Unsuccessful Access Attempts to Files - creat", + "value": "Ensure the audit-libs package as a part of audit Subsystem is Installed", "remarks": "rule_set_314" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_unsuccessful_file_modification_ftruncate", + "value": "grub2_audit_argument", "remarks": "rule_set_315" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Unsuccessful Access Attempts to Files - ftruncate", + "value": "Enable Auditing for Processes Which Start Prior to the Audit Daemon", "remarks": "rule_set_315" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_unsuccessful_file_modification_open", + "value": "grub2_audit_backlog_limit_argument", "remarks": "rule_set_316" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Unsuccessful Access Attempts to Files - open", + "value": "Extend Audit Backlog Limit for the Audit Daemon", "remarks": "rule_set_316" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_unsuccessful_file_modification_openat", + "value": "service_auditd_enabled", "remarks": "rule_set_317" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Unsuccessful Access Attempts to Files - openat", + "value": "Enable auditd Service", "remarks": "rule_set_317" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_unsuccessful_file_modification_truncate", + "value": "auditd_data_retention_max_log_file", "remarks": "rule_set_318" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Unsuccessful Access Attempts to Files - truncate", + "value": "Configure auditd Max Log File Size", "remarks": "rule_set_318" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_group", + "value": "auditd_data_retention_max_log_file_action", "remarks": "rule_set_319" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify User/Group Information - /etc/group", + "value": "Configure auditd max_log_file_action Upon Reaching Maximum Log Size", "remarks": "rule_set_319" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_gshadow", + "value": "auditd_data_disk_error_action", "remarks": "rule_set_320" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify User/Group Information - /etc/gshadow", + "value": "Configure auditd Disk Error Action on Disk Error", "remarks": "rule_set_320" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_opasswd", + "value": "auditd_data_disk_full_action", "remarks": "rule_set_321" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify User/Group Information - /etc/security/opasswd", + "value": "Configure auditd Disk Full Action when Disk Space Is Full", "remarks": "rule_set_321" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_passwd", + "value": "auditd_data_retention_action_mail_acct", "remarks": "rule_set_322" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify User/Group Information - /etc/passwd", + "value": "Configure auditd mail_acct Action on Low Disk Space", "remarks": "rule_set_322" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_shadow", + "value": "auditd_data_retention_admin_space_left_action", "remarks": "rule_set_323" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify User/Group Information - /etc/shadow", + "value": "Configure auditd admin_space_left Action on Low Disk Space", "remarks": "rule_set_323" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_chmod", + "value": "auditd_data_retention_space_left_action", "remarks": "rule_set_324" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - chmod", + "value": "Configure auditd space_left Action on Low Disk Space", "remarks": "rule_set_324" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_chown", + "value": "audit_rules_sysadmin_actions", "remarks": "rule_set_325" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - chown", + "value": "Ensure auditd Collects System Administrator Actions", "remarks": "rule_set_325" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchmod", + "value": "audit_rules_suid_auid_privilege_function", "remarks": "rule_set_326" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fchmod", + "value": "Record Events When Executables Are Run As Another User", "remarks": "rule_set_326" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchmodat", + "value": "audit_sudo_log_events", "remarks": "rule_set_327" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fchmodat", + "value": "Record Attempts to perform maintenance activities", "remarks": "rule_set_327" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchmodat2", + "value": "audit_rules_time_adjtimex", "remarks": "rule_set_328" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fchmodat2", + "value": "Record attempts to alter time through adjtimex", "remarks": "rule_set_328" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchown", + "value": "audit_rules_time_settimeofday", "remarks": "rule_set_329" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fchown", + "value": "Record attempts to alter time through settimeofday", "remarks": "rule_set_329" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchownat", + "value": "audit_rules_time_clock_settime", "remarks": "rule_set_330" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fchownat", + "value": "Record Attempts to Alter Time Through clock_settime", "remarks": "rule_set_330" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fremovexattr", + "value": "audit_rules_time_watch_localtime", "remarks": "rule_set_331" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fremovexattr", + "value": "Record Attempts to Alter the localtime File", "remarks": "rule_set_331" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fsetxattr", + "value": "audit_rules_networkconfig_modification", "remarks": "rule_set_332" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fsetxattr", + "value": "Record Events that Modify the System's Network Environment", "remarks": "rule_set_332" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_lchown", + "value": "audit_rules_networkconfig_modification_network_scripts", "remarks": "rule_set_333" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - lchown", + "value": "Record Events that Modify the System's Network Environment", "remarks": "rule_set_333" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_lremovexattr", + "value": "audit_rules_privileged_commands", "remarks": "rule_set_334" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - lremovexattr", + "value": "Ensure auditd Collects Information on the Use of Privileged Commands", "remarks": "rule_set_334" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_lsetxattr", + "value": "audit_rules_unsuccessful_file_modification_creat", "remarks": "rule_set_335" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - lsetxattr", + "value": "Record Unsuccessful Access Attempts to Files - creat", "remarks": "rule_set_335" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_removexattr", + "value": "audit_rules_unsuccessful_file_modification_ftruncate", "remarks": "rule_set_336" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - removexattr", + "value": "Record Unsuccessful Access Attempts to Files - ftruncate", "remarks": "rule_set_336" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_setxattr", + "value": "audit_rules_unsuccessful_file_modification_open", "remarks": "rule_set_337" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - setxattr", + "value": "Record Unsuccessful Access Attempts to Files - open", "remarks": "rule_set_337" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_media_export", + "value": "audit_rules_unsuccessful_file_modification_openat", "remarks": "rule_set_338" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on Exporting to Media (successful)", + "value": "Record Unsuccessful Access Attempts to Files - openat", "remarks": "rule_set_338" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_session_events_utmp", + "value": "audit_rules_unsuccessful_file_modification_truncate", "remarks": "rule_set_339" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Attempts to Alter Process and Session Initiation Information utmp", + "value": "Record Unsuccessful Access Attempts to Files - truncate", "remarks": "rule_set_339" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_session_events_btmp", + "value": "audit_rules_usergroup_modification_group", "remarks": "rule_set_340" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Attempts to Alter Process and Session Initiation Information btmp", + "value": "Record Events that Modify User/Group Information - /etc/group", "remarks": "rule_set_340" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_session_events_wtmp", + "value": "audit_rules_usergroup_modification_passwd", "remarks": "rule_set_341" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Attempts to Alter Process and Session Initiation Information wtmp", + "value": "Record Events that Modify User/Group Information - /etc/passwd", "remarks": "rule_set_341" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_login_events_faillock", + "value": "audit_rules_usergroup_modification_gshadow", "remarks": "rule_set_342" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Attempts to Alter Logon and Logout Events - faillock", + "value": "Record Events that Modify User/Group Information - /etc/gshadow", "remarks": "rule_set_342" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_login_events_lastlog", + "value": "audit_rules_usergroup_modification_shadow", "remarks": "rule_set_343" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Attempts to Alter Logon and Logout Events - lastlog", + "value": "Record Events that Modify User/Group Information - /etc/shadow", "remarks": "rule_set_343" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_rename", + "value": "audit_rules_usergroup_modification_opasswd", "remarks": "rule_set_344" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects File Deletion Events by User - rename", + "value": "Record Events that Modify User/Group Information - /etc/security/opasswd", "remarks": "rule_set_344" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_renameat", + "value": "audit_rules_dac_modification_chmod", "remarks": "rule_set_345" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects File Deletion Events by User - renameat", + "value": "Record Events that Modify the System's Discretionary Access Controls - chmod", "remarks": "rule_set_345" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_renameat2", + "value": "audit_rules_dac_modification_fchmod", "remarks": "rule_set_346" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects File Deletion Events by User - renameat2", + "value": "Record Events that Modify the System's Discretionary Access Controls - fchmod", "remarks": "rule_set_346" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_unlink", + "value": "audit_rules_dac_modification_fchmodat", "remarks": "rule_set_347" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects File Deletion Events by User - unlink", + "value": "Record Events that Modify the System's Discretionary Access Controls - fchmodat", "remarks": "rule_set_347" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_unlinkat", + "value": "audit_rules_dac_modification_fchmodat2", "remarks": "rule_set_348" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects File Deletion Events by User - unlinkat", + "value": "Record Events that Modify the System's Discretionary Access Controls - fchmodat2", "remarks": "rule_set_348" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_mac_modification_etc_selinux", + "value": "audit_rules_dac_modification_chown", "remarks": "rule_set_349" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Mandatory Access Controls (/etc/selinux)", + "value": "Record Events that Modify the System's Discretionary Access Controls - chown", "remarks": "rule_set_349" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_mac_modification_usr_share", + "value": "audit_rules_dac_modification_fchown", "remarks": "rule_set_350" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Mandatory Access Controls in usr/share", + "value": "Record Events that Modify the System's Discretionary Access Controls - fchown", "remarks": "rule_set_350" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_execution_chcon", + "value": "audit_rules_dac_modification_fchownat", "remarks": "rule_set_351" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Any Attempts to Run chcon", + "value": "Record Events that Modify the System's Discretionary Access Controls - fchownat", "remarks": "rule_set_351" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_execution_setfacl", + "value": "audit_rules_dac_modification_lchown", "remarks": "rule_set_352" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Any Attempts to Run setfacl", + "value": "Record Events that Modify the System's Discretionary Access Controls - lchown", "remarks": "rule_set_352" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_execution_chacl", + "value": "audit_rules_dac_modification_fremovexattr", "remarks": "rule_set_353" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Any Attempts to Run chacl", + "value": "Record Events that Modify the System's Discretionary Access Controls - fremovexattr", "remarks": "rule_set_353" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_privileged_commands_usermod", + "value": "audit_rules_dac_modification_fsetxattr", "remarks": "rule_set_354" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on the Use of Privileged Commands - usermod", + "value": "Record Events that Modify the System's Discretionary Access Controls - fsetxattr", "remarks": "rule_set_354" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_delete", + "value": "audit_rules_dac_modification_lremovexattr", "remarks": "rule_set_355" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on Kernel Module Unloading - delete_module", + "value": "Record Events that Modify the System's Discretionary Access Controls - lremovexattr", "remarks": "rule_set_355" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_finit", + "value": "audit_rules_dac_modification_lsetxattr", "remarks": "rule_set_356" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on Kernel Module Loading and Unloading - finit_module", + "value": "Record Events that Modify the System's Discretionary Access Controls - lsetxattr", "remarks": "rule_set_356" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_init", + "value": "audit_rules_dac_modification_removexattr", "remarks": "rule_set_357" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on Kernel Module Loading - init_module", + "value": "Record Events that Modify the System's Discretionary Access Controls - removexattr", "remarks": "rule_set_357" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_query", + "value": "audit_rules_dac_modification_setxattr", "remarks": "rule_set_358" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on Kernel Module Loading and Unloading - query_module", + "value": "Record Events that Modify the System's Discretionary Access Controls - setxattr", "remarks": "rule_set_358" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_privileged_commands_kmod", + "value": "audit_rules_media_export", "remarks": "rule_set_359" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on the Use of Privileged Commands - kmod", + "value": "Ensure auditd Collects Information on Exporting to Media (successful)", "remarks": "rule_set_359" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_immutable", + "value": "audit_rules_session_events_utmp", "remarks": "rule_set_360" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Make the auditd Configuration Immutable", + "value": "Record Attempts to Alter Process and Session Initiation Information utmp", "remarks": "rule_set_360" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "directory_permissions_var_log_audit", + "value": "audit_rules_session_events_btmp", "remarks": "rule_set_361" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "System Audit Logs Must Have Mode 0750 or Less Permissive", + "value": "Record Attempts to Alter Process and Session Initiation Information btmp", "remarks": "rule_set_361" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_var_log_audit", + "value": "audit_rules_session_events_wtmp", "remarks": "rule_set_362" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "System Audit Logs Must Have Mode 0640 or Less Permissive", + "value": "Record Attempts to Alter Process and Session Initiation Information wtmp", "remarks": "rule_set_362" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_var_log_audit_stig", + "value": "audit_rules_login_events_faillock", "remarks": "rule_set_363" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "System Audit Logs Must Be Owned By Root", + "value": "Record Attempts to Alter Logon and Logout Events - faillock", "remarks": "rule_set_363" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_group_ownership_var_log_audit", + "value": "audit_rules_login_events_lastlog", "remarks": "rule_set_364" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "System Audit Logs Must Be Group Owned By Root", + "value": "Record Attempts to Alter Logon and Logout Events - lastlog", "remarks": "rule_set_364" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_audit_configuration", + "value": "audit_rules_file_deletion_events_unlink", "remarks": "rule_set_365" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Audit Configuration Files Permissions are 640 or More Restrictive", + "value": "Ensure auditd Collects File Deletion Events by User - unlink", "remarks": "rule_set_365" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_audit_configuration", + "value": "audit_rules_file_deletion_events_unlinkat", "remarks": "rule_set_366" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Audit Configuration Files Must Be Owned By Root", + "value": "Ensure auditd Collects File Deletion Events by User - unlinkat", "remarks": "rule_set_366" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_audit_configuration", + "value": "audit_rules_file_deletion_events_rename", "remarks": "rule_set_367" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Audit Configuration Files Must Be Owned By Group root", + "value": "Ensure auditd Collects File Deletion Events by User - rename", "remarks": "rule_set_367" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_audit_binaries", + "value": "audit_rules_file_deletion_events_renameat", "remarks": "rule_set_368" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify that audit tools Have Mode 0755 or less", + "value": "Ensure auditd Collects File Deletion Events by User - renameat", "remarks": "rule_set_368" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_audit_binaries", + "value": "audit_rules_file_deletion_events_renameat2", "remarks": "rule_set_369" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify that audit tools are owned by root", + "value": "Ensure auditd Collects File Deletion Events by User - renameat2", "remarks": "rule_set_369" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_audit_binaries", + "value": "audit_rules_mac_modification_etc_selinux", "remarks": "rule_set_370" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify that audit tools are owned by group root", + "value": "Record Events that Modify the System's Mandatory Access Controls (/etc/selinux)", "remarks": "rule_set_370" - } - ], - "control-implementations": [ + }, { - "uuid": "5017dc2a-1f38-465b-883b-cc68472fcb32", - "source": "trestle://profiles/rhel10-cis_rhel10-l2_workstation/profile.json", - "description": "REPLACE_ME", - "props": [ - { - "name": "Framework_Short_Name", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal", - "value": "cis_workstation_l2" - } - ], - "set-parameters": [ - { - "param-id": "cis_banner_text", - "values": [ - "cis" - ] - }, - { - "param-id": "inactivity_timeout_value", - "values": [ - "15_minutes" - ] - }, - { - "param-id": "login_banner_text", - "values": [ - "cis_banners" - ] - }, - { - "param-id": "sshd_idle_timeout_value", - "values": [ - "5_minutes" - ] - }, - { - "param-id": "sshd_max_auth_tries_value", - "values": [ - "4" - ] - }, - { - "param-id": "sshd_strong_kex", - "values": [ - "cis_rhel8" - ] - }, - { - "param-id": "sshd_strong_macs", - "values": [ - "cis_rhel8" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_all_accept_redirects_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_all_accept_source_route_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_all_log_martians_value", - "values": [ - "enabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_all_rp_filter_value", - "values": [ - "enabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_all_secure_redirects_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_default_accept_redirects_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_default_accept_source_route_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_default_log_martians_value", - "values": [ - "enabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_default_rp_filter_value", - "values": [ - "enabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_default_secure_redirects_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts_value", - "values": [ - "enabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses_value", - "values": [ - "enabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_tcp_syncookies_value", - "values": [ - "enabled" - ] - }, - { - "param-id": "sysctl_net_ipv6_conf_all_accept_ra_value", - "values": [ - "disabled" - ] - }, + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_mac_modification_usr_share", + "remarks": "rule_set_371" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Record Events that Modify the System's Mandatory Access Controls in usr/share", + "remarks": "rule_set_371" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_execution_chcon", + "remarks": "rule_set_372" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Record Any Attempts to Run chcon", + "remarks": "rule_set_372" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_execution_setfacl", + "remarks": "rule_set_373" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Record Any Attempts to Run setfacl", + "remarks": "rule_set_373" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_execution_chacl", + "remarks": "rule_set_374" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Record Any Attempts to Run chacl", + "remarks": "rule_set_374" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_privileged_commands_usermod", + "remarks": "rule_set_375" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure auditd Collects Information on the Use of Privileged Commands - usermod", + "remarks": "rule_set_375" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_privileged_commands_kmod", + "remarks": "rule_set_376" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure auditd Collects Information on the Use of Privileged Commands - kmod", + "remarks": "rule_set_376" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_kernel_module_loading_init", + "remarks": "rule_set_377" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure auditd Collects Information on Kernel Module Loading - init_module", + "remarks": "rule_set_377" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_kernel_module_loading_finit", + "remarks": "rule_set_378" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure auditd Collects Information on Kernel Module Loading and Unloading - finit_module", + "remarks": "rule_set_378" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_kernel_module_loading_delete", + "remarks": "rule_set_379" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure auditd Collects Information on Kernel Module Unloading - delete_module", + "remarks": "rule_set_379" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_kernel_module_loading_create", + "remarks": "rule_set_380" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure auditd Collects Information on Kernel Module Unloading - create_module", + "remarks": "rule_set_380" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_kernel_module_loading_query", + "remarks": "rule_set_381" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure auditd Collects Information on Kernel Module Loading and Unloading - query_module", + "remarks": "rule_set_381" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_immutable", + "remarks": "rule_set_382" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Make the auditd Configuration Immutable", + "remarks": "rule_set_382" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "directory_permissions_var_log_audit", + "remarks": "rule_set_383" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "System Audit Logs Must Have Mode 0750 or Less Permissive", + "remarks": "rule_set_383" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_var_log_audit", + "remarks": "rule_set_384" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "System Audit Logs Must Have Mode 0640 or Less Permissive", + "remarks": "rule_set_384" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_ownership_var_log_audit_stig", + "remarks": "rule_set_385" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "System Audit Logs Must Be Owned By Root", + "remarks": "rule_set_385" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_group_ownership_var_log_audit", + "remarks": "rule_set_386" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "System Audit Logs Must Be Group Owned By Root", + "remarks": "rule_set_386" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_audit_configuration", + "remarks": "rule_set_387" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Audit Configuration Files Permissions are 640 or More Restrictive", + "remarks": "rule_set_387" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_ownership_audit_configuration", + "remarks": "rule_set_388" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Audit Configuration Files Must Be Owned By Root", + "remarks": "rule_set_388" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_groupownership_audit_configuration", + "remarks": "rule_set_389" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Audit Configuration Files Must Be Owned By Group root", + "remarks": "rule_set_389" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_audit_binaries", + "remarks": "rule_set_390" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify that audit tools Have Mode 0755 or less", + "remarks": "rule_set_390" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_ownership_audit_binaries", + "remarks": "rule_set_391" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify that audit tools are owned by root", + "remarks": "rule_set_391" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_groupownership_audit_binaries", + "remarks": "rule_set_392" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify that audit tools are owned by group root", + "remarks": "rule_set_392" + } + ], + "control-implementations": [ + { + "uuid": "af20e3d2-ef96-475a-95e9-4756786c9c43", + "source": "trestle://profiles/rhel10-cis_rhel10-l2_workstation/profile.json", + "description": "REPLACE_ME", + "props": [ { - "param-id": "sysctl_net_ipv6_conf_all_accept_redirects_value", + "name": "Framework_Short_Name", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal", + "value": "cis_workstation_l2" + } + ], + "set-parameters": [ + { + "param-id": "cis_banner_text", "values": [ - "disabled" + "cis" ] }, { - "param-id": "sysctl_net_ipv6_conf_all_accept_source_route_value", + "param-id": "inactivity_timeout_value", "values": [ - "disabled" + "15_minutes" ] }, { - "param-id": "sysctl_net_ipv6_conf_all_forwarding_value", + "param-id": "login_banner_text", "values": [ - "disabled" + "cis_banners" ] }, { - "param-id": "sysctl_net_ipv6_conf_default_accept_ra_value", + "param-id": "sshd_idle_timeout_value", "values": [ - "disabled" + "5_minutes" ] }, { - "param-id": "sysctl_net_ipv6_conf_default_accept_redirects_value", + "param-id": "sshd_max_auth_tries_value", "values": [ - "disabled" + "4" ] }, { - "param-id": "sysctl_net_ipv6_conf_default_accept_source_route_value", + "param-id": "sshd_strong_kex", "values": [ - "disabled" + "cis_rhel10" ] }, { - "param-id": "var_account_disable_post_pw_expiration", + "param-id": "sshd_strong_macs", + "values": [ + "cis_rhel10" + ] + }, + { + "param-id": "sysctl_net_ipv4_conf_all_accept_redirects_value", + "values": [ + "disabled" + ] + }, + { + "param-id": "sysctl_net_ipv4_conf_all_accept_source_route_value", + "values": [ + "disabled" + ] + }, + { + "param-id": "sysctl_net_ipv4_conf_all_log_martians_value", + "values": [ + "enabled" + ] + }, + { + "param-id": "sysctl_net_ipv4_conf_all_rp_filter_value", + "values": [ + "enabled" + ] + }, + { + "param-id": "sysctl_net_ipv4_conf_all_secure_redirects_value", + "values": [ + "disabled" + ] + }, + { + "param-id": "sysctl_net_ipv4_conf_default_accept_redirects_value", + "values": [ + "disabled" + ] + }, + { + "param-id": "sysctl_net_ipv4_conf_default_accept_source_route_value", + "values": [ + "disabled" + ] + }, + { + "param-id": "sysctl_net_ipv4_conf_default_log_martians_value", + "values": [ + "enabled" + ] + }, + { + "param-id": "sysctl_net_ipv4_conf_default_rp_filter_value", + "values": [ + "enabled" + ] + }, + { + "param-id": "sysctl_net_ipv4_conf_default_secure_redirects_value", + "values": [ + "disabled" + ] + }, + { + "param-id": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts_value", + "values": [ + "enabled" + ] + }, + { + "param-id": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses_value", + "values": [ + "enabled" + ] + }, + { + "param-id": "sysctl_net_ipv4_tcp_syncookies_value", + "values": [ + "enabled" + ] + }, + { + "param-id": "sysctl_net_ipv6_conf_all_accept_ra_value", + "values": [ + "disabled" + ] + }, + { + "param-id": "sysctl_net_ipv6_conf_all_accept_redirects_value", + "values": [ + "disabled" + ] + }, + { + "param-id": "sysctl_net_ipv6_conf_all_accept_source_route_value", + "values": [ + "disabled" + ] + }, + { + "param-id": "sysctl_net_ipv6_conf_all_forwarding_value", + "values": [ + "disabled" + ] + }, + { + "param-id": "sysctl_net_ipv6_conf_default_accept_ra_value", + "values": [ + "disabled" + ] + }, + { + "param-id": "sysctl_net_ipv6_conf_default_accept_redirects_value", + "values": [ + "disabled" + ] + }, + { + "param-id": "sysctl_net_ipv6_conf_default_accept_source_route_value", + "values": [ + "disabled" + ] + }, + { + "param-id": "sysctl_net_ipv6_conf_default_forwarding_value", + "values": [ + "disabled" + ] + }, + { + "param-id": "var_account_disable_post_pw_expiration", "values": [ "30" ] @@ -5875,19 +6163,19 @@ { "param-id": "var_auditd_admin_space_left_action", "values": [ - "cis_rhel8" + "cis_rhel10" ] }, { "param-id": "var_auditd_disk_error_action", "values": [ - "cis_rhel8" + "cis_rhel10" ] }, { "param-id": "var_auditd_disk_full_action", "values": [ - "cis_rhel8" + "cis_rhel10" ] }, { @@ -5905,7 +6193,7 @@ { "param-id": "var_auditd_space_left_action", "values": [ - "cis_rhel8" + "cis_rhel10" ] }, { @@ -6043,7 +6331,7 @@ ], "implemented-requirements": [ { - "uuid": "5a598a48-f3ef-4f6b-9c2a-780b57755358", + "uuid": "8897ed9e-523f-497e-970b-0bbe0948b564", "control-id": "cis_rhel10_1-1.1.6", "description": "REPLACE_ME", "props": [ @@ -6055,12 +6343,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_squashfs_disabled" + "value": "kernel_module_overlayfs_disabled" } ] }, { - "uuid": "069fa4f8-52c0-4f2c-8a00-28c558cde68a", + "uuid": "ff311789-93de-4cba-b36b-8c3ac48a04c3", "control-id": "cis_rhel10_1-1.1.7", "description": "REPLACE_ME", "props": [ @@ -6072,12 +6360,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_udf_disabled" + "value": "kernel_module_squashfs_disabled" } ] }, { - "uuid": "11a963af-7a68-4e3d-bd56-aeffc9c1273d", + "uuid": "2ba66e2c-bea7-4771-a1ab-69ef79c79049", "control-id": "cis_rhel10_1-1.1.8", "description": "REPLACE_ME", "props": [ @@ -6089,25 +6377,29 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_usb-storage_disabled" + "value": "kernel_module_udf_disabled" } ] }, { - "uuid": "3a4592ce-313a-4859-838b-1978538fd0f3", + "uuid": "06da4145-662e-459c-8e4e-e54914fda625", "control-id": "cis_rhel10_1-1.1.9", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "kernel_module_firewire-core_disabled" } ] }, { - "uuid": "f76d4004-813b-40d5-a42e-11a53a89337d", + "uuid": "9b2c6a43-53f5-44c3-8378-4731c2f5da79", "control-id": "cis_rhel10_1-1.2.3.1", "description": "REPLACE_ME", "props": [ @@ -6124,7 +6416,7 @@ ] }, { - "uuid": "7a636d00-7b7b-445d-8971-eb2a5d7edc71", + "uuid": "9a447ecb-41bf-4829-b375-aa14f8d62bd6", "control-id": "cis_rhel10_1-1.2.4.1", "description": "REPLACE_ME", "props": [ @@ -6141,7 +6433,7 @@ ] }, { - "uuid": "4afacf14-89c0-49e2-98d3-abf0ec1f377b", + "uuid": "88f79971-9140-4891-8f7c-4617017a9495", "control-id": "cis_rhel10_1-1.2.5.1", "description": "REPLACE_ME", "props": [ @@ -6158,7 +6450,7 @@ ] }, { - "uuid": "71e06c91-aaaf-487c-959f-1d47598e768c", + "uuid": "91f14b25-b458-421a-a466-fcee7bef5961", "control-id": "cis_rhel10_1-1.2.6.1", "description": "REPLACE_ME", "props": [ @@ -6175,7 +6467,7 @@ ] }, { - "uuid": "f4979011-b301-449f-bb45-a15e0e97279d", + "uuid": "f9b774bb-ae02-4a62-9561-4f4f4efa9c8a", "control-id": "cis_rhel10_1-1.2.7.1", "description": "REPLACE_ME", "props": [ @@ -6192,7 +6484,7 @@ ] }, { - "uuid": "96053962-5b9d-4bca-b916-2d62d033af16", + "uuid": "a8ad17e3-aaa6-4e66-8951-e4ec25a3fcd9", "control-id": "cis_rhel10_1-2.1.3", "description": "REPLACE_ME", "props": [ @@ -6205,7 +6497,7 @@ ] }, { - "uuid": "f2de08f5-7bec-406f-af35-1b5a040d2bab", + "uuid": "bce373d7-9de2-4e35-97f9-abe3fc0a00e1", "control-id": "cis_rhel10_1-3.1.5", "description": "REPLACE_ME", "props": [ @@ -6222,7 +6514,7 @@ ] }, { - "uuid": "d9230a9f-c238-499f-ba19-6505fbff401f", + "uuid": "f8e2ef66-053f-4ebd-aae1-7e3d2e9cd609", "control-id": "cis_rhel10_1-3.1.6", "description": "REPLACE_ME", "props": [ @@ -6235,8 +6527,8 @@ ] }, { - "uuid": "b9fc86f4-1b84-4d88-929c-b4d460592739", - "control-id": "cis_rhel10_1-8.6", + "uuid": "94b00650-6ffb-4914-8bd7-5df6964b282e", + "control-id": "cis_rhel10_1-5.3", "description": "REPLACE_ME", "props": [ { @@ -6247,18 +6539,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_automount" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_automount_open" + "value": "sysctl_fs_protected_symlinks" } ] }, { - "uuid": "595812f0-8f53-4d19-b29c-20e1d5541d66", - "control-id": "cis_rhel10_1-8.7", + "uuid": "c2fd762c-f106-4b7a-9f0e-ed54b5dbb85c", + "control-id": "cis_rhel10_1-8.4", "description": "REPLACE_ME", "props": [ { @@ -6279,25 +6566,21 @@ ] }, { - "uuid": "9dc5a9dc-244b-4a40-b204-cee02dbee851", - "control-id": "cis_rhel10_2-1.1", + "uuid": "ec6d8fc7-8780-44fb-8234-d201e330e4fb", + "control-id": "cis_rhel10_1-8.6", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_autofs_disabled" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "8972b0e3-33bf-49b2-aa44-076865990182", - "control-id": "cis_rhel10_2-1.2", + "uuid": "2511ea80-78da-4b38-ac7a-350b6f051b57", + "control-id": "cis_rhel10_2-1.1", "description": "REPLACE_ME", "props": [ { @@ -6308,13 +6591,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_avahi-daemon_disabled" + "value": "service_autofs_disabled" } ] }, { - "uuid": "9ddbf88b-5e5a-40ed-82b7-b30a0bdedd34", - "control-id": "cis_rhel10_2-2.2", + "uuid": "9607ba1d-4ecd-4ca0-8361-e1ed661b81b9", + "control-id": "cis_rhel10_2-1.2", "description": "REPLACE_ME", "props": [ { @@ -6325,13 +6608,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_openldap-clients_removed" + "value": "service_avahi-daemon_disabled" } ] }, { - "uuid": "6713cc52-dbbd-456a-8ad2-699ef443f84e", - "control-id": "cis_rhel10_3-1.3", + "uuid": "38b28777-5564-49b3-8c9c-c55c52613162", + "control-id": "cis_rhel10_2-1.3", "description": "REPLACE_ME", "props": [ { @@ -6342,13 +6625,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_bluetooth_disabled" + "value": "service_cockpit_disabled" } ] }, { - "uuid": "110e6e35-5d27-4af9-b801-57eb632e9515", - "control-id": "cis_rhel10_3-2.2", + "uuid": "7f5e7bed-e7db-4542-ad63-009ade2454fc", + "control-id": "cis_rhel10_2-2.2", "description": "REPLACE_ME", "props": [ { @@ -6359,13 +6642,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_tipc_disabled" + "value": "package_openldap-clients_removed" } ] }, { - "uuid": "f1c26a16-ced0-4062-8567-9bd6f4d23d9e", - "control-id": "cis_rhel10_3-2.4", + "uuid": "8a707aaf-5e09-4c8a-bc47-edcc290a70fc", + "control-id": "cis_rhel10_3-1.3", "description": "REPLACE_ME", "props": [ { @@ -6376,12 +6659,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_sctp_disabled" + "value": "service_bluetooth_disabled" } ] }, { - "uuid": "e6a4cf19-163f-450c-bbbe-9a970b4a819c", + "uuid": "b78b6af5-8139-4b4e-9cc6-76136078b726", "control-id": "cis_rhel10_5-2.4", "description": "REPLACE_ME", "props": [ @@ -6398,24 +6681,7 @@ ] }, { - "uuid": "a2b0af54-e8fe-4fc2-ae34-4aac1c7890d6", - "control-id": "cis_rhel10_5-3.3.1.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_deny_root" - } - ] - }, - { - "uuid": "dfb4bcb7-35d3-4d74-abf2-8b3a8f162e12", + "uuid": "621cd654-4954-446e-9eac-798b9b093b6d", "control-id": "cis_rhel10_5-4.1.2", "description": "REPLACE_ME", "props": [ @@ -6437,20 +6703,24 @@ ] }, { - "uuid": "39905598-afa9-4226-8180-8439e0c38f3c", + "uuid": "d4b48d06-fdcb-4036-80d1-92f0afe85f1f", "control-id": "cis_rhel10_5-4.3.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary to create a new rule to check and remove nologin from /etc/shells.\nThe no_tmux_in_shells rule can be used as referece." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "no_nologin_in_shells" } ] }, { - "uuid": "79d0625d-5e59-4ea8-8be6-13072692bb14", + "uuid": "632093c7-495e-4d9b-9944-b20bde51d16e", "control-id": "cis_rhel10_6-3.1.1", "description": "REPLACE_ME", "props": [ @@ -6472,7 +6742,7 @@ ] }, { - "uuid": "82a84fb6-52eb-473c-912b-f9930c027f39", + "uuid": "bc2400b4-721c-4c56-ba91-b1e60d98ccb6", "control-id": "cis_rhel10_6-3.1.2", "description": "REPLACE_ME", "props": [ @@ -6489,7 +6759,7 @@ ] }, { - "uuid": "1e546832-c804-40ec-bf90-c83958f1f194", + "uuid": "64add3f1-e64c-4be4-a9f3-00e0a8c1761c", "control-id": "cis_rhel10_6-3.1.3", "description": "REPLACE_ME", "props": [ @@ -6506,7 +6776,7 @@ ] }, { - "uuid": "b57981bb-294d-4c2e-9540-174100e4a7bb", + "uuid": "05ed4cd5-1700-49ae-b521-20ef9783177e", "control-id": "cis_rhel10_6-3.1.4", "description": "REPLACE_ME", "props": [ @@ -6523,7 +6793,7 @@ ] }, { - "uuid": "8d615cee-d3d0-4e4f-91cf-9128177063c6", + "uuid": "8082260e-3a0e-41ed-bd3f-a035a7a82ac7", "control-id": "cis_rhel10_6-3.2.1", "description": "REPLACE_ME", "props": [ @@ -6540,7 +6810,7 @@ ] }, { - "uuid": "09b9f0e9-774b-4c39-9823-9d4cc52ecb5c", + "uuid": "b47af134-5e14-4ab0-bb30-6d05b4e36e76", "control-id": "cis_rhel10_6-3.2.2", "description": "REPLACE_ME", "props": [ @@ -6557,7 +6827,7 @@ ] }, { - "uuid": "c1bbf060-b4b9-443f-8a9c-def177e7c44c", + "uuid": "a3033c9c-829a-43ef-8546-88d7c92efc98", "control-id": "cis_rhel10_6-3.2.3", "description": "REPLACE_ME", "props": [ @@ -6579,7 +6849,7 @@ ] }, { - "uuid": "e4eacc8c-dca9-4253-a470-ba1e013e9cce", + "uuid": "edc8dbe1-c5a7-497c-9f02-e7ee6c769bd3", "control-id": "cis_rhel10_6-3.2.4", "description": "REPLACE_ME", "props": [ @@ -6606,7 +6876,7 @@ ] }, { - "uuid": "41238ef1-3a79-4015-84b2-2cef4de2356e", + "uuid": "6ed6a801-37b6-4f6f-bdfd-1f1812130896", "control-id": "cis_rhel10_6-3.3.1", "description": "REPLACE_ME", "props": [ @@ -6623,7 +6893,7 @@ ] }, { - "uuid": "caaa5be8-b9bd-4ca3-93c7-e88eb51d20b6", + "uuid": "11b25556-ad43-437a-b362-16481729ef35", "control-id": "cis_rhel10_6-3.3.2", "description": "REPLACE_ME", "props": [ @@ -6640,7 +6910,7 @@ ] }, { - "uuid": "d5d8cf41-d6d8-416c-acdb-02c672515a0c", + "uuid": "4f595e39-133a-47ad-b919-639d05f028aa", "control-id": "cis_rhel10_6-3.3.3", "description": "REPLACE_ME", "props": [ @@ -6657,7 +6927,7 @@ ] }, { - "uuid": "8335d064-6011-4db7-a27c-ff505ee9f6c8", + "uuid": "2017dffa-0e5b-454b-8a1f-3dfa4ccc6f22", "control-id": "cis_rhel10_6-3.3.4", "description": "REPLACE_ME", "props": [ @@ -6689,19 +6959,55 @@ ] }, { - "uuid": "168e63a1-69d5-46e4-abd5-c2170acb31f7", + "uuid": "8389c87f-f773-4180-8a1e-1e30189ce0e0", "control-id": "cis_rhel10_6-3.3.5", - "description": "These rules are not covering \"/etc/hostname\" and \"/etc/NetworkManager/\".", + "description": "This requirement is covered by 6.3.3.6.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "implemented" + } + ] + }, + { + "uuid": "fc5e0202-f1b5-45d5-9d3b-c5b9fdfdd2a5", + "control-id": "cis_rhel10_6-3.3.6", + "description": "REPLACE_ME", + "props": [ + { + "name": "implementation-status", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_networkconfig_modification" + } + ] + }, + { + "uuid": "675a6f79-6737-4d6c-b2c1-63ebf66c986c", + "control-id": "cis_rhel10_6-3.3.7", + "description": "This requirement is partially covered by 6.3.3.6.", + "props": [ + { + "name": "implementation-status", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "implemented" + } + ] + }, + { + "uuid": "c17a518b-4c5f-40f4-bcb0-3b60009305fc", + "control-id": "cis_rhel10_6-3.3.8", + "description": "This requirement is partially covered by 6.3.3.6.", + "props": [ + { + "name": "implementation-status", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "implemented" }, { "name": "Rule_Id", @@ -6711,8 +7017,20 @@ ] }, { - "uuid": "80d13958-8ce1-4101-b6db-8eeffe8cb642", - "control-id": "cis_rhel10_6-3.3.6", + "uuid": "dfeb6b79-2e0c-4dd2-9733-cd23512e131a", + "control-id": "cis_rhel10_6-3.3.9", + "description": "This requirement is covered by 6.3.3.6.", + "props": [ + { + "name": "implementation-status", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "implemented" + } + ] + }, + { + "uuid": "7d9e48fd-5070-4514-8731-40fccb9162ce", + "control-id": "cis_rhel10_6-3.3.10", "description": "REPLACE_ME", "props": [ { @@ -6728,8 +7046,8 @@ ] }, { - "uuid": "6da00c7e-a67b-45fa-a01f-e760fd715e57", - "control-id": "cis_rhel10_6-3.3.7", + "uuid": "5082d439-59fe-4e08-bcb9-5c78c08d21f7", + "control-id": "cis_rhel10_6-3.3.11", "description": "REPLACE_ME", "props": [ { @@ -6765,45 +7083,42 @@ ] }, { - "uuid": "91d57c98-0371-459e-829e-bab901ba6743", - "control-id": "cis_rhel10_6-3.3.8", - "description": "Missing rules to check \"/etc/nsswitch.conf\", \"/etc/pam.conf\" and \"/etc/pam.d\"", + "uuid": "59ab74c8-97ce-406a-9773-fb1b853b843d", + "control-id": "cis_rhel10_6-3.3.12", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_usergroup_modification_group" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_gshadow" - }, + } + ] + }, + { + "uuid": "d2bd76f4-f338-48bf-a5ff-121fc9b44b5d", + "control-id": "cis_rhel10_6-3.3.13", + "description": "REPLACE_ME", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_opasswd" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "audit_rules_usergroup_modification_passwd" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_shadow" } ] }, { - "uuid": "a1db6b91-63fa-4503-a1b3-a16b39b8c0de", - "control-id": "cis_rhel10_6-3.3.9", + "uuid": "452b073d-332f-4bd0-a48c-7a31c98b6c42", + "control-id": "cis_rhel10_6-3.3.14", "description": "REPLACE_ME", "props": [ { @@ -6814,78 +7129,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_chmod" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_chown" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchmod" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchmodat" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchmodat2" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchown" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchownat" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fremovexattr" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fsetxattr" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_lchown" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_lremovexattr" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_lsetxattr" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_removexattr" + "value": "audit_rules_usergroup_modification_gshadow" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_setxattr" + "value": "audit_rules_usergroup_modification_shadow" } ] }, { - "uuid": "c74308e3-1a24-442a-a5d0-d3a73e29a033", - "control-id": "cis_rhel10_6-3.3.10", + "uuid": "47c85300-6182-4f87-9ced-cfbf0ef05b9e", + "control-id": "cis_rhel10_6-3.3.15", "description": "REPLACE_ME", "props": [ { @@ -6896,62 +7151,39 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_media_export" + "value": "audit_rules_usergroup_modification_opasswd" } ] }, { - "uuid": "7a74c0f6-d34b-47c4-931d-f8c24d0d6d9e", - "control-id": "cis_rhel10_6-3.3.11", + "uuid": "bb80d75f-eaaa-446d-bb22-9e1de0290265", + "control-id": "cis_rhel10_6-3.3.16", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_session_events_utmp" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_session_events_btmp" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_session_events_wtmp" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "e5d9f4aa-8f86-4674-abfb-8353b38502ee", - "control-id": "cis_rhel10_6-3.3.12", + "uuid": "bffbb8b8-de66-4262-9420-a9aa7f1655c2", + "control-id": "cis_rhel10_6-3.3.17", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_login_events_faillock" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_login_events_lastlog" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "827fac81-52ce-434f-be68-aeef9126de4a", - "control-id": "cis_rhel10_6-3.3.13", + "uuid": "b8a31b48-0184-4574-b94d-f538c160518f", + "control-id": "cis_rhel10_6-3.3.18", "description": "REPLACE_ME", "props": [ { @@ -6962,33 +7194,28 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_rename" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_renameat" + "value": "audit_rules_dac_modification_chmod" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_renameat2" + "value": "audit_rules_dac_modification_fchmod" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_unlink" + "value": "audit_rules_dac_modification_fchmodat" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_unlinkat" + "value": "audit_rules_dac_modification_fchmodat2" } ] }, { - "uuid": "d220fcef-0d55-4fa8-b13c-05f42166ba8f", - "control-id": "cis_rhel10_6-3.3.14", + "uuid": "403d73cf-4302-482f-9098-1a219b360677", + "control-id": "cis_rhel10_6-3.3.19", "description": "REPLACE_ME", "props": [ { @@ -6999,69 +7226,28 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_mac_modification_etc_selinux" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_mac_modification_usr_share" - } - ] - }, - { - "uuid": "7926017b-cdc8-4ff1-b1b1-a465501b9e96", - "control-id": "cis_rhel10_6-3.3.15", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "audit_rules_dac_modification_chown" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_execution_chcon" - } - ] - }, - { - "uuid": "5fdb848b-673c-433f-95db-c8d637c080ed", - "control-id": "cis_rhel10_6-3.3.16", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "audit_rules_dac_modification_fchown" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_execution_setfacl" - } - ] - }, - { - "uuid": "7bb1cf31-d623-481a-aa01-aba785238b25", - "control-id": "cis_rhel10_6-3.3.17", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "audit_rules_dac_modification_fchownat" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_execution_chacl" + "value": "audit_rules_dac_modification_lchown" } ] }, { - "uuid": "62b611aa-35a0-42b8-9fc5-adea5f81e64b", - "control-id": "cis_rhel10_6-3.3.18", + "uuid": "268b4b45-7472-4a98-ae49-e408684f4db6", + "control-id": "cis_rhel10_6-3.3.20", "description": "REPLACE_ME", "props": [ { @@ -7072,50 +7258,38 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_privileged_commands_usermod" - } - ] - }, - { - "uuid": "b90e6e12-e039-41eb-976e-e8bad3cd947c", - "control-id": "cis_rhel10_6-3.3.19", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "audit_rules_dac_modification_fremovexattr" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_delete" + "value": "audit_rules_dac_modification_fsetxattr" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_finit" + "value": "audit_rules_dac_modification_lremovexattr" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_init" + "value": "audit_rules_dac_modification_lsetxattr" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_query" + "value": "audit_rules_dac_modification_removexattr" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_privileged_commands_kmod" + "value": "audit_rules_dac_modification_setxattr" } ] }, { - "uuid": "bf630e58-a269-48ea-b9e5-73ef7f2b791b", - "control-id": "cis_rhel10_6-3.3.20", + "uuid": "285db8f3-14b4-44ed-9a46-0aa4521aaa57", + "control-id": "cis_rhel10_6-3.3.21", "description": "REPLACE_ME", "props": [ { @@ -7126,25 +7300,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_immutable" - } - ] - }, - { - "uuid": "4c772f76-5e4f-4467-81ac-712b64009867", - "control-id": "cis_rhel10_6-3.3.21", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "audit_rules_media_export" } ] }, { - "uuid": "084a7597-5a88-4da7-9955-e65c3cf1578e", + "uuid": "4c80f4b7-ed13-432e-9d35-71d7d917483d", "control-id": "cis_rhel10_6-3.4.1", "description": "REPLACE_ME", "props": [ @@ -7161,7 +7322,7 @@ ] }, { - "uuid": "c3552a2b-efb9-4db8-b3a5-091ba3f077da", + "uuid": "7a4556c0-c09b-490a-8050-d38e72ce4396", "control-id": "cis_rhel10_6-3.4.2", "description": "REPLACE_ME", "props": [ @@ -7178,7 +7339,7 @@ ] }, { - "uuid": "0160fa46-d6f0-4342-8260-80c4f85aa230", + "uuid": "1d98c335-e177-4634-883d-f8db8e0b1c2a", "control-id": "cis_rhel10_6-3.4.3", "description": "REPLACE_ME", "props": [ @@ -7195,7 +7356,7 @@ ] }, { - "uuid": "50ebddae-a7fa-4a46-9fba-6dac1dc6f774", + "uuid": "41e8d19a-880d-463b-b065-a627bc5a64f0", "control-id": "cis_rhel10_6-3.4.4", "description": "REPLACE_ME", "props": [ @@ -7212,7 +7373,7 @@ ] }, { - "uuid": "c6ac23f9-ceba-4a1c-b2bf-beeca391136d", + "uuid": "191a61c2-f418-411b-9d21-8fcdc227916d", "control-id": "cis_rhel10_6-3.4.5", "description": "REPLACE_ME", "props": [ @@ -7229,7 +7390,7 @@ ] }, { - "uuid": "aeba021b-6496-43a3-97b0-c9a16b21128d", + "uuid": "75696b04-f5b5-4f1b-9310-b5ec564edbc5", "control-id": "cis_rhel10_6-3.4.6", "description": "REPLACE_ME", "props": [ @@ -7246,7 +7407,7 @@ ] }, { - "uuid": "9d239a43-9347-442c-82f0-9a1874edd0da", + "uuid": "9f5d37bd-8c31-4f75-85c3-a0982b61d7dd", "control-id": "cis_rhel10_6-3.4.7", "description": "REPLACE_ME", "props": [ @@ -7263,7 +7424,7 @@ ] }, { - "uuid": "88b13fef-33af-4e4e-98de-00c7c20cf8e9", + "uuid": "c92ba2e9-acfe-4985-ab95-dde9519756c6", "control-id": "cis_rhel10_6-3.4.8", "description": "REPLACE_ME", "props": [ @@ -7280,7 +7441,7 @@ ] }, { - "uuid": "692df13f-9ff6-4d51-afde-15c1940dd6ac", + "uuid": "66def112-fcdd-44e6-bf8e-9b0e68b2fb50", "control-id": "cis_rhel10_6-3.4.9", "description": "REPLACE_ME", "props": [ @@ -7297,7 +7458,7 @@ ] }, { - "uuid": "22a536ba-d8ba-4ab0-9067-326dcfa7a47c", + "uuid": "4c7aefa6-4682-41ef-9186-dcc8fb0bde17", "control-id": "cis_rhel10_6-3.4.10", "description": "REPLACE_ME", "props": [ @@ -7314,20 +7475,7 @@ ] }, { - "uuid": "bda7ec34-8155-4db7-a864-b1019e25d543", - "control-id": "cis_rhel10_7-1.14", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } - ] - }, - { - "uuid": "f54b8f83-e651-48b4-ad4b-905e88e4d208", + "uuid": "ddd56ff6-2354-4882-b2b8-c2ef95aa3edf", "control-id": "reload_dconf_db", "description": "This is a helper rule to reload Dconf database correctly.", "props": [ @@ -7344,7 +7492,7 @@ ] }, { - "uuid": "9dac5610-dc5d-4e24-a838-1cc0445fb4f1", + "uuid": "3e393d56-1678-4f74-a928-891060f111ba", "control-id": "cis_rhel10_1-1.2.1.1", "description": "REPLACE_ME", "props": [ @@ -7361,7 +7509,7 @@ ] }, { - "uuid": "a184b80b-594c-4a83-a95c-0ef4972f8b7f", + "uuid": "dfb53dcb-bfd2-4089-976e-cefde62ff0d0", "control-id": "cis_rhel10_1-1.2.1.2", "description": "REPLACE_ME", "props": [ @@ -7378,7 +7526,7 @@ ] }, { - "uuid": "6cc5d2e8-8977-479b-a71e-94ffd74ae87b", + "uuid": "7a0898d3-daf3-408a-891a-985322dcf13c", "control-id": "cis_rhel10_1-1.2.1.3", "description": "REPLACE_ME", "props": [ @@ -7395,7 +7543,7 @@ ] }, { - "uuid": "0419fad9-8797-4457-bcfb-c597c6246c95", + "uuid": "e8ea0f4a-66ed-4123-8263-7d9d1c3d2d29", "control-id": "cis_rhel10_1-1.2.1.4", "description": "REPLACE_ME", "props": [ @@ -7412,7 +7560,7 @@ ] }, { - "uuid": "3ac6214f-0ba7-4791-a9bc-7aefab5bf093", + "uuid": "ae6a987f-ead2-47bc-a580-b94e1a135665", "control-id": "cis_rhel10_1-1.2.2.1", "description": "REPLACE_ME", "props": [ @@ -7429,7 +7577,7 @@ ] }, { - "uuid": "d06fdbf0-4e63-4d06-968a-709dee6d61ce", + "uuid": "fecd20f4-0d9f-406b-8682-d79cd6916554", "control-id": "cis_rhel10_1-1.2.2.2", "description": "REPLACE_ME", "props": [ @@ -7446,7 +7594,7 @@ ] }, { - "uuid": "6d988b60-2e0e-4768-a129-0fe540f3169e", + "uuid": "30c13685-9fa6-43eb-ad6d-7d162a12f6cd", "control-id": "cis_rhel10_1-1.2.2.3", "description": "REPLACE_ME", "props": [ @@ -7463,7 +7611,7 @@ ] }, { - "uuid": "367d5c9a-7d08-4d73-9c91-9b4494fee6a1", + "uuid": "e471a228-128e-4781-aef8-26d96a45e6ec", "control-id": "cis_rhel10_1-1.2.2.4", "description": "REPLACE_ME", "props": [ @@ -7480,7 +7628,7 @@ ] }, { - "uuid": "46118a7d-7b5f-4f9f-9ca2-5d69e9ab7610", + "uuid": "fbc52c05-b548-4c3d-bf94-7025e042a860", "control-id": "cis_rhel10_1-1.2.3.2", "description": "REPLACE_ME", "props": [ @@ -7497,7 +7645,7 @@ ] }, { - "uuid": "fb150afc-d191-41fe-9256-8bd46a638bf3", + "uuid": "d7ce6e58-5a03-4824-810a-84011dc51370", "control-id": "cis_rhel10_1-1.2.3.3", "description": "REPLACE_ME", "props": [ @@ -7514,7 +7662,7 @@ ] }, { - "uuid": "f9570739-0d2f-407b-bdc6-d454b66cdb73", + "uuid": "aa79635c-6ec1-4241-890d-18158b95a100", "control-id": "cis_rhel10_1-1.2.4.2", "description": "REPLACE_ME", "props": [ @@ -7531,7 +7679,7 @@ ] }, { - "uuid": "39fedde4-4ae0-485b-a202-68d8014d8441", + "uuid": "cd0af7ee-f7e7-473e-b7c3-de3f3bb8dc17", "control-id": "cis_rhel10_1-1.2.4.3", "description": "REPLACE_ME", "props": [ @@ -7548,7 +7696,7 @@ ] }, { - "uuid": "340282b7-7077-4da3-bf2e-c27f4b0cef17", + "uuid": "2fcd726a-dafd-485b-9def-56f07255d63b", "control-id": "cis_rhel10_1-1.2.5.2", "description": "REPLACE_ME", "props": [ @@ -7565,7 +7713,7 @@ ] }, { - "uuid": "8356c839-b278-492f-b86c-6324f6939e3a", + "uuid": "023aeec1-4eb6-451b-a263-d7c8ff9e511f", "control-id": "cis_rhel10_1-1.2.5.3", "description": "REPLACE_ME", "props": [ @@ -7582,7 +7730,7 @@ ] }, { - "uuid": "782c737b-5c1f-4ece-ab04-65ce44512835", + "uuid": "771bb52a-f842-40b6-aa16-6730c9702e67", "control-id": "cis_rhel10_1-1.2.5.4", "description": "REPLACE_ME", "props": [ @@ -7599,7 +7747,7 @@ ] }, { - "uuid": "e3587cfa-30f4-46c6-a9d1-52fbde6a07a9", + "uuid": "b1f2150b-0575-49e3-9379-0ce3cf2ab06b", "control-id": "cis_rhel10_1-1.2.6.2", "description": "REPLACE_ME", "props": [ @@ -7616,7 +7764,7 @@ ] }, { - "uuid": "1f63a463-9d81-41bc-9d0e-4870022e20fe", + "uuid": "e7d1d055-66ac-428d-a8af-198a0e907f0f", "control-id": "cis_rhel10_1-1.2.6.3", "description": "REPLACE_ME", "props": [ @@ -7633,7 +7781,7 @@ ] }, { - "uuid": "06ed6f90-16ca-42da-a1b3-d558534864cb", + "uuid": "0d2dd918-b259-47fe-994d-1572e7851db2", "control-id": "cis_rhel10_1-1.2.6.4", "description": "REPLACE_ME", "props": [ @@ -7650,7 +7798,7 @@ ] }, { - "uuid": "80c72923-968c-4e84-a453-3604022ab6ed", + "uuid": "2b18b196-9337-4584-a887-76f4f9a6da13", "control-id": "cis_rhel10_1-1.2.7.2", "description": "REPLACE_ME", "props": [ @@ -7667,7 +7815,7 @@ ] }, { - "uuid": "040027ae-6f23-4cf5-b0d3-f6f71a0fde12", + "uuid": "2bc9e429-7eef-4837-a210-2d7d162523b6", "control-id": "cis_rhel10_1-1.2.7.3", "description": "REPLACE_ME", "props": [ @@ -7684,7 +7832,7 @@ ] }, { - "uuid": "efb846f3-547f-4ec1-be7f-a4bfc38c829b", + "uuid": "1dedbb60-d8b0-4d6e-9f83-8956988fcf86", "control-id": "cis_rhel10_1-1.2.7.4", "description": "REPLACE_ME", "props": [ @@ -7701,7 +7849,7 @@ ] }, { - "uuid": "871b7c1d-8fe4-4db6-ae1a-87df0707f65f", + "uuid": "2390af35-e6a9-4d8e-ab87-c41fa89c9a2e", "control-id": "cis_rhel10_1-2.1.1", "description": "REPLACE_ME", "props": [ @@ -7714,7 +7862,7 @@ ] }, { - "uuid": "7c8a0a01-1909-4a1b-8e1f-6a5bd45daff6", + "uuid": "88e33233-555d-4eac-9c6d-5e6573da18db", "control-id": "cis_rhel10_1-2.1.2", "description": "REPLACE_ME", "props": [ @@ -7731,7 +7879,7 @@ ] }, { - "uuid": "f205ab45-34f1-46b3-8c28-0946945260eb", + "uuid": "9b048236-f8b6-4ea6-a299-2a72d951ccdf", "control-id": "cis_rhel10_1-2.1.4", "description": "REPLACE_ME", "props": [ @@ -7744,7 +7892,7 @@ ] }, { - "uuid": "318af584-83ed-47ef-99a7-d9c9167a7640", + "uuid": "1f1bfa6d-2730-45d5-8cb2-6cf141d9afd5", "control-id": "cis_rhel10_1-2.2.1", "description": "REPLACE_ME", "props": [ @@ -7757,7 +7905,7 @@ ] }, { - "uuid": "1d2196b4-9f32-4ed0-9896-49814ff1c7a6", + "uuid": "205b7ce9-4b49-47a2-883e-4d2702d06c8f", "control-id": "cis_rhel10_1-3.1.1", "description": "REPLACE_ME", "props": [ @@ -7774,7 +7922,7 @@ ] }, { - "uuid": "a7cd3791-da2f-4206-8ca8-d2955f1d040d", + "uuid": "c93afd71-4232-431c-abd0-d23f9fc04e3b", "control-id": "cis_rhel10_1-3.1.2", "description": "REPLACE_ME", "props": [ @@ -7791,7 +7939,7 @@ ] }, { - "uuid": "5bdc4ddc-9ef9-47c9-9540-2e6f16d415b9", + "uuid": "2be0f72c-b9fc-4aaf-b365-7084aa094e59", "control-id": "cis_rhel10_1-3.1.3", "description": "REPLACE_ME", "props": [ @@ -7808,7 +7956,7 @@ ] }, { - "uuid": "88f334d8-5358-490a-9dfe-9928c8801454", + "uuid": "b46f139a-2606-4b42-9d2a-c402234b01ef", "control-id": "cis_rhel10_1-3.1.4", "description": "REPLACE_ME", "props": [ @@ -7825,7 +7973,7 @@ ] }, { - "uuid": "327e281e-8caa-48fd-9f32-6dcbb32ee694", + "uuid": "0261c041-3b7e-45e3-813c-6b64d0d1dfa5", "control-id": "cis_rhel10_1-3.1.7", "description": "REPLACE_ME", "props": [ @@ -7842,7 +7990,7 @@ ] }, { - "uuid": "2f46bf23-c508-43c5-9321-f2e863ca987c", + "uuid": "ce9d53da-84e3-421e-87f6-ca99ccf9caef", "control-id": "cis_rhel10_1-4.1", "description": "There is no automated remediation for this rule and this is intentional.\nMore details in the rule description.", "props": [ @@ -7859,7 +8007,7 @@ ] }, { - "uuid": "f4353d00-b927-44d6-ac2e-b64038c8e409", + "uuid": "752f9866-01c2-4687-a99f-90e598a9bb70", "control-id": "cis_rhel10_1-4.2", "description": "REPLACE_ME", "props": [ @@ -7902,25 +8050,8 @@ ] }, { - "uuid": "efd67d23-3438-4cdf-a52a-a1c7088c4538", + "uuid": "f5e7e82d-5f23-450e-b4c5-b732ec2da477", "control-id": "cis_rhel10_1-5.1", - "description": "Address Space Layout Randomization (ASLR)", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_kernel_randomize_va_space" - } - ] - }, - { - "uuid": "63de1c68-d82e-48bb-bd9b-4a1be15f8bd2", - "control-id": "cis_rhel10_1-5.2", "description": "REPLACE_ME", "props": [ { @@ -7931,13 +8062,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_kernel_yama_ptrace_scope" + "value": "disable_users_coredumps" } ] }, { - "uuid": "b43f40cf-fb69-4ace-8604-6433b74abadd", - "control-id": "cis_rhel10_1-5.3", + "uuid": "71abf60a-2f20-4e43-8f2e-4208de947be2", + "control-id": "cis_rhel10_1-5.2", "description": "REPLACE_ME", "props": [ { @@ -7948,12 +8079,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_backtraces" + "value": "sysctl_fs_protected_hardlinks" } ] }, { - "uuid": "77fa9be6-7604-467f-bac8-c67901508e1e", + "uuid": "88afe44c-add4-4c9b-8287-f74ffe8aca1f", "control-id": "cis_rhel10_1-5.4", "description": "REPLACE_ME", "props": [ @@ -7965,12 +8096,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_storage" + "value": "sysctl_fs_suid_dumpable" } ] }, { - "uuid": "edc621de-942b-4951-90a3-490e24f1bbb6", + "uuid": "3fbe1324-a986-4907-9443-d44af7f7a9a3", "control-id": "cis_rhel10_1-6.1", "description": "REPLACE_ME", "props": [ @@ -7987,36 +8118,33 @@ ] }, { - "uuid": "7e9f1107-955c-47e6-baaf-5d92ef08c234", + "uuid": "d50eea60-c709-46a4-a345-a2fa7e7038ae", "control-id": "cis_rhel10_1-6.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_ssh_crypto_policy" + "value": "alternative", + "remarks": "It is necessary a new rule to ensure a module disabling sha1 in\n/etc/crypto-policies/policies/modules/ so it can be used by update-crypto-policies command." } ] }, { - "uuid": "8439ebf1-ef58-4cbc-9f70-249770d0a9df", + "uuid": "00756dfc-32ee-479d-8536-be6ed54cd152", "control-id": "cis_rhel10_1-6.3", - "description": "This requirement is already satisfied by 1.6.1.", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "alternative", + "remarks": "It is necessary a new rule to ensure a module disabling weak MACs in\n/etc/crypto-policies/policies/modules/ so it can be used by update-crypto-policies command." } ] }, { - "uuid": "79a2bd89-37d8-4fae-ad0a-61ba1fa1e30e", + "uuid": "ed0f6f13-7ebc-4849-9e06-c725e45831c4", "control-id": "cis_rhel10_1-6.4", "description": "REPLACE_ME", "props": [ @@ -8024,69 +8152,30 @@ "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "alternative", - "remarks": "It is necessary a new rule to ensure a module disabling weak MACs in\n/etc/crypto-policies/policies/modules/ so it can be used by update-crypto-policies command." + "remarks": "It is necessary a new rule to ensure a module disabling CBC in\n/etc/crypto-policies/policies/modules/ so it can be used by update-crypto-policies command." } ] }, { - "uuid": "0e64fb02-f250-428e-8a41-8adb313d23ed", - "control-id": "cis_rhel10_1-6.5", + "uuid": "31fa7b15-83b2-47c6-b8eb-9c8e469bb70c", + "control-id": "cis_rhel10_1-7.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary a new rule to ensure a module disabling CBC in\n/etc/crypto-policies/policies/modules/ so it can be used by update-crypto-policies command." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "banner_etc_motd_cis" } ] }, { - "uuid": "820fb1da-c4dc-4e51-9391-e164ca77791a", - "control-id": "cis_rhel10_1-6.6", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } - ] - }, - { - "uuid": "eeac4759-fb6f-495a-a2b4-c72b031f553e", - "control-id": "cis_rhel10_1-6.7", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } - ] - }, - { - "uuid": "631b662f-c2b5-4523-84d8-a59d3c5e5aa2", - "control-id": "cis_rhel10_1-7.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "banner_etc_motd_cis" - } - ] - }, - { - "uuid": "58521ee5-fd5c-4113-a3f3-35c30092ffb6", - "control-id": "cis_rhel10_1-7.2", + "uuid": "be3d34ae-cfbc-4774-bdf2-04956413a554", + "control-id": "cis_rhel10_1-7.2", "description": "REPLACE_ME", "props": [ { @@ -8102,7 +8191,7 @@ ] }, { - "uuid": "36e0d5d4-cbd3-4015-bcea-8a0e692d858c", + "uuid": "428be4b2-f0ed-4a22-895b-aec473cf1739", "control-id": "cis_rhel10_1-7.3", "description": "REPLACE_ME", "props": [ @@ -8119,7 +8208,7 @@ ] }, { - "uuid": "0002447a-5cce-4a82-9c80-0d0b0bfa38a6", + "uuid": "69c06b9a-1579-4f50-8321-2d5c45abc6d3", "control-id": "cis_rhel10_1-7.4", "description": "REPLACE_ME", "props": [ @@ -8146,7 +8235,7 @@ ] }, { - "uuid": "1bf786dd-5089-4599-b33d-a0f14ea9f5a1", + "uuid": "77d6e969-5700-41a7-911d-3bfb372a6613", "control-id": "cis_rhel10_1-7.5", "description": "REPLACE_ME", "props": [ @@ -8173,7 +8262,7 @@ ] }, { - "uuid": "d369f7e1-5b78-49be-8b75-c1bf6e16e65c", + "uuid": "9cca73d6-2d9c-401b-9111-015465f248c9", "control-id": "cis_rhel10_1-7.6", "description": "REPLACE_ME", "props": [ @@ -8200,31 +8289,9 @@ ] }, { - "uuid": "1ba44d64-1be4-45bc-b920-b8a72d507a42", + "uuid": "c8dc3b8d-2f4f-4939-8940-1e39fc578d1f", "control-id": "cis_rhel10_1-8.2", "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_banner_enabled" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_login_banner_text" - } - ] - }, - { - "uuid": "81ee584b-5887-450a-a075-3452d404ebe2", - "control-id": "cis_rhel10_1-8.3", - "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -8239,8 +8306,8 @@ ] }, { - "uuid": "26fed501-3ca4-4f55-b128-139787890a5f", - "control-id": "cis_rhel10_1-8.4", + "uuid": "577045c0-e633-4fc7-803d-bb299b002cd4", + "control-id": "cis_rhel10_1-8.3", "description": "REPLACE_ME", "props": [ { @@ -8257,18 +8324,6 @@ "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "dconf_gnome_screensaver_lock_delay" - } - ] - }, - { - "uuid": "f458d9ba-6fe1-48d0-a115-0c4804018489", - "control-id": "cis_rhel10_1-8.5", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" }, { "name": "Rule_Id", @@ -8283,25 +8338,8 @@ ] }, { - "uuid": "74230f6f-8aea-46ed-ab61-88e660b38a37", - "control-id": "cis_rhel10_1-8.8", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_autorun" - } - ] - }, - { - "uuid": "7348c7a8-9e7a-4e75-93d9-463d9eb15c37", - "control-id": "cis_rhel10_1-8.9", + "uuid": "34da85e9-ea0f-4e1e-9c28-4e8f4dd3e121", + "control-id": "cis_rhel10_1-8.5", "description": "REPLACE_ME", "props": [ { @@ -8317,36 +8355,7 @@ ] }, { - "uuid": "ccfa311a-546a-40a0-872e-f035d0cacca0", - "control-id": "cis_rhel10_1-8.10", - "description": "This was inherited from the RHEL 9 profile.\nHowever, it was reported that XDMCP is no\nlonger in RHEL 10.", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - } - ] - }, - { - "uuid": "421545f8-268f-4359-af01-78a08fd0043b", - "control-id": "cis_rhel10_2-1.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_kea_removed" - } - ] - }, - { - "uuid": "76c4d9a9-f9aa-4e4d-a2b6-e64bdee0b972", + "uuid": "0a4c2ac2-3bf3-424a-ba52-dd3a39135536", "control-id": "cis_rhel10_2-1.4", "description": "REPLACE_ME", "props": [ @@ -8358,12 +8367,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_bind_removed" + "value": "package_kea_removed" } ] }, { - "uuid": "dae2ee8e-50eb-4ddb-8c40-862638075fe8", + "uuid": "ad8e686a-88eb-487c-97eb-1cd046af8f1a", "control-id": "cis_rhel10_2-1.5", "description": "REPLACE_ME", "props": [ @@ -8375,12 +8384,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_dnsmasq_removed" + "value": "package_bind_removed" } ] }, { - "uuid": "1cc95316-1f9a-419a-9f98-c86a267aaff2", + "uuid": "aa628670-122b-4878-9891-9dc8f4b54116", "control-id": "cis_rhel10_2-1.6", "description": "REPLACE_ME", "props": [ @@ -8392,12 +8401,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_samba_removed" + "value": "package_dnsmasq_removed" } ] }, { - "uuid": "53b4a7c4-1526-4217-9798-231b29ec2259", + "uuid": "7aefdaac-df78-41ae-87c6-7ae3ebcea0a1", "control-id": "cis_rhel10_2-1.7", "description": "REPLACE_ME", "props": [ @@ -8414,7 +8423,7 @@ ] }, { - "uuid": "e280c645-7635-4580-927c-abbb1e15e794", + "uuid": "9926ac99-c8d8-46a0-afec-71ee7ee22309", "control-id": "cis_rhel10_2-1.8", "description": "REPLACE_ME", "props": [ @@ -8436,7 +8445,7 @@ ] }, { - "uuid": "2c898dcb-074f-4a49-9c16-6eeb17c38b3c", + "uuid": "ff0af25b-3f92-46db-8498-dd2c5388a9d9", "control-id": "cis_rhel10_2-1.9", "description": "Many of the libvirt packages used by Enterprise Linux virtualization are dependent on the\nnfs-utils package.", "props": [ @@ -8453,21 +8462,9 @@ ] }, { - "uuid": "5c4ce950-c6bc-4140-a75d-33e838d860fb", - "control-id": "cis_rhel10_2-1.10", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - } - ] - }, - { - "uuid": "46ba64a6-a7ea-430f-85fc-377e8d56c9b9", + "uuid": "c7bb5fde-b76b-4537-afe7-e8da6cd04af2", "control-id": "cis_rhel10_2-1.12", - "description": "Many of the libvirt packages used by Enterprise Linux virtualization, and the nfs-utils\npackage used for The Network File System (NFS), are dependent on the rpcbind package.", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -8477,12 +8474,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_rpcbind_disabled" + "value": "package_rsync_removed" } ] }, { - "uuid": "2c5aaa52-e096-41ec-8923-44ef580b13cd", + "uuid": "6baf1767-419b-4ed5-a40d-fe75c416f811", "control-id": "cis_rhel10_2-1.13", "description": "REPLACE_ME", "props": [ @@ -8494,12 +8491,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_rsync_removed" + "value": "package_samba_removed" } ] }, { - "uuid": "29265ced-2c63-4709-b970-7a4e2ea7ad2c", + "uuid": "93c2df47-917a-4c06-b62e-b3d4cd5813fe", "control-id": "cis_rhel10_2-1.14", "description": "REPLACE_ME", "props": [ @@ -8516,7 +8513,7 @@ ] }, { - "uuid": "3f6e76c9-7560-49f6-86d2-eb28cdad8892", + "uuid": "8cddcf63-afdf-470d-af57-6c1992277237", "control-id": "cis_rhel10_2-1.15", "description": "REPLACE_ME", "props": [ @@ -8533,7 +8530,7 @@ ] }, { - "uuid": "f0e60515-240c-4b77-8bd1-9cbed16f9703", + "uuid": "c7bac39f-be61-4f4f-8be4-9cc4b4a9ad71", "control-id": "cis_rhel10_2-1.16", "description": "REPLACE_ME", "props": [ @@ -8550,7 +8547,7 @@ ] }, { - "uuid": "98920f60-df38-4b5a-8be3-b7cce6a59f12", + "uuid": "2f320a1d-f618-4d8d-8448-a7d1041a36cf", "control-id": "cis_rhel10_2-1.17", "description": "REPLACE_ME", "props": [ @@ -8567,7 +8564,7 @@ ] }, { - "uuid": "a031a085-d35a-410b-938d-a65e9a4975af", + "uuid": "e00599d3-97d4-40de-9ce0-8e063cafe279", "control-id": "cis_rhel10_2-1.18", "description": "REPLACE_ME", "props": [ @@ -8589,7 +8586,7 @@ ] }, { - "uuid": "d8ba0b7f-f2db-4827-a053-14a13c2f62ab", + "uuid": "ed1607cb-4b4a-4154-a80f-e6c389945501", "control-id": "cis_rhel10_2-1.21", "description": "The rule has_nonlocal_mta currently checks for services listening only on port 25,\nbut the policy checks also for ports 465 and 587", "props": [ @@ -8611,7 +8608,7 @@ ] }, { - "uuid": "a4df7595-54eb-4d5f-bdef-fdacde8e09a3", + "uuid": "ab2b97b3-e558-42e1-9452-84460758a3cb", "control-id": "cis_rhel10_2-1.22", "description": "REPLACE_ME", "props": [ @@ -8624,7 +8621,7 @@ ] }, { - "uuid": "0330e3a9-8b70-4699-b5b9-31a0101198e5", + "uuid": "4b0d6a42-6a71-445e-826b-f6fc38045a5e", "control-id": "cis_rhel10_2-2.1", "description": "REPLACE_ME", "props": [ @@ -8641,21 +8638,9 @@ ] }, { - "uuid": "8c4c0193-b84b-47ac-891a-ad8e30997709", + "uuid": "cabc4630-7485-4173-a642-3a8502c100ca", "control-id": "cis_rhel10_2-2.3", "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - } - ] - }, - { - "uuid": "f39e414f-0401-490a-8354-c753e649299c", - "control-id": "cis_rhel10_2-2.4", - "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -8670,8 +8655,8 @@ ] }, { - "uuid": "43e4b8fe-cb8f-43ab-94f7-63abd10975e7", - "control-id": "cis_rhel10_2-2.5", + "uuid": "2f31eb6e-60cb-406e-aff2-5a7d50b7420a", + "control-id": "cis_rhel10_2-2.4", "description": "REPLACE_ME", "props": [ { @@ -8687,7 +8672,7 @@ ] }, { - "uuid": "8d713db0-b746-4e48-b907-3fa8296f30ae", + "uuid": "1aa56b19-58c9-4429-874a-35bcd3eebf65", "control-id": "cis_rhel10_2-3.1", "description": "REPLACE_ME", "props": [ @@ -8699,7 +8684,7 @@ ] }, { - "uuid": "5ca556a3-b836-494a-a61b-fbc849daff8d", + "uuid": "0bd9204a-6a9b-43e5-bf43-b8affdc4f978", "control-id": "cis_rhel10_2-3.2", "description": "REPLACE_ME", "props": [ @@ -8716,7 +8701,7 @@ ] }, { - "uuid": "5b368cb1-ae71-4db7-8bf7-47616f183e60", + "uuid": "d788ee78-3491-4d27-b59f-c9a67941297f", "control-id": "cis_rhel10_2-3.3", "description": "REPLACE_ME", "props": [ @@ -8733,7 +8718,7 @@ ] }, { - "uuid": "7dc6cde5-cf7e-462d-a1e7-46bc55b504a3", + "uuid": "99cbcdb8-e8e8-4120-a066-e7b5d9d4703d", "control-id": "cis_rhel10_2-4.1.1", "description": "REPLACE_ME", "props": [ @@ -8755,7 +8740,7 @@ ] }, { - "uuid": "0d4fbbf7-7b60-4dd2-b27c-e8a630ce2c7f", + "uuid": "331453be-107a-41f8-b3d1-f98ecaedcc53", "control-id": "cis_rhel10_2-4.1.2", "description": "REPLACE_ME", "props": [ @@ -8782,7 +8767,7 @@ ] }, { - "uuid": "4c9da0ab-af68-46e9-99e3-ddab0f71d78d", + "uuid": "5aa42348-7563-435b-ad00-c4843f6841ab", "control-id": "cis_rhel10_2-4.1.3", "description": "REPLACE_ME", "props": [ @@ -8809,7 +8794,7 @@ ] }, { - "uuid": "db58c682-1f72-4a6e-bd3b-3e2cbc584994", + "uuid": "a58038cb-ca60-4f62-a717-09607745f87f", "control-id": "cis_rhel10_2-4.1.4", "description": "REPLACE_ME", "props": [ @@ -8836,7 +8821,7 @@ ] }, { - "uuid": "20dfd8da-11a5-4d41-88df-b49064cf05d3", + "uuid": "15a9a9cf-5c41-4b8f-a60f-c73c10cc417b", "control-id": "cis_rhel10_2-4.1.5", "description": "REPLACE_ME", "props": [ @@ -8863,7 +8848,7 @@ ] }, { - "uuid": "2b522d3c-fe59-435b-aea9-4508fbae813a", + "uuid": "a7a30c79-6803-4ae8-8cd3-e13911ba9e38", "control-id": "cis_rhel10_2-4.1.6", "description": "REPLACE_ME", "props": [ @@ -8890,34 +8875,20 @@ ] }, { - "uuid": "60be969d-afc4-40cc-bcd0-72e60b772317", + "uuid": "aeae1331-b8d9-48d6-a67a-74a5122465d3", "control-id": "cis_rhel10_2-4.1.7", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_d" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_d" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_d" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "676b321a-b467-4d28-9eb4-f5c4e01e03be", + "uuid": "1fe5a204-cf59-4fe3-bac1-d7b9316f4a39", "control-id": "cis_rhel10_2-4.1.8", "description": "REPLACE_ME", "props": [ @@ -8929,32 +8900,22 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_cron_deny_not_exist" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_cron_allow_exists" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_allow" + "value": "file_groupowner_cron_d" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_allow" + "value": "file_owner_cron_d" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_allow" + "value": "file_permissions_cron_d" } ] }, { - "uuid": "800a5fbe-32c0-4e17-bbd6-5d641020c5d3", + "uuid": "d13247ff-3c63-4694-bcfb-66c695e00687", "control-id": "cis_rhel10_2-4.2.1", "description": "It is necessary to create a rule to ensure the existence of at.allow.\nfile_cron_allow_exists can be used as reference for a new templated rule.", "props": [ @@ -8986,7 +8947,7 @@ ] }, { - "uuid": "c3706e4e-0010-4a93-a837-45d1d977bd78", + "uuid": "21a03fde-860a-41c5-882f-ee5e088e8997", "control-id": "cis_rhel10_3-1.1", "description": "REPLACE_ME", "props": [ @@ -8999,8 +8960,8 @@ ] }, { - "uuid": "776916d6-9074-4be2-8fc5-48994bcbdb91", - "control-id": "cis_rhel10_3-3.1", + "uuid": "d7db8d6d-22a2-43e8-99f6-7f1aa3361f18", + "control-id": "cis_rhel10_3-2.2", "description": "REPLACE_ME", "props": [ { @@ -9011,18 +8972,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_ip_forward" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_forwarding" + "value": "kernel_module_can_disabled" } ] }, { - "uuid": "fd3036a8-8c1c-447b-bcd4-50b44c7aa45b", - "control-id": "cis_rhel10_3-3.2", + "uuid": "b389f994-2180-4e49-8bdf-e5e69689c63b", + "control-id": "cis_rhel10_3-2.4", "description": "REPLACE_ME", "props": [ { @@ -9033,18 +8989,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_send_redirects" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_send_redirects" + "value": "kernel_module_tipc_disabled" } ] }, { - "uuid": "0d446ce4-2429-4d0b-adce-00bf747f304b", - "control-id": "cis_rhel10_3-3.3", + "uuid": "89f36e2e-21d9-4412-9095-6b0a1ab55015", + "control-id": "cis_rhel10_4-1.1", "description": "REPLACE_ME", "props": [ { @@ -9055,30 +9006,26 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses" + "value": "package_firewalld_installed" } ] }, { - "uuid": "2eb93202-ddcb-4aa8-923f-9f85d3c183ef", - "control-id": "cis_rhel10_3-3.4", + "uuid": "e3d26340-f189-498d-8806-8a8d90a80c36", + "control-id": "cis_rhel10_4-1.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "9c517957-9c75-4709-90bb-d38ae6e2dd83", - "control-id": "cis_rhel10_3-3.5", + "uuid": "79556d9f-354b-47a9-9426-22c8a3bfe632", + "control-id": "cis_rhel10_5-1.1", "description": "REPLACE_ME", "props": [ { @@ -9089,28 +9036,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_accept_redirects" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_accept_redirects" + "value": "file_groupowner_sshd_config" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_redirects" + "value": "file_owner_sshd_config" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_redirects" + "value": "file_permissions_sshd_config" } ] }, { - "uuid": "a4263dfe-4c10-420a-b713-a4b06977cb1a", - "control-id": "cis_rhel10_3-3.6", + "uuid": "f0693179-49d9-4522-bb02-22bc85eade22", + "control-id": "cis_rhel10_5-1.2", "description": "REPLACE_ME", "props": [ { @@ -9121,18 +9063,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_secure_redirects" + "value": "file_groupownership_sshd_private_key" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_ownership_sshd_private_key" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_secure_redirects" + "value": "file_permissions_sshd_private_key" } ] }, { - "uuid": "4d46d306-27c6-490f-ac1a-00622bceccb2", - "control-id": "cis_rhel10_3-3.7", + "uuid": "f3cfe519-38ed-4182-8217-6d46efd70aa8", + "control-id": "cis_rhel10_5-1.3", "description": "REPLACE_ME", "props": [ { @@ -9143,18 +9090,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_rp_filter" + "value": "file_groupownership_sshd_pub_key" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_ownership_sshd_pub_key" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_rp_filter" + "value": "file_permissions_sshd_pub_key" } ] }, { - "uuid": "0411182a-fb04-42e3-8b2d-d4f96510737a", - "control-id": "cis_rhel10_3-3.8", + "uuid": "d0c9dd8b-38c0-4833-af74-a44dc01e5d95", + "control-id": "cis_rhel10_5-1.4", "description": "REPLACE_ME", "props": [ { @@ -9165,29 +9117,43 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_accept_source_route" - }, + "value": "sshd_limit_user_access" + } + ] + }, + { + "uuid": "d1c6158b-da1f-4458-9d76-c471bd2739ff", + "control-id": "cis_rhel10_5-1.5", + "description": "REPLACE_ME", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_accept_source_route" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_source_route" - }, + "value": "sshd_enable_warning_banner_net" + } + ] + }, + { + "uuid": "b76dcbb6-b54d-4934-88a2-e27f33b62277", + "control-id": "cis_rhel10_5-1.6", + "description": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation.", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_source_route" + "value": "implemented" } ] }, { - "uuid": "2ee42c81-1b02-475b-841d-ea26c83aab64", - "control-id": "cis_rhel10_3-3.9", - "description": "REPLACE_ME", + "uuid": "103b8585-30c1-40ef-b3d8-a3de8158e11b", + "control-id": "cis_rhel10_5-1.7", + "description": "The requirement gives an example of 45 seconds, but is flexible about the values. It is only\nnecessary to ensure there is a timeout configured in alignment to the site policy.", "props": [ { "name": "implementation-status", @@ -9197,18 +9163,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_log_martians" + "value": "sshd_set_idle_timeout" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_log_martians" + "value": "sshd_set_keepalive" } ] }, { - "uuid": "be2c08b7-9164-411e-9ac4-895a612f3bae", - "control-id": "cis_rhel10_3-3.10", + "uuid": "111b0ae7-86e1-461c-af64-9b96c2186671", + "control-id": "cis_rhel10_5-1.8", "description": "REPLACE_ME", "props": [ { @@ -9219,13 +9185,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_tcp_syncookies" + "value": "sshd_disable_forwarding" } ] }, { - "uuid": "8e8c3389-c159-4b21-ad62-1edd63c116b1", - "control-id": "cis_rhel10_3-3.11", + "uuid": "2bc4d809-b7db-4c79-b29b-3e2ce61fd743", + "control-id": "cis_rhel10_5-1.9", "description": "REPLACE_ME", "props": [ { @@ -9236,18 +9202,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_ra" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_ra" + "value": "sshd_disable_gssapi_auth" } ] }, { - "uuid": "5be6c978-a620-47c9-8b0e-518ead5c546c", - "control-id": "cis_rhel10_4-1.1", + "uuid": "432d4545-8c86-4e0a-98dc-989feb8131b4", + "control-id": "cis_rhel10_5-1.10", "description": "REPLACE_ME", "props": [ { @@ -9258,13 +9219,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_nftables_installed" + "value": "disable_host_auth" } ] }, { - "uuid": "b3ac3cd8-c0c0-47ee-97a8-b99cb2b22698", - "control-id": "cis_rhel10_4-1.2", + "uuid": "4c347fa0-d6eb-4c56-98b7-bc66a6d6214f", + "control-id": "cis_rhel10_5-1.11", "description": "REPLACE_ME", "props": [ { @@ -9275,36 +9236,31 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_firewalld_enabled" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_firewalld_installed" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_nftables_disabled" + "value": "sshd_disable_rhosts" } ] }, { - "uuid": "28fcf754-00bf-43f0-ae6a-d86b475fa5c2", - "control-id": "cis_rhel10_4-2.1", + "uuid": "22ad755c-ab14-4826-94c7-141ba25e64bb", + "control-id": "cis_rhel10_5-1.12", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "alternative", - "remarks": "REPLACE_ME" + "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_use_strong_kex" } ] }, { - "uuid": "c423ef71-8499-4d8c-9564-6b9e3ddeeb9b", - "control-id": "cis_rhel10_4-2.2", + "uuid": "cc6a44d2-99f4-480a-bb0f-d5782868645c", + "control-id": "cis_rhel10_5-1.13", "description": "REPLACE_ME", "props": [ { @@ -9315,67 +9271,82 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "firewalld_loopback_traffic_trusted" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "firewalld_loopback_traffic_restricted" + "value": "sshd_set_login_grace_time" } ] }, { - "uuid": "b94226e4-f38d-4513-8099-3b042b6464df", - "control-id": "cis_rhel10_4-3.1", - "description": "RHEL systems use firewalld for firewall management. Although nftables is the default\nback-end for firewalld, it is not recommended to use nftables directly when firewalld\nis in use. When using firewalld the base chains are installed by default.", + "uuid": "52b955b2-0fb2-4a28-be3e-cd1dae7cd577", + "control-id": "cis_rhel10_5-1.14", + "description": "The CIS benchmark is not opinionated about which loglevel is selected here. Here, this\nprofile uses VERBOSE by default, as it allows for the capture of login and logout activity\nas well as key fingerprints.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_set_loglevel_verbose" } ] }, { - "uuid": "098267b3-fd87-4f67-9401-0752f0db3342", - "control-id": "cis_rhel10_4-3.2", + "uuid": "657b797f-8329-4dba-b5e0-fbb711c9a924", + "control-id": "cis_rhel10_5-1.15", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "alternative", - "remarks": "REPLACE_ME" + "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_use_strong_macs" } ] }, { - "uuid": "463246e5-158d-429b-92bb-13c473b873f5", - "control-id": "cis_rhel10_4-3.3", - "description": "RHEL systems use firewalld for firewall management. Although nftables is the default\nback-end for firewalld, it is not recommended to use nftables directly when firewalld\nis in use.", + "uuid": "c8a4fb99-5a74-4419-8d96-67d2bf41c33b", + "control-id": "cis_rhel10_5-1.16", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_set_max_auth_tries" } ] }, { - "uuid": "01e40130-46bd-4082-8d0e-14c112ae485b", - "control-id": "cis_rhel10_4-3.4", - "description": "RHEL systems use firewalld for firewall management. Although nftables is the default\nback-end for firewalld, it is not recommended to use nftables directly when firewalld\nis in use.", + "uuid": "b71a3cf5-6563-4f26-b4ab-d9e60d603c9b", + "control-id": "cis_rhel10_5-1.17", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_set_maxstartups" } ] }, { - "uuid": "0dfb4354-6990-4e47-b796-ae5ba8bfc42a", - "control-id": "cis_rhel10_5-1.1", + "uuid": "fcddcb30-1ed3-4d0f-9d75-e0c8d1ec159c", + "control-id": "cis_rhel10_5-1.18", "description": "REPLACE_ME", "props": [ { @@ -9386,23 +9357,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_sshd_config" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_sshd_config" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_config" + "value": "sshd_set_max_sessions" } ] }, { - "uuid": "52412cf5-3fb0-4d56-add3-e89b9e58e635", - "control-id": "cis_rhel10_5-1.2", + "uuid": "582ff8e3-3ba3-4b60-a81f-f6888a89335d", + "control-id": "cis_rhel10_5-1.19", "description": "REPLACE_ME", "props": [ { @@ -9413,23 +9374,30 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_private_key" - }, + "value": "sshd_disable_empty_passwords" + } + ] + }, + { + "uuid": "8a921a98-dc51-4cc6-9093-a31b2a087409", + "control-id": "cis_rhel10_5-1.20", + "description": "REPLACE_ME", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_private_key" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_sshd_private_key" + "value": "sshd_disable_root_login" } ] }, { - "uuid": "2811d18a-41d9-49ef-b58c-311caa8052b3", - "control-id": "cis_rhel10_5-1.3", + "uuid": "209d2f72-8e85-492c-8cc6-046a3ad4b7f7", + "control-id": "cis_rhel10_5-1.21", "description": "REPLACE_ME", "props": [ { @@ -9440,72 +9408,81 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_pub_key" - }, + "value": "sshd_do_not_permit_user_env" + } + ] + }, + { + "uuid": "c68b158e-8782-4622-b16d-0c945ecfbbf2", + "control-id": "cis_rhel10_5-1.22", + "description": "REPLACE_ME", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_pub_key" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_sshd_pub_key" + "value": "sshd_enable_pam" } ] }, { - "uuid": "e19a5e6f-5a5d-45e9-ba9a-25ff8709a2cb", - "control-id": "cis_rhel10_5-1.4", + "uuid": "30b9450c-e851-402c-b4f7-87238495a45d", + "control-id": "cis_rhel10_5-2.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "package_sudo_installed" } ] }, { - "uuid": "1f612682-7448-474c-bdee-8dd9c7e2b72b", - "control-id": "cis_rhel10_5-1.5", + "uuid": "e6f32b95-bb00-4d59-8a41-f092646cf63d", + "control-id": "cis_rhel10_5-2.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_kex" + "value": "sudo_add_use_pty" } ] }, { - "uuid": "f580d52f-5917-4544-9f4e-1c6ffe315930", - "control-id": "cis_rhel10_5-1.6", + "uuid": "494cecc2-f8d0-4b12-bb92-b69ae0df8960", + "control-id": "cis_rhel10_5-2.3", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_macs" + "value": "sudo_custom_logfile" } ] }, { - "uuid": "02687fae-4b7a-4410-84a7-dbedd800e168", - "control-id": "cis_rhel10_5-1.7", + "uuid": "8ae174ee-de72-4f83-994a-9e2bf21be86e", + "control-id": "cis_rhel10_5-2.5", "description": "REPLACE_ME", "props": [ { @@ -9516,13 +9493,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_limit_user_access" + "value": "sudo_require_authentication" } ] }, { - "uuid": "cf6461ff-1bd4-442c-854c-86c0588716b7", - "control-id": "cis_rhel10_5-1.8", + "uuid": "b4ff9652-6e1e-481f-830f-081175987fb2", + "control-id": "cis_rhel10_5-2.6", "description": "REPLACE_ME", "props": [ { @@ -9533,14 +9510,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_enable_warning_banner_net" + "value": "sudo_require_reauthentication" } ] }, { - "uuid": "bc460343-2ac6-44e7-beb7-429dd9a50d95", - "control-id": "cis_rhel10_5-1.9", - "description": "The requirement gives an example of 45 seconds, but is flexible about the values. It is only\nnecessary to ensure there is a timeout configured in alignment to the site policy.", + "uuid": "a79d2aad-d167-4c73-ad9a-55e726c9bdc9", + "control-id": "cis_rhel10_5-2.7", + "description": "Members of \"wheel\" or GID 0 groups are checked by default if the group option is not set for\npam_wheel.so module. The recommendation states the group should be empty to reinforce the\nuse of \"sudo\" for privileged access. Therefore, members of these groups should be manually\nchecked or a different group should be informed.", "props": [ { "name": "implementation-status", @@ -9550,32 +9527,31 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_idle_timeout" + "value": "use_pam_wheel_group_for_su" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_keepalive" + "value": "ensure_pam_wheel_group_empty" } ] }, { - "uuid": "b7b6c634-f67e-4df7-ac02-c6f7c8c22449", - "control-id": "cis_rhel10_5-1.10", - "description": "REPLACE_ME", + "uuid": "219c40a8-9951-4944-96bc-23f009b095e8", + "control-id": "cis_rhel10_5-3.1.1", + "description": "This requirement is hard to be automated without any specific requirement. The policy even\nstates that provided commands are examples, other custom settings might be in place and the\nsettings might be different depending on site policies. The other rules will already make\nsure there is a correct autheselect profile regardless of the existing settings. It is\nnecessary to better discuss with CIS Community.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "New templated rule is necessary for \"disableforwarding\" option." + "value": "partial" } ] }, { - "uuid": "5ecae6ad-ee45-4f72-aa48-7b9813d872c6", - "control-id": "cis_rhel10_5-1.11", - "description": "REPLACE_ME", + "uuid": "582ba017-8384-4e1c-8fde-12a1741fec94", + "control-id": "cis_rhel10_5-3.1.2", + "description": "This requirement is also indirectly satisfied by the requirement 5.3.2.1.", "props": [ { "name": "implementation-status", @@ -9585,14 +9561,19 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_gssapi_auth" + "value": "account_password_pam_faillock_password_auth" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "account_password_pam_faillock_system_auth" } ] }, { - "uuid": "cee66f0b-44ae-40fd-9493-b1b3430732a0", - "control-id": "cis_rhel10_5-1.12", - "description": "REPLACE_ME", + "uuid": "dfafccce-d8f6-4d1a-9883-54071a6c4288", + "control-id": "cis_rhel10_5-3.1.3", + "description": "This requirement is also indirectly satisfied by the requirement 5.3.2.2.", "props": [ { "name": "implementation-status", @@ -9602,13 +9583,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "disable_host_auth" + "value": "package_pam_pwquality_installed" } ] }, { - "uuid": "999c37e9-a73e-4eb0-b444-4a086e1dd015", - "control-id": "cis_rhel10_5-1.13", + "uuid": "7aa21706-97d7-46cf-91e8-9fdbf380e8a2", + "control-id": "cis_rhel10_5-4.1.1", "description": "REPLACE_ME", "props": [ { @@ -9619,13 +9600,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_rhosts" + "value": "accounts_maximum_age_login_defs" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_password_set_max_life_existing" } ] }, { - "uuid": "a5bb25d5-57c1-4063-b223-013f1b094eeb", - "control-id": "cis_rhel10_5-1.14", + "uuid": "c9cceca1-b975-456e-b12f-f7937f2ffa35", + "control-id": "cis_rhel10_5-4.1.3", "description": "REPLACE_ME", "props": [ { @@ -9636,14 +9622,19 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_login_grace_time" + "value": "accounts_password_warn_age_login_defs" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_password_set_warn_age_existing" } ] }, { - "uuid": "0505fac0-5da8-4997-85a8-e07748edd92b", - "control-id": "cis_rhel10_5-1.15", - "description": "The CIS benchmark is not opinionated about which loglevel is selected here. Here, this\nprofile uses VERBOSE by default, as it allows for the capture of login and logout activity\nas well as key fingerprints.", + "uuid": "188ffb56-1296-4bab-b8c5-672150446235", + "control-id": "cis_rhel10_5-4.1.4", + "description": "There's a \"new\" set of options in /etc/login.defs file to define the number of iterations\nperformed during the hashing process.", "props": [ { "name": "implementation-status", @@ -9653,13 +9644,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_loglevel_verbose" + "value": "set_password_hashing_algorithm_libuserconf" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "set_password_hashing_algorithm_logindefs" } ] }, { - "uuid": "dbace1a3-dd97-4115-a7ff-6f7422877ea5", - "control-id": "cis_rhel10_5-1.16", + "uuid": "428e95d1-8786-4d3b-8e45-c7c834974ab9", + "control-id": "cis_rhel10_5-4.1.5", "description": "REPLACE_ME", "props": [ { @@ -9670,13 +9666,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_max_auth_tries" + "value": "account_disable_post_pw_expiration" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_set_post_pw_existing" } ] }, { - "uuid": "e66fcf60-ed94-4c63-9591-f7083050a678", - "control-id": "cis_rhel10_5-1.17", + "uuid": "cebf320d-a97b-47ea-a5b5-55fa5c4112bc", + "control-id": "cis_rhel10_5-4.1.6", "description": "REPLACE_ME", "props": [ { @@ -9687,13 +9688,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_maxstartups" + "value": "accounts_password_last_change_is_in_past" } ] }, { - "uuid": "b52fe6e1-c107-4561-a996-213fe47486fb", - "control-id": "cis_rhel10_5-1.18", + "uuid": "96647439-c8e3-4021-b30e-b7ad2162fd58", + "control-id": "cis_rhel10_5-4.2.1", "description": "REPLACE_ME", "props": [ { @@ -9704,30 +9705,30 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_max_sessions" + "value": "accounts_no_uid_except_zero" } ] }, { - "uuid": "3321616c-7199-4ce1-9f3c-503d60b91c51", - "control-id": "cis_rhel10_5-1.19", - "description": "REPLACE_ME", + "uuid": "2e77b884-2bc4-46a7-8f9b-4c77f985e3b1", + "control-id": "cis_rhel10_5-4.2.2", + "description": "The rule confirms the primary group for root, but doesn't check if any other user are also\nusing GID 0. New rule is necessary.\nThere is assessment but no automated remediation for this rule and this sounds reasonable.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "partial" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_empty_passwords" + "value": "accounts_root_gid_zero" } ] }, { - "uuid": "f7947871-8dc8-44a9-acfc-c1aa16dbf7da", - "control-id": "cis_rhel10_5-1.20", + "uuid": "50ff3dce-1ffe-480f-bf9c-3038089da127", + "control-id": "cis_rhel10_5-4.2.3", "description": "REPLACE_ME", "props": [ { @@ -9738,13 +9739,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_root_login" + "value": "groups_no_zero_gid_except_root" } ] }, { - "uuid": "693fead9-3206-4505-a221-8a9036c4f2ea", - "control-id": "cis_rhel10_5-1.21", + "uuid": "f85ea106-1605-4746-883b-bd673dc6539a", + "control-id": "cis_rhel10_5-4.2.4", "description": "REPLACE_ME", "props": [ { @@ -9755,13 +9756,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_do_not_permit_user_env" + "value": "ensure_root_password_configured" } ] }, { - "uuid": "9e41e2af-96b2-4b77-bd9f-644f8bb8cd28", - "control-id": "cis_rhel10_5-1.22", + "uuid": "3a9f3e7e-e7f1-4c4f-9461-cc68914dc48e", + "control-id": "cis_rhel10_5-4.2.5", "description": "REPLACE_ME", "props": [ { @@ -9772,13 +9773,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_enable_pam" + "value": "accounts_root_path_dirs_no_write" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "root_path_no_dot" } ] }, { - "uuid": "4b255c08-78db-4d9f-a6de-239cbd2f3b2f", - "control-id": "cis_rhel10_5-2.1", + "uuid": "d56a3aa5-d19f-43aa-921c-5a8aa6f6295f", + "control-id": "cis_rhel10_5-4.2.6", "description": "REPLACE_ME", "props": [ { @@ -9789,13 +9795,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_sudo_installed" + "value": "accounts_umask_root" } ] }, { - "uuid": "a1382326-d4d9-4ce4-9508-b50b5780ef23", - "control-id": "cis_rhel10_5-2.2", + "uuid": "8a41c587-914c-42b5-9c8a-eeb272a986da", + "control-id": "cis_rhel10_5-4.2.7", "description": "REPLACE_ME", "props": [ { @@ -9806,30 +9812,30 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_add_use_pty" + "value": "no_password_auth_for_systemaccounts" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "no_shelllogin_for_systemaccounts" } ] }, { - "uuid": "53a1699a-f668-4c54-b09a-2eeb0db39460", - "control-id": "cis_rhel10_5-2.3", - "description": "REPLACE_ME", + "uuid": "bda7c396-2ffa-47a1-b2a1-c65059c595ae", + "control-id": "cis_rhel10_5-4.2.8", + "description": "New rule is necessary.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_custom_logfile" } ] }, { - "uuid": "c5c9a16b-3830-4491-a703-07ab5e66dd3f", - "control-id": "cis_rhel10_5-2.5", + "uuid": "4c95a3d1-fc10-41d0-8a6d-a043540a6354", + "control-id": "cis_rhel10_5-4.3.2", "description": "REPLACE_ME", "props": [ { @@ -9840,13 +9846,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_require_reauthentication" + "value": "accounts_tmout" } ] }, { - "uuid": "a1cbe7e8-edbf-49f5-8cc9-4c4b4b3d1f49", - "control-id": "cis_rhel10_5-2.6", + "uuid": "00d6608d-c723-4014-a2fa-d34188f590e3", + "control-id": "cis_rhel10_5-4.3.3", "description": "REPLACE_ME", "props": [ { @@ -9857,14 +9863,24 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_require_reauthentication" + "value": "accounts_umask_etc_bashrc" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_umask_etc_login_defs" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_umask_etc_profile" } ] }, { - "uuid": "dba642de-e9c9-4725-b1b6-28e2150f306b", - "control-id": "cis_rhel10_5-2.7", - "description": "Members of \"wheel\" or GID 0 groups are checked by default if the group option is not set for\npam_wheel.so module. The recommendation states the group should be empty to reinforce the\nuse of \"sudo\" for privileged access. Therefore, members of these groups should be manually\nchecked or a different group should be informed.", + "uuid": "ac331207-36c0-4b00-be26-9074a731bfd4", + "control-id": "cis_rhel10_6-1.1", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -9874,132 +9890,121 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "use_pam_wheel_group_for_su" + "value": "package_aide_installed" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_pam_wheel_group_empty" + "value": "aide_build_database" } ] }, { - "uuid": "7358bfa7-1cbf-4957-964e-8afbeabd7454", - "control-id": "cis_rhel10_5-3.1.1", + "uuid": "e14d4f9a-bf1d-43a9-b54c-e3a6916c31cc", + "control-id": "cis_rhel10_6-1.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary a new rule to ensure PAM package is updated." - } - ] - }, - { - "uuid": "4dc28c9f-9a13-4dd4-8dc8-8e546ff6db0b", - "control-id": "cis_rhel10_5-3.1.2", - "description": "REPLACE_ME", - "props": [ + "value": "implemented" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary a new rule to ensure authselect package is updated." + "value": "aide_periodic_cron_checking" } ] }, { - "uuid": "cdef4ebe-1587-4484-a61b-b269b30e9125", - "control-id": "cis_rhel10_5-3.1.3", + "uuid": "22ae63bf-d205-47a1-841b-81b494a3ab2d", + "control-id": "cis_rhel10_6-1.3", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary a new rule to ensure libpwquality package is updated." + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_pam_pwquality_installed" + "value": "aide_check_audit_tools" } ] }, { - "uuid": "ef8b7f0c-b71c-4135-a959-0936b5fac1cc", - "control-id": "cis_rhel10_5-3.2.1", - "description": "This requirement is hard to be automated without any specific requirement. The policy even\nstates that provided commands are examples, other custom settings might be in place and the\nsettings might be different depending on site policies. The other rules will already make\nsure there is a correct autheselect profile regardless of the existing settings. It is\nnecessary to better discuss with CIS Community.", + "uuid": "4072cc0f-c81a-40f5-83b4-971ed78b5e03", + "control-id": "cis_rhel10_6-2.1.1", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "service_systemd-journald_enabled" } ] }, { - "uuid": "2800d919-3bf9-49ce-ae9d-80823696b483", - "control-id": "cis_rhel10_5-3.2.2", - "description": "This requirement is also indirectly satisfied by the requirement 5.3.3.1.", + "uuid": "4f6e4d8a-ed03-45e1-8e89-4864e039d2ef", + "control-id": "cis_rhel10_6-2.1.2", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_password_auth" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_system_auth" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "86c48642-bd4b-4d3b-a702-b7d34fb6ae72", - "control-id": "cis_rhel10_5-3.2.3", - "description": "This requirement is also indirectly satisfied by the requirement 5.3.3.2.", + "uuid": "0cdcf23b-94e0-478f-9fee-8c69b0f4ec79", + "control-id": "cis_rhel10_6-2.1.3", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "b16c24b3-0fab-4aab-8c7f-3a9bba37cde5", - "control-id": "cis_rhel10_5-3.2.4", - "description": "The module is properly enabled by the rules mentioned in related_rules.\nRequirements in 5.3.3.3 use these rules.", + "uuid": "a0968feb-1274-4994-a276-e4e388c86927", + "control-id": "cis_rhel10_6-2.1.4", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "alternative", + "remarks": "It is necessary to create a new rule to check the status of journald and rsyslog.\nIt would also be necessary a new rule to disable or remove rsyslog." } ] }, { - "uuid": "a59016d6-9741-4f22-aa56-133028688775", - "control-id": "cis_rhel10_5-3.2.5", - "description": "This module is always present by default. It is necessary to investigate if a new rule to\ncheck its existence needs to be created. But so far the rule no_empty_passwords, used in\n5.3.3.4 can ensure this requirement is attended.", + "uuid": "77421df0-1f9c-43f1-aed2-8d04a4821357", + "control-id": "cis_rhel10_6-2.2.2", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "alternative", + "remarks": "This rule conflicts with 6.2.3.3. More investigation is needed to properly solve this." } ] }, { - "uuid": "37fa8e2b-86f8-4a0d-8715-19a77c05a3ee", - "control-id": "cis_rhel10_5-3.3.1.1", + "uuid": "18038a02-f36d-40c5-a578-30e7ff5f53d8", + "control-id": "cis_rhel10_6-2.2.3", "description": "REPLACE_ME", "props": [ { @@ -10010,14 +10015,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_deny" + "value": "journald_compress" } ] }, { - "uuid": "d62c47f1-ddb8-47a8-9146-7683abbd5be0", - "control-id": "cis_rhel10_5-3.3.1.2", - "description": "The policy also accepts value 0, which means the locked accounts should be manually unlocked\nby an administrator. However, it also mentions that using value 0 can facilitate a DoS\nattack to legitimate users.", + "uuid": "d03943d0-e855-4671-8b62-c0c9dc28f269", + "control-id": "cis_rhel10_6-2.2.4", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -10027,13 +10032,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_unlock_time" + "value": "journald_storage" } ] }, { - "uuid": "88fdd8b9-40e9-4e0d-9303-6a99e95828d5", - "control-id": "cis_rhel10_5-3.3.2.1", + "uuid": "d6a1eb9c-bce9-4972-976a-eb02a121db39", + "control-id": "cis_rhel10_6-2.2.1.1", "description": "REPLACE_ME", "props": [ { @@ -10044,47 +10049,39 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_difok" + "value": "package_systemd-journal-remote_installed" } ] }, { - "uuid": "3f1caef5-4cc1-4b63-a276-416b5a061069", - "control-id": "cis_rhel10_5-3.3.2.2", + "uuid": "94c26299-5a62-4bd3-8a04-9f6fc3912bd2", + "control-id": "cis_rhel10_6-2.2.1.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_minlen" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "e56d0de2-28e3-4a2a-a255-96f7f074d6ca", - "control-id": "cis_rhel10_5-3.3.2.3", - "description": "This requirement is expected to be manual. However, in previous versions of the policy\nit was already automated the configuration of \"minclass\" option. This posture was kept for\nRHEL 9 in this new version. Rules related to other options are informed in related_rules.\nIn short, minclass=4 alone can achieve the same result achieved by the combination of the\nother 4 options mentioned in the policy.", + "uuid": "c4498253-817e-4561-9a1d-66caf368fab4", + "control-id": "cis_rhel10_6-2.2.1.3", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_minclass" + "value": "alternative", + "remarks": "New templated rule is necessary." } ] }, { - "uuid": "6128f010-1c7a-4fab-99a3-b6908847d0ef", - "control-id": "cis_rhel10_5-3.3.2.4", + "uuid": "a12d9c88-f456-4c2e-a4d6-b4d135d018f6", + "control-id": "cis_rhel10_6-2.2.1.4", "description": "REPLACE_ME", "props": [ { @@ -10095,138 +10092,113 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_maxrepeat" + "value": "socket_systemd-journal-remote_disabled" } ] }, { - "uuid": "cf53c69c-5e36-4c68-803d-8f81fca7f138", - "control-id": "cis_rhel10_5-3.3.2.5", + "uuid": "fb25ed1c-41bc-484d-a559-eeb638c5af3a", + "control-id": "cis_rhel10_6-2.3.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "planned", - "remarks": "A new templated rule and variable are necessary for the maxsequence option." + "value": "implemented" } ] }, { - "uuid": "f202f3f8-0d11-4a3b-877b-7563c10b5703", - "control-id": "cis_rhel10_5-3.3.2.6", + "uuid": "7d11efeb-9bc9-4591-aaf9-0f2e84ee6b2d", + "control-id": "cis_rhel10_6-2.3.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_dictcheck" } ] }, { - "uuid": "0436b438-20c7-46c4-b327-8017c7131783", - "control-id": "cis_rhel10_5-3.3.2.7", + "uuid": "0b452722-9631-439e-892c-09dd61909f10", + "control-id": "cis_rhel10_6-2.3.3", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_enforce_root" } ] }, { - "uuid": "af30caa2-2365-45fb-898b-b0534ba25f73", - "control-id": "cis_rhel10_5-3.3.3.1", - "description": "Although mentioned in the section 5.3.3.3, there is no explicit requirement to configure\nretry option of pam_pwhistory. If come in the future, the rule accounts_password_pam_retry\ncan be used.", + "uuid": "40802664-c701-49ee-b18c-b9495d706ff8", + "control-id": "cis_rhel10_6-2.3.4", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_pwhistory_remember_password_auth" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_pwhistory_remember_system_auth" } ] }, { - "uuid": "a93c454a-d811-49a7-b555-5f6142bd2dd6", - "control-id": "cis_rhel10_5-3.3.3.2", + "uuid": "39eace4f-4ada-46ae-aeea-b25159b8e39c", + "control-id": "cis_rhel10_6-2.3.5", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "planned", - "remarks": "A new rule needs to be created to check and remediate the enforce_for_root option in\n/etc/security/pwhistory.conf. accounts_password_pam_enforce_root can be used as reference." + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "74cf7604-5669-4f21-9884-1f38c9e09d22", - "control-id": "cis_rhel10_5-3.3.3.3", - "description": "In RHEL 9 pam_pwhistory is enabled via authselect feature, as required in 5.3.2.4. The\nfeature automatically set \"use_authok\" option. In any case, we don't have a rule to check\nthis option specifically.", + "uuid": "25131a8b-b25c-43ab-918a-0e14f070e444", + "control-id": "cis_rhel10_6-2.3.6", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "6d738910-aecd-4c85-9763-ae7d59897725", - "control-id": "cis_rhel10_5-3.3.4.1", - "description": "The rule more specifically used in this requirement also satify the requirement 5.3.2.5.", + "uuid": "0b1b7624-7c74-475d-b2dd-7e2aff5b545a", + "control-id": "cis_rhel10_6-2.3.7", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_empty_passwords" } ] }, { - "uuid": "f6ccb4bb-0a4a-4e61-8797-f6c3360d9a55", - "control-id": "cis_rhel10_5-3.3.4.2", + "uuid": "bfea8c77-de5c-4339-a993-a935cd2634f4", + "control-id": "cis_rhel10_6-2.3.8", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "alternative", - "remarks": "Usage of pam_unix.so module together with \"remember\" option is deprecated and is not\nrecommened by this policy. Instead, it should be used remember option of pam_pwhistory\nmodule, as required in 5.3.3.3.1. See here for more details about pam_unix.so:\nhttps://bugzilla.redhat.com/show_bug.cgi?id=1778929\nA new rule needs to be created to remove the remember option from pam_unix module." + "remarks": "REPLACE_ME" } ] }, { - "uuid": "d026f78e-a285-4ee5-9952-1dd7c1bf504a", - "control-id": "cis_rhel10_5-3.3.4.3", - "description": "Changes in logindefs mentioned in this requirement are more specifically covered by 5.4.1.4", + "uuid": "179072a5-344e-4594-9b70-d78a52c51673", + "control-id": "cis_rhel10_6-2.4.1", + "description": "It is not harmful to run these rules even if rsyslog is not installed or active.", "props": [ { "name": "implementation-status", @@ -10236,30 +10208,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_systemauth" + "value": "rsyslog_files_groupownership" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_passwordauth" - } - ] - }, - { - "uuid": "71466350-4827-4552-81db-6ed5f6100a24", - "control-id": "cis_rhel10_5-3.3.4.4", - "description": "In RHEL 9 pam_unix is enabled by default in all authselect profiles already with the\nuse_authtok option set. In any case, we don't have a rule to check this option specifically,\nlike in 5.3.3.3.3.", - "props": [ + "value": "rsyslog_files_ownership" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "rsyslog_files_permissions" } ] }, { - "uuid": "98c2d85f-c193-4a58-a4d9-131ffa35b872", - "control-id": "cis_rhel10_5-4.1.1", + "uuid": "84604ffe-71ad-41ae-ae05-bbe8b8896cc1", + "control-id": "cis_rhel10_7-1.1", "description": "REPLACE_ME", "props": [ { @@ -10270,18 +10235,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_maximum_age_login_defs" + "value": "file_groupowner_etc_passwd" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_set_max_life_existing" + "value": "file_owner_etc_passwd" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_etc_passwd" } ] }, { - "uuid": "2d26db46-2dda-447c-bb20-63909b54cdd6", - "control-id": "cis_rhel10_5-4.1.3", + "uuid": "fc4f2057-cdfc-4a54-9ecc-3bb987f69ef5", + "control-id": "cis_rhel10_7-1.2", "description": "REPLACE_ME", "props": [ { @@ -10292,19 +10262,24 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_warn_age_login_defs" + "value": "file_groupowner_backup_etc_passwd" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_set_warn_age_existing" + "value": "file_owner_backup_etc_passwd" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_backup_etc_passwd" } ] }, { - "uuid": "456374ef-f52a-494e-8b49-95f38027bf6b", - "control-id": "cis_rhel10_5-4.1.4", - "description": "There's a \"new\" set of options in /etc/login.defs file to define the number of iterations\nperformed during the hashing process.", + "uuid": "ce77c4ba-b2a0-4181-81e2-cd2352fa8b4f", + "control-id": "cis_rhel10_7-1.3", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -10314,18 +10289,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_libuserconf" + "value": "file_groupowner_etc_group" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_logindefs" + "value": "file_owner_etc_group" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_etc_group" } ] }, { - "uuid": "8efb9ba8-e7d0-4013-af88-1ac0c4d63815", - "control-id": "cis_rhel10_5-4.1.5", + "uuid": "478a290d-dcc5-447d-9bbc-71bdaa940913", + "control-id": "cis_rhel10_7-1.4", "description": "REPLACE_ME", "props": [ { @@ -10336,18 +10316,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_disable_post_pw_expiration" + "value": "file_groupowner_backup_etc_group" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_set_post_pw_existing" + "value": "file_owner_backup_etc_group" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_backup_etc_group" } ] }, { - "uuid": "9a1aa70f-2732-4b14-869c-254c95d32a32", - "control-id": "cis_rhel10_5-4.1.6", + "uuid": "01b6242f-8298-4b09-b58c-dfd324eb1cb6", + "control-id": "cis_rhel10_7-1.5", "description": "REPLACE_ME", "props": [ { @@ -10358,60 +10343,50 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_last_change_is_in_past" - } - ] - }, - { - "uuid": "03c6d063-d74b-40ba-abc5-b0c07ee1ff66", - "control-id": "cis_rhel10_5-4.2.1", - "description": "REPLACE_ME", - "props": [ + "value": "file_owner_etc_shadow" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "file_groupowner_etc_shadow" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_no_uid_except_zero" + "value": "file_permissions_etc_shadow" } ] }, { - "uuid": "eceb392b-7d35-4d56-aa53-2c6442a3a70c", - "control-id": "cis_rhel10_5-4.2.2", - "description": "The rule confirms the primary group for root, but doesn't check if any other user are also\nusing GID 0. New rule is necessary.\nThere is assessment but no automated remediation for this rule and this sounds reasonable.", + "uuid": "cbe07cae-5f99-44b0-b70e-bd49c5a3b291", + "control-id": "cis_rhel10_7-1.6", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_root_gid_zero" - } - ] - }, - { - "uuid": "c216eaae-b11d-45ae-a671-b5f012fdc818", - "control-id": "cis_rhel10_5-4.2.3", - "description": "REPLACE_ME", - "props": [ + "value": "file_groupowner_backup_etc_shadow" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "New rule is necessary." + "value": "file_owner_backup_etc_shadow" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_backup_etc_shadow" } ] }, { - "uuid": "261549be-2aa2-4b82-a6f1-4f74ec86947e", - "control-id": "cis_rhel10_5-4.2.4", + "uuid": "ae61ae1a-9abf-4efc-b6bb-cc6efdf0a79b", + "control-id": "cis_rhel10_7-1.7", "description": "REPLACE_ME", "props": [ { @@ -10422,48 +10397,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_root_password_configured" - } - ] - }, - { - "uuid": "5133cf56-ac90-46b9-817c-1d3bbfd4641d", - "control-id": "cis_rhel10_5-4.2.5", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "file_groupowner_etc_gshadow" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_root_path_dirs_no_write" + "value": "file_owner_etc_gshadow" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "root_path_no_dot" - } - ] - }, - { - "uuid": "88171e79-966c-411a-bc8b-10a7f4ee973e", - "control-id": "cis_rhel10_5-4.2.6", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "There is no rule to ensure umask in /root/.bash_profile and /root/.bashrc. A new rule have\nto be created. It can be based on accounts_umask_interactive_users." + "value": "file_permissions_etc_gshadow" } ] }, { - "uuid": "b542684b-b255-49ab-961e-435b6f955c82", - "control-id": "cis_rhel10_5-4.2.7", + "uuid": "11a3e914-03be-4320-8916-a6ccd0cd8350", + "control-id": "cis_rhel10_7-1.8", "description": "REPLACE_ME", "props": [ { @@ -10474,48 +10424,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_password_auth_for_systemaccounts" + "value": "file_groupowner_backup_etc_gshadow" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_shelllogin_for_systemaccounts" - } - ] - }, - { - "uuid": "7ae8c8b7-3f3c-4e77-96ed-47e783b8d44f", - "control-id": "cis_rhel10_5-4.2.8", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "New rule is necessary." - } - ] - }, - { - "uuid": "d85831fa-f7dd-4976-80e2-96abd7a14ad0", - "control-id": "cis_rhel10_5-4.3.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "file_owner_backup_etc_gshadow" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_tmout" + "value": "file_permissions_backup_etc_gshadow" } ] }, { - "uuid": "64f86d65-e6fc-445a-9a37-f5bd779122d1", - "control-id": "cis_rhel10_5-4.3.3", + "uuid": "8fbe43f5-a229-45bb-aac2-6f86aedd9565", + "control-id": "cis_rhel10_7-1.9", "description": "REPLACE_ME", "props": [ { @@ -10526,23 +10451,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_umask_etc_bashrc" + "value": "file_groupowner_etc_shells" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_umask_etc_login_defs" + "value": "file_owner_etc_shells" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_umask_etc_profile" + "value": "file_permissions_etc_shells" } ] }, { - "uuid": "0e409bbf-893f-48cf-8f31-07c9cbc7e351", - "control-id": "cis_rhel10_6-1.1", + "uuid": "1dfcc1ce-6a8b-4564-98b0-d6ef14030b48", + "control-id": "cis_rhel10_7-1.10", "description": "REPLACE_ME", "props": [ { @@ -10553,18 +10478,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_aide_installed" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "aide_build_database" + "value": "file_etc_security_opasswd" } ] }, { - "uuid": "fc757c4e-7101-40ca-a301-0c3f392ee17b", - "control-id": "cis_rhel10_6-1.2", + "uuid": "71ac1e7b-33e1-4888-ab17-91c53f502a80", + "control-id": "cis_rhel10_7-1.11", "description": "REPLACE_ME", "props": [ { @@ -10575,60 +10495,40 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "aide_periodic_cron_checking" - } - ] - }, - { - "uuid": "f1153805-ffbd-48ae-9368-474698f944cf", - "control-id": "cis_rhel10_6-1.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "file_permissions_unauthorized_world_writable" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "aide_check_audit_tools" + "value": "dir_perms_world_writable_sticky_bits" } ] }, { - "uuid": "bafc065b-c7d5-4f3f-8c50-c5fd2dcc11ac", - "control-id": "cis_rhel10_6-2.1.1", + "uuid": "183f9b02-c754-4772-a9cf-1179d8e5f512", + "control-id": "cis_rhel10_7-1.12", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "partial" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_systemd-journald_enabled" - } - ] - }, - { - "uuid": "2ec49119-5507-4256-93b3-5797dac74b82", - "control-id": "cis_rhel10_6-2.1.2", - "description": "REPLACE_ME", - "props": [ + "value": "no_files_unowned_by_user" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "file_permissions_ungroupowned" } ] }, { - "uuid": "c2e52e0f-36bb-4102-9ffd-7a7c6df6d169", - "control-id": "cis_rhel10_6-2.1.3", + "uuid": "557eb73c-e861-4264-9397-b545bbaf6793", + "control-id": "cis_rhel10_7-1.13", "description": "REPLACE_ME", "props": [ { @@ -10640,21 +10540,8 @@ ] }, { - "uuid": "771642ef-8ee0-48dd-87f7-771b7750f1cc", - "control-id": "cis_rhel10_6-2.1.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary to create a new rule to check the status of journald and rsyslog.\nIt would also be necessary a new rule to disable or remove rsyslog." - } - ] - }, - { - "uuid": "14016d8c-a557-4228-a4ff-31cc83224957", - "control-id": "cis_rhel10_6-2.2.1.1", + "uuid": "971e5dda-7017-4766-926a-ec27d276a07e", + "control-id": "cis_rhel10_7-2.1", "description": "REPLACE_ME", "props": [ { @@ -10665,39 +10552,30 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_systemd-journal-remote_installed" + "value": "accounts_password_all_shadowed" } ] }, { - "uuid": "ed259b98-646d-48b9-977e-ad99f15e2307", - "control-id": "cis_rhel10_6-2.2.1.2", + "uuid": "6b1502c3-fd1b-405b-a6ce-46b83c32f876", + "control-id": "cis_rhel10_7-2.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } - ] - }, - { - "uuid": "6f8fec65-71e6-4cb1-aa61-1eebae27e3cb", - "control-id": "cis_rhel10_6-2.2.1.3", - "description": "REPLACE_ME", - "props": [ + "value": "implemented" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "New templated rule is necessary." + "value": "no_empty_passwords_etc_shadow" } ] }, { - "uuid": "d9c60c1f-8f90-4295-ae60-b8db0cbf3c66", - "control-id": "cis_rhel10_6-2.2.1.4", + "uuid": "405300ba-33b7-43ed-939c-e0875d41e1b3", + "control-id": "cis_rhel10_7-2.3", "description": "REPLACE_ME", "props": [ { @@ -10708,26 +10586,30 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "socket_systemd-journal-remote_disabled" + "value": "gid_passwd_group_same" } ] }, { - "uuid": "ca91d5a9-9ec2-4583-b1aa-b7a5f92410be", - "control-id": "cis_rhel10_6-2.2.2", + "uuid": "98d4486e-1e64-445f-8f51-5a9d984710b8", + "control-id": "cis_rhel10_7-2.4", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "This rule conflicts with 6.2.3.3. More investigation is needed to properly solve this." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "account_unique_id" } ] }, { - "uuid": "e80491fb-f894-4861-8574-3bece6d99f7a", - "control-id": "cis_rhel10_6-2.2.3", + "uuid": "43cfbff2-8ad9-4ba3-ab0a-967ac649a8a5", + "control-id": "cis_rhel10_7-2.5", "description": "REPLACE_ME", "props": [ { @@ -10738,13 +10620,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_compress" + "value": "group_unique_id" } ] }, { - "uuid": "dfd67861-9713-4e87-8336-f7075a39333b", - "control-id": "cis_rhel10_6-2.2.4", + "uuid": "387fbd61-8a14-459a-a241-575bed9406f2", + "control-id": "cis_rhel10_7-2.6", "description": "REPLACE_ME", "props": [ { @@ -10755,638 +10637,93 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_storage" + "value": "account_unique_name" } ] }, { - "uuid": "05ec0c02-1ef9-48cf-bec2-9961f2fa0e90", - "control-id": "cis_rhel10_6-2.3.1", + "uuid": "c85ab798-e726-4b62-9894-f927368ba965", + "control-id": "cis_rhel10_7-2.7", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - } - ] - }, - { - "uuid": "7d65a877-b4e2-4251-aae6-2f78aceee80e", - "control-id": "cis_rhel10_6-2.3.2", - "description": "REPLACE_ME", - "props": [ + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "group_unique_name" } ] }, { - "uuid": "10499c6b-f6ba-4eef-881e-24509266ae1f", - "control-id": "cis_rhel10_6-2.3.3", + "uuid": "3013ea80-9d3d-4d33-8467-2d8060e011c5", + "control-id": "cis_rhel10_7-2.8", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - } - ] - }, - { - "uuid": "56b33a5a-db82-4c66-9af4-c67386e0329c", - "control-id": "cis_rhel10_6-2.3.4", - "description": "REPLACE_ME", - "props": [ + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - } - ] - }, - { - "uuid": "69c5cb7e-463e-420a-87a1-91e05c664a60", - "control-id": "cis_rhel10_6-2.3.5", - "description": "REPLACE_ME", - "props": [ + "value": "accounts_user_interactive_home_directory_exists" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } - ] - }, - { - "uuid": "74f6bf30-669c-41df-98ba-90618f423eb4", - "control-id": "cis_rhel10_6-2.3.6", - "description": "REPLACE_ME", - "props": [ + "value": "file_ownership_home_directories" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "file_permissions_home_directories" } ] }, { - "uuid": "6ceae884-a9c3-46c7-ae33-dfb723cdb708", - "control-id": "cis_rhel10_6-2.3.7", - "description": "REPLACE_ME", + "uuid": "281c24e6-0b2c-4a1d-ac6a-755fac35e914", + "control-id": "cis_rhel10_7-2.9", + "description": "Missing a rule to check that .bash_history is mode 0600 or more restrictive.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - } - ] - }, - { - "uuid": "b23579f7-a5fd-44f2-a04f-5760f57c832b", - "control-id": "cis_rhel10_6-2.3.8", - "description": "REPLACE_ME", - "props": [ + "value": "partial" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } - ] - }, - { - "uuid": "a346c2c5-ed6d-4c7b-bab6-9a0eef2ffd65", - "control-id": "cis_rhel10_6-2.4.1", - "description": "It is not harmful to run these rules even if rsyslog is not installed or active.", - "props": [ + "value": "accounts_user_dot_group_ownership" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "accounts_user_dot_user_ownership" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "rsyslog_files_groupownership" + "value": "accounts_user_dot_no_world_writable_programs" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "rsyslog_files_ownership" + "value": "file_permission_user_init_files" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "rsyslog_files_permissions" - } - ] - }, - { - "uuid": "4f7b37ae-1acc-4433-b896-460349430604", - "control-id": "cis_rhel10_7-1.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_passwd" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_passwd" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_passwd" - } - ] - }, - { - "uuid": "3f47ff93-ad1b-4aad-bd97-a25a44bfd2cb", - "control-id": "cis_rhel10_7-1.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_passwd" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_passwd" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_passwd" - } - ] - }, - { - "uuid": "986d3b10-47ce-498d-93b7-f6f6aead94e2", - "control-id": "cis_rhel10_7-1.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_group" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_group" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_group" - } - ] - }, - { - "uuid": "924db0bc-b0e0-41e9-871e-466744fab4e1", - "control-id": "cis_rhel10_7-1.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_group" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_group" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_group" - } - ] - }, - { - "uuid": "965ea16d-0d4d-43c1-8cd9-9c9a0a02280f", - "control-id": "cis_rhel10_7-1.5", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_shadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_shadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_shadow" - } - ] - }, - { - "uuid": "c013c6b8-a442-452a-bd43-7772c9a049f0", - "control-id": "cis_rhel10_7-1.6", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_shadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_shadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_shadow" - } - ] - }, - { - "uuid": "5eb78bd0-c7e2-4326-87ff-fe8bff96008e", - "control-id": "cis_rhel10_7-1.7", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_gshadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_gshadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_gshadow" - } - ] - }, - { - "uuid": "95ba1316-6515-41d4-a8f3-44ffb7e463cb", - "control-id": "cis_rhel10_7-1.8", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_gshadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_gshadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_gshadow" - } - ] - }, - { - "uuid": "acf4cd0b-6cfa-44e3-9a62-a5682c6135fb", - "control-id": "cis_rhel10_7-1.9", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_shells" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_shells" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_shells" - } - ] - }, - { - "uuid": "e97a921e-2ffd-45d7-81ec-72818b2834b3", - "control-id": "cis_rhel10_7-1.10", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "no_forward_files" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_etc_security_opasswd" - } - ] - }, - { - "uuid": "fa81b709-b004-4091-bee6-592b2fcb3e15", - "control-id": "cis_rhel10_7-1.11", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_unauthorized_world_writable" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dir_perms_world_writable_sticky_bits" - } - ] - }, - { - "uuid": "5e52cb1b-6d7c-4ed6-bb23-8103a3505039", - "control-id": "cis_rhel10_7-1.12", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_files_unowned_by_user" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_ungroupowned" - } - ] - }, - { - "uuid": "950bebc6-56bc-4f39-ae2c-7bfdf5adbad1", - "control-id": "cis_rhel10_7-1.13", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } - ] - }, - { - "uuid": "8c8bb80e-d135-4481-90dc-fd0bd81473b5", - "control-id": "cis_rhel10_7-2.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_all_shadowed" - } - ] - }, - { - "uuid": "150a8f44-8316-4c7d-8157-5a363a0a284d", - "control-id": "cis_rhel10_7-2.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_empty_passwords_etc_shadow" - } - ] - }, - { - "uuid": "4b0bb1e1-e389-4e07-abad-b33c3aa829ba", - "control-id": "cis_rhel10_7-2.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "gid_passwd_group_same" - } - ] - }, - { - "uuid": "59664ce1-6ad0-4099-b09d-154b11521ab0", - "control-id": "cis_rhel10_7-2.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_unique_id" - } - ] - }, - { - "uuid": "ba760dcb-39ad-4cb2-b735-6a3cb4855092", - "control-id": "cis_rhel10_7-2.5", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "group_unique_id" - } - ] - }, - { - "uuid": "df009230-fee1-48ba-8e68-4006905573d5", - "control-id": "cis_rhel10_7-2.6", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_unique_name" - } - ] - }, - { - "uuid": "f3f028b1-8736-45d6-9e90-23975bb45934", - "control-id": "cis_rhel10_7-2.7", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "group_unique_name" - } - ] - }, - { - "uuid": "efea6b2b-1f13-4b22-a814-b54480f79bd4", - "control-id": "cis_rhel10_7-2.8", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_user_interactive_home_directory_exists" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_home_directories" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_home_directories" - } - ] - }, - { - "uuid": "2dafc7ed-794e-466f-9da0-21e173863b4a", - "control-id": "cis_rhel10_7-2.9", - "description": "Missing a rule to check that .bash_history is mode 0600 or more restrictive.", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_user_dot_group_ownership" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_user_dot_user_ownership" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_user_dot_no_world_writable_programs" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permission_user_init_files" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_forward_files" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_netrc_files" + "value": "no_netrc_files" } ] } @@ -11529,7 +10866,7 @@ { "name": "Parameter_Value_Alternatives_5", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", + "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel10': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", "remarks": "rule_set_000" }, { @@ -11547,7 +10884,7 @@ { "name": "Parameter_Value_Alternatives_6", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", + "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel10': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", "remarks": "rule_set_000" }, { @@ -11913,10817 +11250,10545 @@ { "name": "Parameter_Id_27", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_account_disable_post_pw_expiration", + "value": "sysctl_net_ipv6_conf_default_forwarding_value", "remarks": "rule_set_000" }, { "name": "Parameter_Description_27", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The number of days to wait after a password expires, until the account will be permanently disabled.", + "value": "Toggle IPv6 default Forwarding", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_27", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'0': '0', 180: 180, 30: 30, 35: 35, 40: 40, 45: 45, 60: 60, 90: 90, 'default': 35}", + "value": "{'default': '0', 'disabled': '0', 'enabled': 1}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_28", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_maximum_age_login_defs", + "value": "var_account_disable_post_pw_expiration", "remarks": "rule_set_000" }, { "name": "Parameter_Description_28", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Maximum age of password in days", + "value": "The number of days to wait after a password expires, until the account will be permanently disabled.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_28", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{365: 365, 120: 120, 180: 180, 90: 90, 60: 60, 45: 45, 'default': 60}", + "value": "{'0': '0', 180: 180, 30: 30, 35: 35, 40: 40, 45: 45, 60: 60, 90: 90, 'default': 35}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_29", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_minimum_age_login_defs", + "value": "var_accounts_maximum_age_login_defs", "remarks": "rule_set_000" }, { "name": "Parameter_Description_29", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Minimum age of password in days", + "value": "Maximum age of password in days", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_29", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'0': '0', 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 'default': 7}", + "value": "{365: 365, 120: 120, 180: 180, 90: 90, 60: 60, 45: 45, 'default': 60}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_30", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_password_warn_age_login_defs", + "value": "var_accounts_minimum_age_login_defs", "remarks": "rule_set_000" }, { "name": "Parameter_Description_30", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The number of days' warning given before a password expires.", + "value": "Minimum age of password in days", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_30", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'0': '0', 14: 14, 10: 10, 7: 7, 'default': 7}", + "value": "{'0': '0', 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 'default': 7}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_31", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_passwords_pam_faillock_deny", + "value": "var_accounts_password_warn_age_login_defs", "remarks": "rule_set_000" }, { "name": "Parameter_Description_31", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Number of failed login attempts before account lockout", + "value": "The number of days' warning given before a password expires.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_31", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{10: 10, 3: 3, 4: 4, 5: 5, 6: 6, 8: 8, 'default': 3}", + "value": "{'0': '0', 14: 14, 10: 10, 7: 7, 'default': 7}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_32", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_passwords_pam_faillock_dir", + "value": "var_accounts_passwords_pam_faillock_deny", "remarks": "rule_set_000" }, { "name": "Parameter_Description_32", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The directory where the user files with the failure records are kept", + "value": "Number of failed login attempts before account lockout", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_32", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'ol8': '/var/log/faillock', 'default': '/var/log/faillock', 'run': '/var/run/faillock'}", + "value": "{10: 10, 3: 3, 4: 4, 5: 5, 6: 6, 8: 8, 'default': 3}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_33", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_passwords_pam_faillock_unlock_time", + "value": "var_accounts_passwords_pam_faillock_dir", "remarks": "rule_set_000" }, { "name": "Parameter_Description_33", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Seconds before automatic unlocking or permanently locking after excessive failed logins", + "value": "The directory where the user files with the failure records are kept", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_33", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{1800: 1800, 3600: 3600, 600: 600, 604800: 604800, 86400: 86400, 900: 900, 300: 300, 'default': 0, 'never': 0}", + "value": "{'ol8': '/var/log/faillock', 'default': '/var/log/faillock', 'run': '/var/run/faillock'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_34", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_tmout", + "value": "var_accounts_passwords_pam_faillock_unlock_time", "remarks": "rule_set_000" }, { "name": "Parameter_Description_34", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "In an interactive shell, the value is interpreted as the number of seconds to wait for input after issuing the primary prompt. Bash terminates after waiting for that number of seconds if input does not arrive.", + "value": "Seconds before automatic unlocking or permanently locking after excessive failed logins", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_34", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'30_min': 1800, '10_min': 600, '15_min': 900, '5_min': 300, 'default': 600}", + "value": "{1800: 1800, 3600: 3600, 600: 600, 604800: 604800, 86400: 86400, 900: 900, 300: 300, 'default': 0, 'never': 0}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_35", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_accounts_user_umask", + "value": "var_accounts_tmout", "remarks": "rule_set_000" }, { "name": "Parameter_Description_35", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enter default user umask", + "value": "In an interactive shell, the value is interpreted as the number of seconds to wait for input after issuing the primary prompt. Bash terminates after waiting for that number of seconds if input does not arrive.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_35", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'007': '007', '022': '022', '027': '027', '077': '077', 'default': '027'}", + "value": "{'30_min': 1800, '10_min': 600, '15_min': 900, '5_min': 300, 'default': 600}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_36", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_auditd_action_mail_acct", + "value": "var_accounts_user_umask", "remarks": "rule_set_000" }, { "name": "Parameter_Description_36", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The setting for action_mail_acct in /etc/audit/auditd.conf", + "value": "Enter default user umask", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_36", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'admin': 'admin', 'default': 'root', 'root': 'root'}", + "value": "{'007': '007', '022': '022', '027': '027', '077': '077', 'default': '027'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_auditd_admin_space_left_action", + "value": "var_auditd_action_mail_acct", "remarks": "rule_set_000" }, { "name": "Parameter_Description_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The setting for admin_space_left_action in /etc/audit/auditd.conf", + "value": "The setting for action_mail_acct in /etc/audit/auditd.conf", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt'}", + "value": "{'admin': 'admin', 'default': 'root', 'root': 'root'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_auditd_disk_error_action", + "value": "var_auditd_admin_space_left_action", "remarks": "rule_set_000" }, { "name": "Parameter_Description_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "'The setting for disk_error_action in /etc/audit/auditd.conf, if multiple values are allowed write them separated by pipes as in \"syslog|single|halt\", for remediations the first value will be taken'", + "value": "The setting for admin_space_left_action in /etc/audit/auditd.conf", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", + "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt', 'cis_rhel10': 'single|halt'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_auditd_disk_full_action", + "value": "var_auditd_disk_error_action", "remarks": "rule_set_000" }, { "name": "Parameter_Description_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "'The setting for disk_full_action in /etc/audit/auditd.conf, if multiple values are allowed write them separated by pipes as in \"syslog|single|halt\", for remediations the first value will be taken'", + "value": "'The setting for disk_error_action in /etc/audit/auditd.conf, if multiple values are allowed write them separated by pipes as in \"syslog|single|halt\", for remediations the first value will be taken'", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_rhel10': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_40", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_auditd_max_log_file", + "value": "var_auditd_disk_full_action", "remarks": "rule_set_000" }, { "name": "Parameter_Description_40", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The setting for max_log_file in /etc/audit/auditd.conf", + "value": "'The setting for disk_full_action in /etc/audit/auditd.conf, if multiple values are allowed write them separated by pipes as in \"syslog|single|halt\", for remediations the first value will be taken'", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_40", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{1: 1, 10: 10, 20: 20, 5: 5, 6: 6, 'default': 6}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_rhel10': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_41", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_auditd_max_log_file_action", + "value": "var_auditd_max_log_file", "remarks": "rule_set_000" }, { "name": "Parameter_Description_41", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The setting for max_log_file_action in /etc/audit/auditd.conf. The following options are available:
ignore - audit daemon does nothing.
syslog - audit daemon will issue a warning to syslog.
suspend - audit daemon will stop writing records to the disk.
rotate - audit daemon will rotate logs in the same convention used by logrotate.
keep_logs - similar to rotate but prevents audit logs to be overwritten. May trigger space_left_action if volume is full.", + "value": "The setting for max_log_file in /etc/audit/auditd.conf", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_41", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'rotate', 'keep_logs': 'keep_logs', 'rotate': 'rotate', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore'}", + "value": "{1: 1, 10: 10, 20: 20, 5: 5, 6: 6, 'default': 6}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_42", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_auditd_space_left_action", + "value": "var_auditd_max_log_file_action", "remarks": "rule_set_000" }, { "name": "Parameter_Description_42", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The setting for space_left_action in /etc/audit/auditd.conf", + "value": "The setting for max_log_file_action in /etc/audit/auditd.conf. The following options are available:
ignore - audit daemon does nothing.
syslog - audit daemon will issue a warning to syslog.
suspend - audit daemon will stop writing records to the disk.
rotate - audit daemon will rotate logs in the same convention used by logrotate.
keep_logs - similar to rotate but prevents audit logs to be overwritten. May trigger space_left_action if volume is full.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_42", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt'}", + "value": "{'default': 'rotate', 'keep_logs': 'keep_logs', 'rotate': 'rotate', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_43", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_authselect_profile", + "value": "var_auditd_space_left_action", "remarks": "rule_set_000" }, { "name": "Parameter_Description_43", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the authselect profile to select", + "value": "The setting for space_left_action in /etc/audit/auditd.conf", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_43", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'local': 'local', 'default': 'minimal', 'minimal': 'minimal', 'sssd': 'sssd'}", + "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt', 'cis_rhel10': 'email|exec|single|halt'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_44", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_multiple_time_servers", + "value": "var_authselect_profile", "remarks": "rule_set_000" }, { "name": "Parameter_Description_44", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The list of vendor-approved time servers", + "value": "Specify the authselect profile to select", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_44", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'generic': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'stig': '0.us.pool.ntp.mil', 'fedora': '0.fedora.pool.ntp.org,1.fedora.pool.ntp.org,2.fedora.pool.ntp.org,3.fedora.pool.ntp.org', 'rhel': '0.rhel.pool.ntp.org,1.rhel.pool.ntp.org,2.rhel.pool.ntp.org,3.rhel.pool.ntp.org', 'ol': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'suse': '0.suse.pool.ntp.org,1.suse.pool.ntp.org,2.suse.pool.ntp.org,3.suse.pool.ntp.org', 'alinux': '0.ntp.cloud.aliyuncs.com,1.ntp.aliyun.com,2.ntp1.aliyun.com,3.ntp1.cloud.aliyuncs.com', 'amazon': '0.rhel.pool.ntp.org,1.rhel.pool.ntp.org,2.rhel.pool.ntp.org,3.rhel.pool.ntp.org', 'ubuntu': '0.ubuntu.pool.ntp.org,1.ubuntu.pool.ntp.org,2.ubuntu.pool.ntp.org,3.ubuntu.pool.ntp.org', 'almalinux': '0.almalinux.pool.ntp.org,1.almalinux.pool.ntp.org,2.almalinux.pool.ntp.org,3.almalinux.pool.ntp.org', 'debian': '0.debian.pool.ntp.org,1.debian.pool.ntp.org,2.debian.pool.ntp.org,3.debian.pool.ntp.org', 'nist': 'time.nist.gov,time-a-g.nist.gov,time-b-g.nist.gov,time-c-g.nist.gov'}", + "value": "{'local': 'local', 'default': 'minimal', 'minimal': 'minimal', 'sssd': 'sssd'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_45", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_pam_wheel_group_for_su", + "value": "var_multiple_time_servers", "remarks": "rule_set_000" }, { "name": "Parameter_Description_45", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "pam_wheel module has a parameter called group, which controls which groups can access the su command. This variable holds the valid value for the parameter.", + "value": "The list of vendor-approved time servers", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_45", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'sugroup', 'cis': 'sugroup'}", + "value": "{'default': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'generic': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'stig': '0.us.pool.ntp.mil', 'fedora': '0.fedora.pool.ntp.org,1.fedora.pool.ntp.org,2.fedora.pool.ntp.org,3.fedora.pool.ntp.org', 'rhel': '0.rhel.pool.ntp.org,1.rhel.pool.ntp.org,2.rhel.pool.ntp.org,3.rhel.pool.ntp.org', 'ol': '0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org', 'suse': '0.suse.pool.ntp.org,1.suse.pool.ntp.org,2.suse.pool.ntp.org,3.suse.pool.ntp.org', 'alinux': '0.ntp.cloud.aliyuncs.com,1.ntp.aliyun.com,2.ntp1.aliyun.com,3.ntp1.cloud.aliyuncs.com', 'amazon': '0.rhel.pool.ntp.org,1.rhel.pool.ntp.org,2.rhel.pool.ntp.org,3.rhel.pool.ntp.org', 'ubuntu': '0.ubuntu.pool.ntp.org,1.ubuntu.pool.ntp.org,2.ubuntu.pool.ntp.org,3.ubuntu.pool.ntp.org', 'almalinux': '0.almalinux.pool.ntp.org,1.almalinux.pool.ntp.org,2.almalinux.pool.ntp.org,3.almalinux.pool.ntp.org', 'debian': '0.debian.pool.ntp.org,1.debian.pool.ntp.org,2.debian.pool.ntp.org,3.debian.pool.ntp.org', 'nist': 'time.nist.gov,time-a-g.nist.gov,time-b-g.nist.gov,time-c-g.nist.gov'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_46", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_hashing_algorithm", + "value": "var_pam_wheel_group_for_su", "remarks": "rule_set_000" }, { "name": "Parameter_Description_46", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the system default encryption algorithm for encrypting passwords. Defines the value set as ENCRYPT_METHOD in /etc/login.defs.", + "value": "pam_wheel module has a parameter called group, which controls which groups can access the su command. This variable holds the valid value for the parameter.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_46", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'SHA512', 'SHA512': 'SHA512', 'SHA256': 'SHA256', 'yescrypt': 'YESCRYPT', 'cis_ubuntu2404': 'SHA512|YESCRYPT'}", + "value": "{'default': 'sugroup', 'cis': 'sugroup'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_47", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_hashing_algorithm_pam", + "value": "var_password_hashing_algorithm", "remarks": "rule_set_000" }, { "name": "Parameter_Description_47", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the system default encryption algorithm for encrypting passwords. Defines the hashing algorithm to be used in pam_unix.so.", + "value": "Specify the system default encryption algorithm for encrypting passwords. Defines the value set as ENCRYPT_METHOD in /etc/login.defs.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_47", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'sha512', 'sha512': 'sha512', 'yescrypt': 'yescrypt'}", + "value": "{'default': 'SHA512', 'SHA512': 'SHA512', 'SHA256': 'SHA256', 'yescrypt': 'YESCRYPT', 'cis_ubuntu2404': 'SHA512|YESCRYPT'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_48", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_dictcheck", + "value": "var_password_hashing_algorithm_pam", "remarks": "rule_set_000" }, { "name": "Parameter_Description_48", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Prevent the use of dictionary words for passwords.", + "value": "Specify the system default encryption algorithm for encrypting passwords. Defines the hashing algorithm to be used in pam_unix.so.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_48", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{1: 1, 'default': 1}", + "value": "{'default': 'sha512', 'sha512': 'sha512', 'yescrypt': 'yescrypt'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_49", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_difok", + "value": "var_password_pam_dictcheck", "remarks": "rule_set_000" }, { "name": "Parameter_Description_49", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Minimum number of characters not present in old password", + "value": "Prevent the use of dictionary words for passwords.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_49", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{15: 15, 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 8: 8, 'default': 8}", + "value": "{1: 1, 'default': 1}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_50", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_maxrepeat", + "value": "var_password_pam_difok", "remarks": "rule_set_000" }, { "name": "Parameter_Description_50", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Maximum Number of Consecutive Repeating Characters in a Password", + "value": "Minimum number of characters not present in old password", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_50", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{1: 1, 2: 2, 3: 3, 'default': 3}", + "value": "{15: 15, 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 8: 8, 'default': 8}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_51", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_minclass", + "value": "var_password_pam_maxrepeat", "remarks": "rule_set_000" }, { "name": "Parameter_Description_51", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Minimum number of categories of characters that must exist in a password", + "value": "Maximum Number of Consecutive Repeating Characters in a Password", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_51", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{1: 1, 2: 2, 3: 3, 4: 4, 'default': 3}", + "value": "{1: 1, 2: 2, 3: 3, 'default': 3}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_52", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_minlen", + "value": "var_password_pam_minclass", "remarks": "rule_set_000" }, { "name": "Parameter_Description_52", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Minimum number of characters in password", + "value": "Minimum number of categories of characters that must exist in a password", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_52", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{10: 10, 12: 12, 14: 14, 15: 15, 17: 17, 18: 18, 20: 20, 6: 6, 7: 7, 8: 8, 'default': 15}", + "value": "{1: 1, 2: 2, 3: 3, 4: 4, 'default': 3}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_53", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_remember", + "value": "var_password_pam_minlen", "remarks": "rule_set_000" }, { "name": "Parameter_Description_53", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Prevent password re-use using password history lookup", + "value": "Minimum number of characters in password", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_53", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'0': '0', 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 8: 8, 9: 9, 24: 24, 'default': 5}", + "value": "{10: 10, 12: 12, 14: 14, 15: 15, 17: 17, 18: 18, 20: 20, 6: 6, 7: 7, 8: 8, 'default': 15}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_54", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_password_pam_remember_control_flag", + "value": "var_password_pam_remember", "remarks": "rule_set_000" }, { "name": "Parameter_Description_54", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "'Specify the control flag required for password remember requirement. If multiple values are allowed write them separated by commas as in \"required,requisite\", for remediations the first value will be taken'", + "value": "Prevent password re-use using password history lookup", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_54", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'required': 'required', 'optional': 'optional', 'requisite': 'requisite', 'sufficient': 'sufficient', 'binding': 'binding', 'ol8': 'required,requisite', 'requisite_or_required': 'requisite,required', 'default': 'requisite'}", + "value": "{'0': '0', 1: 1, 2: 2, 3: 3, 4: 4, 5: 5, 6: 6, 7: 7, 8: 8, 9: 9, 24: 24, 'default': 5}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_55", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_postfix_inet_interfaces", + "value": "var_password_pam_remember_control_flag", "remarks": "rule_set_000" }, { "name": "Parameter_Description_55", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "The setting for inet_interfaces in /etc/postfix/main.cf", + "value": "'Specify the control flag required for password remember requirement. If multiple values are allowed write them separated by commas as in \"required,requisite\", for remediations the first value will be taken'", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_55", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'loopback-only': 'loopback-only', 'default': 'loopback-only', 'localhost': 'localhost'}", + "value": "{'required': 'required', 'optional': 'optional', 'requisite': 'requisite', 'sufficient': 'sufficient', 'binding': 'binding', 'ol8': 'required,requisite', 'requisite_or_required': 'requisite,required', 'default': 'requisite'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_56", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_screensaver_lock_delay", + "value": "var_postfix_inet_interfaces", "remarks": "rule_set_000" }, { "name": "Parameter_Description_56", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Choose allowed duration (in seconds) after a screensaver becomes active before displaying an authentication prompt", + "value": "The setting for inet_interfaces in /etc/postfix/main.cf", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_56", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'10_seconds': 10, '5_seconds': 5, 'default': '0', 'immediate': '0'}", + "value": "{'loopback-only': 'loopback-only', 'default': 'loopback-only', 'localhost': 'localhost'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_57", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_selinux_policy_name", + "value": "var_screensaver_lock_delay", "remarks": "rule_set_000" }, { "name": "Parameter_Description_57", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Type of policy in use. Possible values are:
targeted - Only targeted network daemons are protected.
strict - Full SELinux protection.
mls - Multiple levels of security", + "value": "Choose allowed duration (in seconds) after a screensaver becomes active before displaying an authentication prompt", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_57", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'targeted', 'mls': 'mls', 'targeted': 'targeted'}", + "value": "{'10_seconds': 10, '5_seconds': 5, 'default': '0', 'immediate': '0'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_58", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_selinux_state", + "value": "var_selinux_policy_name", "remarks": "rule_set_000" }, { "name": "Parameter_Description_58", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "enforcing - SELinux security policy is enforced.
permissive - SELinux prints warnings instead of enforcing.
disabled - SELinux is fully disabled.", + "value": "Type of policy in use. Possible values are:
targeted - Only targeted network daemons are protected.
strict - Full SELinux protection.
mls - Multiple levels of security", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_58", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'enforcing', 'disabled': 'disabled', 'enforcing': 'enforcing', 'permissive': 'permissive'}", + "value": "{'default': 'targeted', 'mls': 'mls', 'targeted': 'targeted'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_59", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_sshd_max_sessions", + "value": "var_selinux_state", "remarks": "rule_set_000" }, { "name": "Parameter_Description_59", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the maximum number of open sessions permitted.", + "value": "enforcing - SELinux security policy is enforced.
permissive - SELinux prints warnings instead of enforcing.
disabled - SELinux is fully disabled.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_59", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{10: 10, 4: 4, 3: 3, 2: 2, 1: 1, 0: 0, 'default': 10}", + "value": "{'default': 'enforcing', 'disabled': 'disabled', 'enforcing': 'enforcing', 'permissive': 'permissive'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_60", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_sshd_set_keepalive", + "value": "var_sshd_max_sessions", "remarks": "rule_set_000" }, { "name": "Parameter_Description_60", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the maximum number of idle message counts before session is terminated.", + "value": "Specify the maximum number of open sessions permitted.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_60", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{10: 10, 3: 3, 5: 5, 0: 0, 1: 1, 'default': 0}", + "value": "{10: 10, 4: 4, 3: 3, 2: 2, 1: 1, 0: 0, 'default': 10}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_61", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_sshd_set_login_grace_time", + "value": "var_sshd_set_keepalive", "remarks": "rule_set_000" }, { "name": "Parameter_Description_61", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure parameters for how long the servers stays connected before the user has successfully logged in", + "value": "Specify the maximum number of idle message counts before session is terminated.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_61", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 60, 60: 60}", + "value": "{10: 10, 3: 3, 5: 5, 0: 0, 1: 1, 'default': 0}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_62", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_sshd_set_maxstartups", + "value": "var_sshd_set_login_grace_time", "remarks": "rule_set_000" }, { "name": "Parameter_Description_62", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure parameters for maximum concurrent unauthenticated connections to the SSH daemon.", + "value": "Configure parameters for how long the servers stays connected before the user has successfully logged in", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_62", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': '10:30:100', '10:30:60': '10:30:60'}", + "value": "{'default': 60, 60: 60}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_63", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_system_crypto_policy", + "value": "var_sshd_set_maxstartups", "remarks": "rule_set_000" }, { "name": "Parameter_Description_63", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Specify the crypto policy for the system.", + "value": "Configure parameters for maximum concurrent unauthenticated connections to the SSH daemon.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_63", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': '10:30:100', '10:30:60': '10:30:60'}", "remarks": "rule_set_000" }, { "name": "Parameter_Id_64", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "var_user_initialization_files_regex", + "value": "var_system_crypto_policy", "remarks": "rule_set_000" }, { "name": "Parameter_Description_64", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "'A regular expression describing a list of file names for files that are sourced at login time for interactive users'", + "value": "Specify the crypto policy for the system.", "remarks": "rule_set_000" }, { "name": "Parameter_Value_Alternatives_64", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Id_65", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "var_user_initialization_files_regex", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Description_65", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "'A regular expression describing a list of file names for files that are sourced at login time for interactive users'", + "remarks": "rule_set_000" + }, + { + "name": "Parameter_Value_Alternatives_65", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "{'default': '^(\\\\.bashrc|\\\\.zshrc|\\\\.cshrc|\\\\.profile|\\\\.bash_login|\\\\.bash_profile)$', 'all_dotfiles': '^\\\\.[\\\\w\\\\- ]+$'}", "remarks": "rule_set_000" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_tmp", + "value": "kernel_module_cramfs_disabled", "remarks": "rule_set_001" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /tmp Located On Separate Partition", + "value": "Disable Mounting of cramfs", "remarks": "rule_set_001" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_tmp", + "value": "kernel_module_cramfs_disabled", "remarks": "rule_set_001" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /tmp Located On Separate Partition", + "value": "Disable Mounting of cramfs", "remarks": "rule_set_001" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_nodev", + "value": "kernel_module_freevxfs_disabled", "remarks": "rule_set_002" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /tmp", + "value": "Disable Mounting of freevxfs", "remarks": "rule_set_002" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_nodev", + "value": "kernel_module_freevxfs_disabled", "remarks": "rule_set_002" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /tmp", + "value": "Disable Mounting of freevxfs", "remarks": "rule_set_002" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_nosuid", + "value": "kernel_module_hfs_disabled", "remarks": "rule_set_003" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /tmp", + "value": "Disable Mounting of hfs", "remarks": "rule_set_003" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_nosuid", + "value": "kernel_module_hfs_disabled", "remarks": "rule_set_003" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /tmp", + "value": "Disable Mounting of hfs", "remarks": "rule_set_003" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_noexec", + "value": "kernel_module_hfsplus_disabled", "remarks": "rule_set_004" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /tmp", + "value": "Disable Mounting of hfsplus", "remarks": "rule_set_004" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_noexec", + "value": "kernel_module_hfsplus_disabled", "remarks": "rule_set_004" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /tmp", + "value": "Disable Mounting of hfsplus", "remarks": "rule_set_004" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_dev_shm", + "value": "kernel_module_jffs2_disabled", "remarks": "rule_set_005" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /dev/shm is configured", + "value": "Disable Mounting of jffs2", "remarks": "rule_set_005" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_dev_shm", + "value": "kernel_module_jffs2_disabled", "remarks": "rule_set_005" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /dev/shm is configured", + "value": "Disable Mounting of jffs2", "remarks": "rule_set_005" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_nodev", + "value": "partition_for_tmp", "remarks": "rule_set_006" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /dev/shm", + "value": "Ensure /tmp Located On Separate Partition", "remarks": "rule_set_006" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_nodev", + "value": "partition_for_tmp", "remarks": "rule_set_006" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /dev/shm", + "value": "Ensure /tmp Located On Separate Partition", "remarks": "rule_set_006" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_nosuid", + "value": "mount_option_tmp_nodev", "remarks": "rule_set_007" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /dev/shm", + "value": "Add nodev Option to /tmp", "remarks": "rule_set_007" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_nosuid", + "value": "mount_option_tmp_nodev", "remarks": "rule_set_007" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /dev/shm", + "value": "Add nodev Option to /tmp", "remarks": "rule_set_007" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_noexec", + "value": "mount_option_tmp_nosuid", "remarks": "rule_set_008" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /dev/shm", + "value": "Add nosuid Option to /tmp", "remarks": "rule_set_008" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_noexec", + "value": "mount_option_tmp_nosuid", "remarks": "rule_set_008" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /dev/shm", + "value": "Add nosuid Option to /tmp", "remarks": "rule_set_008" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_home_nodev", + "value": "mount_option_tmp_noexec", "remarks": "rule_set_009" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /home", + "value": "Add noexec Option to /tmp", "remarks": "rule_set_009" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_home_nodev", + "value": "mount_option_tmp_noexec", "remarks": "rule_set_009" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /home", + "value": "Add noexec Option to /tmp", "remarks": "rule_set_009" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_home_nosuid", + "value": "partition_for_dev_shm", "remarks": "rule_set_010" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /home", + "value": "Ensure /dev/shm is configured", "remarks": "rule_set_010" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_home_nosuid", + "value": "partition_for_dev_shm", "remarks": "rule_set_010" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /home", + "value": "Ensure /dev/shm is configured", "remarks": "rule_set_010" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_nodev", + "value": "mount_option_dev_shm_nodev", "remarks": "rule_set_011" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /var", + "value": "Add nodev Option to /dev/shm", "remarks": "rule_set_011" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_nodev", + "value": "mount_option_dev_shm_nodev", "remarks": "rule_set_011" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /var", + "value": "Add nodev Option to /dev/shm", "remarks": "rule_set_011" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_nosuid", + "value": "mount_option_dev_shm_nosuid", "remarks": "rule_set_012" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /var", + "value": "Add nosuid Option to /dev/shm", "remarks": "rule_set_012" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_nosuid", + "value": "mount_option_dev_shm_nosuid", "remarks": "rule_set_012" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /var", + "value": "Add nosuid Option to /dev/shm", "remarks": "rule_set_012" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_tmp_nodev", + "value": "mount_option_dev_shm_noexec", "remarks": "rule_set_013" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /var/tmp", + "value": "Add noexec Option to /dev/shm", "remarks": "rule_set_013" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_tmp_nodev", + "value": "mount_option_dev_shm_noexec", "remarks": "rule_set_013" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /var/tmp", + "value": "Add noexec Option to /dev/shm", "remarks": "rule_set_013" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_tmp_nosuid", + "value": "mount_option_home_nodev", "remarks": "rule_set_014" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /var/tmp", + "value": "Add nodev Option to /home", "remarks": "rule_set_014" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_tmp_nosuid", + "value": "mount_option_home_nodev", "remarks": "rule_set_014" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /var/tmp", + "value": "Add nodev Option to /home", "remarks": "rule_set_014" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_tmp_noexec", + "value": "mount_option_home_nosuid", "remarks": "rule_set_015" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /var/tmp", + "value": "Add nosuid Option to /home", "remarks": "rule_set_015" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_tmp_noexec", + "value": "mount_option_home_nosuid", "remarks": "rule_set_015" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /var/tmp", + "value": "Add nosuid Option to /home", "remarks": "rule_set_015" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_nodev", + "value": "mount_option_var_nodev", "remarks": "rule_set_016" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /var/log", + "value": "Add nodev Option to /var", "remarks": "rule_set_016" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_nodev", + "value": "mount_option_var_nodev", "remarks": "rule_set_016" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /var/log", + "value": "Add nodev Option to /var", "remarks": "rule_set_016" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_nosuid", + "value": "mount_option_var_nosuid", "remarks": "rule_set_017" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /var/log", + "value": "Add nosuid Option to /var", "remarks": "rule_set_017" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_nosuid", + "value": "mount_option_var_nosuid", "remarks": "rule_set_017" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /var/log", + "value": "Add nosuid Option to /var", "remarks": "rule_set_017" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_noexec", + "value": "mount_option_var_tmp_nodev", "remarks": "rule_set_018" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /var/log", + "value": "Add nodev Option to /var/tmp", "remarks": "rule_set_018" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_noexec", + "value": "mount_option_var_tmp_nodev", "remarks": "rule_set_018" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /var/log", + "value": "Add nodev Option to /var/tmp", "remarks": "rule_set_018" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_audit_nodev", + "value": "mount_option_var_tmp_nosuid", "remarks": "rule_set_019" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /var/log/audit", + "value": "Add nosuid Option to /var/tmp", "remarks": "rule_set_019" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_audit_nodev", + "value": "mount_option_var_tmp_nosuid", "remarks": "rule_set_019" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nodev Option to /var/log/audit", + "value": "Add nosuid Option to /var/tmp", "remarks": "rule_set_019" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_audit_nosuid", + "value": "mount_option_var_tmp_noexec", "remarks": "rule_set_020" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /var/log/audit", + "value": "Add noexec Option to /var/tmp", "remarks": "rule_set_020" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_audit_nosuid", + "value": "mount_option_var_tmp_noexec", "remarks": "rule_set_020" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add nosuid Option to /var/log/audit", + "value": "Add noexec Option to /var/tmp", "remarks": "rule_set_020" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_audit_noexec", + "value": "mount_option_var_log_nodev", "remarks": "rule_set_021" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /var/log/audit", + "value": "Add nodev Option to /var/log", "remarks": "rule_set_021" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_audit_noexec", + "value": "mount_option_var_log_nodev", "remarks": "rule_set_021" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Add noexec Option to /var/log/audit", + "value": "Add nodev Option to /var/log", "remarks": "rule_set_021" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_gpgcheck_globally_activated", + "value": "mount_option_var_log_nosuid", "remarks": "rule_set_022" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure gpgcheck Enabled In Main dnf Configuration", + "value": "Add nosuid Option to /var/log", "remarks": "rule_set_022" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_gpgcheck_globally_activated", + "value": "mount_option_var_log_nosuid", "remarks": "rule_set_022" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure gpgcheck Enabled In Main dnf Configuration", + "value": "Add nosuid Option to /var/log", "remarks": "rule_set_022" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_libselinux_installed", + "value": "mount_option_var_log_noexec", "remarks": "rule_set_023" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install libselinux Package", + "value": "Add noexec Option to /var/log", "remarks": "rule_set_023" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_libselinux_installed", + "value": "mount_option_var_log_noexec", "remarks": "rule_set_023" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install libselinux Package", + "value": "Add noexec Option to /var/log", "remarks": "rule_set_023" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "grub2_enable_selinux", + "value": "mount_option_var_log_audit_nodev", "remarks": "rule_set_024" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure SELinux Not Disabled in /etc/default/grub", + "value": "Add nodev Option to /var/log/audit", "remarks": "rule_set_024" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "grub2_enable_selinux", + "value": "mount_option_var_log_audit_nodev", "remarks": "rule_set_024" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure SELinux Not Disabled in /etc/default/grub", + "value": "Add nodev Option to /var/log/audit", "remarks": "rule_set_024" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "selinux_policytype", + "value": "mount_option_var_log_audit_nosuid", "remarks": "rule_set_025" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure SELinux Policy", + "value": "Add nosuid Option to /var/log/audit", "remarks": "rule_set_025" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "selinux_policytype", + "value": "mount_option_var_log_audit_nosuid", "remarks": "rule_set_025" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure SELinux Policy", + "value": "Add nosuid Option to /var/log/audit", "remarks": "rule_set_025" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "selinux_not_disabled", + "value": "mount_option_var_log_audit_noexec", "remarks": "rule_set_026" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure SELinux is Not Disabled", + "value": "Add noexec Option to /var/log/audit", "remarks": "rule_set_026" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "selinux_not_disabled", + "value": "mount_option_var_log_audit_noexec", "remarks": "rule_set_026" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure SELinux is Not Disabled", + "value": "Add noexec Option to /var/log/audit", "remarks": "rule_set_026" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_mcstrans_removed", + "value": "ensure_gpgcheck_globally_activated", "remarks": "rule_set_027" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall mcstrans Package", + "value": "Ensure gpgcheck Enabled In Main dnf Configuration", "remarks": "rule_set_027" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_mcstrans_removed", + "value": "ensure_gpgcheck_globally_activated", "remarks": "rule_set_027" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall mcstrans Package", + "value": "Ensure gpgcheck Enabled In Main dnf Configuration", "remarks": "rule_set_027" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "grub2_password", + "value": "package_libselinux_installed", "remarks": "rule_set_028" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Boot Loader Password in grub2", + "value": "Install libselinux Package", "remarks": "rule_set_028" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "grub2_password", + "value": "package_libselinux_installed", "remarks": "rule_set_028" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Boot Loader Password in grub2", + "value": "Install libselinux Package", "remarks": "rule_set_028" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_grub2_cfg", + "value": "grub2_enable_selinux", "remarks": "rule_set_029" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/grub.cfg Group Ownership", + "value": "Ensure SELinux Not Disabled in /etc/default/grub", "remarks": "rule_set_029" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_grub2_cfg", + "value": "grub2_enable_selinux", "remarks": "rule_set_029" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/grub.cfg Group Ownership", + "value": "Ensure SELinux Not Disabled in /etc/default/grub", "remarks": "rule_set_029" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_grub2_cfg", + "value": "selinux_policytype", "remarks": "rule_set_030" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/grub.cfg User Ownership", + "value": "Configure SELinux Policy", "remarks": "rule_set_030" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_grub2_cfg", + "value": "selinux_policytype", "remarks": "rule_set_030" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/grub.cfg User Ownership", + "value": "Configure SELinux Policy", "remarks": "rule_set_030" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_grub2_cfg", + "value": "selinux_not_disabled", "remarks": "rule_set_031" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/grub.cfg Permissions", + "value": "Ensure SELinux is Not Disabled", "remarks": "rule_set_031" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_grub2_cfg", + "value": "selinux_not_disabled", "remarks": "rule_set_031" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/grub.cfg Permissions", + "value": "Ensure SELinux is Not Disabled", "remarks": "rule_set_031" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_user_cfg", + "value": "package_mcstrans_removed", "remarks": "rule_set_032" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/user.cfg Group Ownership", + "value": "Uninstall mcstrans Package", "remarks": "rule_set_032" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_user_cfg", + "value": "package_mcstrans_removed", "remarks": "rule_set_032" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/user.cfg Group Ownership", + "value": "Uninstall mcstrans Package", "remarks": "rule_set_032" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_user_cfg", + "value": "grub2_password", "remarks": "rule_set_033" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/user.cfg User Ownership", + "value": "Set Boot Loader Password in grub2", "remarks": "rule_set_033" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_user_cfg", + "value": "grub2_password", "remarks": "rule_set_033" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/user.cfg User Ownership", + "value": "Set Boot Loader Password in grub2", "remarks": "rule_set_033" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_user_cfg", + "value": "file_groupowner_grub2_cfg", "remarks": "rule_set_034" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/user.cfg Permissions", + "value": "Verify /boot/grub2/grub.cfg Group Ownership", "remarks": "rule_set_034" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_user_cfg", + "value": "file_groupowner_grub2_cfg", "remarks": "rule_set_034" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify /boot/grub2/user.cfg Permissions", + "value": "Verify /boot/grub2/grub.cfg Group Ownership", "remarks": "rule_set_034" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_kernel_randomize_va_space", + "value": "file_owner_grub2_cfg", "remarks": "rule_set_035" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Randomized Layout of Virtual Address Space", + "value": "Verify /boot/grub2/grub.cfg User Ownership", "remarks": "rule_set_035" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_kernel_randomize_va_space", + "value": "file_owner_grub2_cfg", "remarks": "rule_set_035" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Randomized Layout of Virtual Address Space", + "value": "Verify /boot/grub2/grub.cfg User Ownership", "remarks": "rule_set_035" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_kernel_yama_ptrace_scope", + "value": "file_permissions_grub2_cfg", "remarks": "rule_set_036" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Restrict usage of ptrace to descendant processes", + "value": "Verify /boot/grub2/grub.cfg Permissions", "remarks": "rule_set_036" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_kernel_yama_ptrace_scope", + "value": "file_permissions_grub2_cfg", "remarks": "rule_set_036" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Restrict usage of ptrace to descendant processes", + "value": "Verify /boot/grub2/grub.cfg Permissions", "remarks": "rule_set_036" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_backtraces", + "value": "file_groupowner_user_cfg", "remarks": "rule_set_037" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable core dump backtraces", + "value": "Verify /boot/grub2/user.cfg Group Ownership", "remarks": "rule_set_037" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_backtraces", + "value": "file_groupowner_user_cfg", "remarks": "rule_set_037" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable core dump backtraces", + "value": "Verify /boot/grub2/user.cfg Group Ownership", "remarks": "rule_set_037" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_storage", + "value": "file_owner_user_cfg", "remarks": "rule_set_038" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable storing core dump", + "value": "Verify /boot/grub2/user.cfg User Ownership", "remarks": "rule_set_038" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_storage", + "value": "file_owner_user_cfg", "remarks": "rule_set_038" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable storing core dump", + "value": "Verify /boot/grub2/user.cfg User Ownership", "remarks": "rule_set_038" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_crypto_policy", + "value": "file_permissions_user_cfg", "remarks": "rule_set_039" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure System Cryptography Policy", + "value": "Verify /boot/grub2/user.cfg Permissions", "remarks": "rule_set_039" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_crypto_policy", + "value": "file_permissions_user_cfg", "remarks": "rule_set_039" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure System Cryptography Policy", + "value": "Verify /boot/grub2/user.cfg Permissions", "remarks": "rule_set_039" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_ssh_crypto_policy", + "value": "disable_users_coredumps", "remarks": "rule_set_040" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure SSH to use System Crypto Policy", + "value": "Disable Core Dumps for All Users", "remarks": "rule_set_040" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_ssh_crypto_policy", + "value": "disable_users_coredumps", "remarks": "rule_set_040" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure SSH to use System Crypto Policy", + "value": "Disable Core Dumps for All Users", "remarks": "rule_set_040" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "banner_etc_motd_cis", + "value": "sysctl_fs_protected_hardlinks", "remarks": "rule_set_041" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Message Of The Day Is Configured Properly", + "value": "Enable Kernel Parameter to Enforce DAC on Hardlinks", "remarks": "rule_set_041" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "banner_etc_motd_cis", + "value": "sysctl_fs_protected_hardlinks", "remarks": "rule_set_041" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Message Of The Day Is Configured Properly", + "value": "Enable Kernel Parameter to Enforce DAC on Hardlinks", "remarks": "rule_set_041" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "banner_etc_issue_cis", + "value": "sysctl_fs_suid_dumpable", "remarks": "rule_set_042" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Local Login Warning Banner Is Configured Properly", + "value": "Disable Core Dumps for SUID programs", "remarks": "rule_set_042" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "banner_etc_issue_cis", + "value": "sysctl_fs_suid_dumpable", "remarks": "rule_set_042" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Local Login Warning Banner Is Configured Properly", + "value": "Disable Core Dumps for SUID programs", "remarks": "rule_set_042" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "banner_etc_issue_net_cis", + "value": "sysctl_kernel_dmesg_restrict", "remarks": "rule_set_043" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Remote Login Warning Banner Is Configured Properly", + "value": "Restrict Access to Kernel Message Buffer", "remarks": "rule_set_043" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "banner_etc_issue_net_cis", + "value": "sysctl_kernel_dmesg_restrict", "remarks": "rule_set_043" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Remote Login Warning Banner Is Configured Properly", + "value": "Restrict Access to Kernel Message Buffer", "remarks": "rule_set_043" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_motd", + "value": "sysctl_kernel_kptr_restrict", "remarks": "rule_set_044" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Ownership of Message of the Day Banner", + "value": "Restrict Exposed Kernel Pointer Addresses Access", "remarks": "rule_set_044" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_motd", + "value": "sysctl_kernel_kptr_restrict", "remarks": "rule_set_044" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Ownership of Message of the Day Banner", + "value": "Restrict Exposed Kernel Pointer Addresses Access", "remarks": "rule_set_044" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_motd", + "value": "sysctl_kernel_yama_ptrace_scope", "remarks": "rule_set_045" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify ownership of Message of the Day Banner", + "value": "Restrict usage of ptrace to descendant processes", "remarks": "rule_set_045" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_motd", + "value": "sysctl_kernel_yama_ptrace_scope", "remarks": "rule_set_045" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify ownership of Message of the Day Banner", + "value": "Restrict usage of ptrace to descendant processes", "remarks": "rule_set_045" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_motd", + "value": "sysctl_kernel_randomize_va_space", "remarks": "rule_set_046" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify permissions on Message of the Day Banner", + "value": "Enable Randomized Layout of Virtual Address Space", "remarks": "rule_set_046" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_motd", + "value": "sysctl_kernel_randomize_va_space", "remarks": "rule_set_046" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify permissions on Message of the Day Banner", + "value": "Enable Randomized Layout of Virtual Address Space", "remarks": "rule_set_046" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_issue", + "value": "coredump_disable_backtraces", "remarks": "rule_set_047" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Ownership of System Login Banner", + "value": "Disable core dump backtraces", "remarks": "rule_set_047" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_issue", + "value": "coredump_disable_backtraces", "remarks": "rule_set_047" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Ownership of System Login Banner", + "value": "Disable core dump backtraces", "remarks": "rule_set_047" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_issue", + "value": "coredump_disable_storage", "remarks": "rule_set_048" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify ownership of System Login Banner", + "value": "Disable storing core dump", "remarks": "rule_set_048" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_issue", + "value": "coredump_disable_storage", "remarks": "rule_set_048" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify ownership of System Login Banner", + "value": "Disable storing core dump", "remarks": "rule_set_048" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_issue", + "value": "configure_crypto_policy", "remarks": "rule_set_049" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify permissions on System Login Banner", + "value": "Configure System Cryptography Policy", "remarks": "rule_set_049" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_issue", + "value": "configure_crypto_policy", "remarks": "rule_set_049" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify permissions on System Login Banner", + "value": "Configure System Cryptography Policy", "remarks": "rule_set_049" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_issue_net", + "value": "banner_etc_motd_cis", "remarks": "rule_set_050" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Ownership of System Login Banner for Remote Connections", + "value": "Ensure Message Of The Day Is Configured Properly", "remarks": "rule_set_050" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_issue_net", + "value": "banner_etc_motd_cis", "remarks": "rule_set_050" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Ownership of System Login Banner for Remote Connections", + "value": "Ensure Message Of The Day Is Configured Properly", "remarks": "rule_set_050" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_issue_net", + "value": "banner_etc_issue_cis", "remarks": "rule_set_051" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify ownership of System Login Banner for Remote Connections", + "value": "Ensure Local Login Warning Banner Is Configured Properly", "remarks": "rule_set_051" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_issue_net", + "value": "banner_etc_issue_cis", "remarks": "rule_set_051" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify ownership of System Login Banner for Remote Connections", + "value": "Ensure Local Login Warning Banner Is Configured Properly", "remarks": "rule_set_051" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_issue_net", + "value": "banner_etc_issue_net_cis", "remarks": "rule_set_052" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify permissions on System Login Banner for Remote Connections", + "value": "Ensure Remote Login Warning Banner Is Configured Properly", "remarks": "rule_set_052" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_issue_net", + "value": "banner_etc_issue_net_cis", "remarks": "rule_set_052" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify permissions on System Login Banner for Remote Connections", + "value": "Ensure Remote Login Warning Banner Is Configured Properly", "remarks": "rule_set_052" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_banner_enabled", + "value": "file_groupowner_etc_motd", "remarks": "rule_set_053" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable GNOME3 Login Warning Banner", + "value": "Verify Group Ownership of Message of the Day Banner", "remarks": "rule_set_053" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_banner_enabled", + "value": "file_groupowner_etc_motd", "remarks": "rule_set_053" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable GNOME3 Login Warning Banner", + "value": "Verify Group Ownership of Message of the Day Banner", "remarks": "rule_set_053" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_login_banner_text", + "value": "file_owner_etc_motd", "remarks": "rule_set_054" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set the GNOME3 Login Warning Banner Text", + "value": "Verify ownership of Message of the Day Banner", "remarks": "rule_set_054" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_login_banner_text", + "value": "file_owner_etc_motd", "remarks": "rule_set_054" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set the GNOME3 Login Warning Banner Text", + "value": "Verify ownership of Message of the Day Banner", "remarks": "rule_set_054" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_user_list", + "value": "file_permissions_etc_motd", "remarks": "rule_set_055" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable the GNOME3 Login User List", + "value": "Verify permissions on Message of the Day Banner", "remarks": "rule_set_055" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_user_list", + "value": "file_permissions_etc_motd", "remarks": "rule_set_055" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable the GNOME3 Login User List", + "value": "Verify permissions on Message of the Day Banner", "remarks": "rule_set_055" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_screensaver_idle_delay", + "value": "file_groupowner_etc_issue", "remarks": "rule_set_056" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set GNOME3 Screensaver Inactivity Timeout", + "value": "Verify Group Ownership of System Login Banner", "remarks": "rule_set_056" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_screensaver_idle_delay", + "value": "file_groupowner_etc_issue", "remarks": "rule_set_056" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set GNOME3 Screensaver Inactivity Timeout", + "value": "Verify Group Ownership of System Login Banner", "remarks": "rule_set_056" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_screensaver_lock_delay", + "value": "file_owner_etc_issue", "remarks": "rule_set_057" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set GNOME3 Screensaver Lock Delay After Activation Period", + "value": "Verify ownership of System Login Banner", "remarks": "rule_set_057" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_screensaver_lock_delay", + "value": "file_owner_etc_issue", "remarks": "rule_set_057" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set GNOME3 Screensaver Lock Delay After Activation Period", + "value": "Verify ownership of System Login Banner", "remarks": "rule_set_057" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_session_idle_user_locks", + "value": "file_permissions_etc_issue", "remarks": "rule_set_058" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Users Cannot Change GNOME3 Session Idle Settings", + "value": "Verify permissions on System Login Banner", "remarks": "rule_set_058" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_session_idle_user_locks", + "value": "file_permissions_etc_issue", "remarks": "rule_set_058" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Users Cannot Change GNOME3 Session Idle Settings", + "value": "Verify permissions on System Login Banner", "remarks": "rule_set_058" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_screensaver_user_locks", + "value": "file_groupowner_etc_issue_net", "remarks": "rule_set_059" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Users Cannot Change GNOME3 Screensaver Settings", + "value": "Verify Group Ownership of System Login Banner for Remote Connections", "remarks": "rule_set_059" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_screensaver_user_locks", + "value": "file_groupowner_etc_issue_net", "remarks": "rule_set_059" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Users Cannot Change GNOME3 Screensaver Settings", + "value": "Verify Group Ownership of System Login Banner for Remote Connections", "remarks": "rule_set_059" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_autorun", + "value": "file_owner_etc_issue_net", "remarks": "rule_set_060" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable GNOME3 Automount running", + "value": "Verify ownership of System Login Banner for Remote Connections", "remarks": "rule_set_060" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_autorun", + "value": "file_owner_etc_issue_net", "remarks": "rule_set_060" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable GNOME3 Automount running", + "value": "Verify ownership of System Login Banner for Remote Connections", "remarks": "rule_set_060" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_kea_removed", + "value": "file_permissions_etc_issue_net", "remarks": "rule_set_061" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall kea Package", + "value": "Verify permissions on System Login Banner for Remote Connections", "remarks": "rule_set_061" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_kea_removed", + "value": "file_permissions_etc_issue_net", "remarks": "rule_set_061" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall kea Package", + "value": "Verify permissions on System Login Banner for Remote Connections", "remarks": "rule_set_061" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_bind_removed", + "value": "dconf_gnome_banner_enabled", "remarks": "rule_set_062" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall bind Package", + "value": "Enable GNOME3 Login Warning Banner", "remarks": "rule_set_062" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_bind_removed", + "value": "dconf_gnome_banner_enabled", "remarks": "rule_set_062" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall bind Package", + "value": "Enable GNOME3 Login Warning Banner", "remarks": "rule_set_062" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_dnsmasq_removed", + "value": "dconf_gnome_login_banner_text", "remarks": "rule_set_063" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall dnsmasq Package", + "value": "Set the GNOME3 Login Warning Banner Text", "remarks": "rule_set_063" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_dnsmasq_removed", + "value": "dconf_gnome_login_banner_text", "remarks": "rule_set_063" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall dnsmasq Package", + "value": "Set the GNOME3 Login Warning Banner Text", "remarks": "rule_set_063" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_samba_removed", + "value": "dconf_gnome_disable_user_list", "remarks": "rule_set_064" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall Samba Package", + "value": "Disable the GNOME3 Login User List", "remarks": "rule_set_064" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_samba_removed", + "value": "dconf_gnome_disable_user_list", "remarks": "rule_set_064" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall Samba Package", + "value": "Disable the GNOME3 Login User List", "remarks": "rule_set_064" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_vsftpd_removed", + "value": "dconf_gnome_screensaver_idle_delay", "remarks": "rule_set_065" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall vsftpd Package", + "value": "Set GNOME3 Screensaver Inactivity Timeout", "remarks": "rule_set_065" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_vsftpd_removed", + "value": "dconf_gnome_screensaver_idle_delay", "remarks": "rule_set_065" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall vsftpd Package", + "value": "Set GNOME3 Screensaver Inactivity Timeout", "remarks": "rule_set_065" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_dovecot_removed", + "value": "dconf_gnome_screensaver_lock_delay", "remarks": "rule_set_066" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall dovecot Package", + "value": "Set GNOME3 Screensaver Lock Delay After Activation Period", "remarks": "rule_set_066" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_dovecot_removed", + "value": "dconf_gnome_screensaver_lock_delay", "remarks": "rule_set_066" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall dovecot Package", + "value": "Set GNOME3 Screensaver Lock Delay After Activation Period", "remarks": "rule_set_066" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_cyrus-imapd_removed", + "value": "dconf_gnome_session_idle_user_locks", "remarks": "rule_set_067" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall cyrus-imapd Package", + "value": "Ensure Users Cannot Change GNOME3 Session Idle Settings", "remarks": "rule_set_067" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_cyrus-imapd_removed", + "value": "dconf_gnome_session_idle_user_locks", "remarks": "rule_set_067" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall cyrus-imapd Package", + "value": "Ensure Users Cannot Change GNOME3 Session Idle Settings", "remarks": "rule_set_067" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_nfs_disabled", + "value": "dconf_gnome_screensaver_user_locks", "remarks": "rule_set_068" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Network File System (nfs)", + "value": "Ensure Users Cannot Change GNOME3 Screensaver Settings", "remarks": "rule_set_068" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_nfs_disabled", + "value": "dconf_gnome_screensaver_user_locks", "remarks": "rule_set_068" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Network File System (nfs)", + "value": "Ensure Users Cannot Change GNOME3 Screensaver Settings", "remarks": "rule_set_068" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_rpcbind_disabled", + "value": "dconf_gnome_disable_autorun", "remarks": "rule_set_069" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable rpcbind Service", + "value": "Disable GNOME3 Automount running", "remarks": "rule_set_069" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_rpcbind_disabled", + "value": "dconf_gnome_disable_autorun", "remarks": "rule_set_069" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable rpcbind Service", + "value": "Disable GNOME3 Automount running", "remarks": "rule_set_069" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_rsync_removed", + "value": "package_kea_removed", "remarks": "rule_set_070" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall rsync Package", + "value": "Uninstall kea Package", "remarks": "rule_set_070" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_rsync_removed", + "value": "package_kea_removed", "remarks": "rule_set_070" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall rsync Package", + "value": "Uninstall kea Package", "remarks": "rule_set_070" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_net-snmp_removed", + "value": "package_bind_removed", "remarks": "rule_set_071" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall net-snmp Package", + "value": "Uninstall bind Package", "remarks": "rule_set_071" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_net-snmp_removed", + "value": "package_bind_removed", "remarks": "rule_set_071" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall net-snmp Package", + "value": "Uninstall bind Package", "remarks": "rule_set_071" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_telnet-server_removed", + "value": "package_dnsmasq_removed", "remarks": "rule_set_072" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall telnet-server Package", + "value": "Uninstall dnsmasq Package", "remarks": "rule_set_072" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_telnet-server_removed", + "value": "package_dnsmasq_removed", "remarks": "rule_set_072" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall telnet-server Package", + "value": "Uninstall dnsmasq Package", "remarks": "rule_set_072" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_tftp-server_removed", + "value": "package_vsftpd_removed", "remarks": "rule_set_073" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall tftp-server Package", + "value": "Uninstall vsftpd Package", "remarks": "rule_set_073" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_tftp-server_removed", + "value": "package_vsftpd_removed", "remarks": "rule_set_073" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall tftp-server Package", + "value": "Uninstall vsftpd Package", "remarks": "rule_set_073" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_squid_removed", + "value": "package_dovecot_removed", "remarks": "rule_set_074" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall squid Package", + "value": "Uninstall dovecot Package", "remarks": "rule_set_074" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_squid_removed", + "value": "package_dovecot_removed", "remarks": "rule_set_074" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall squid Package", + "value": "Uninstall dovecot Package", "remarks": "rule_set_074" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_httpd_removed", + "value": "package_cyrus-imapd_removed", "remarks": "rule_set_075" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall httpd Package", + "value": "Uninstall cyrus-imapd Package", "remarks": "rule_set_075" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_httpd_removed", + "value": "package_cyrus-imapd_removed", "remarks": "rule_set_075" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall httpd Package", + "value": "Uninstall cyrus-imapd Package", "remarks": "rule_set_075" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_nginx_removed", + "value": "service_nfs_disabled", "remarks": "rule_set_076" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall nginx Package", + "value": "Disable Network File System (nfs)", "remarks": "rule_set_076" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_nginx_removed", + "value": "service_nfs_disabled", "remarks": "rule_set_076" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Uninstall nginx Package", + "value": "Disable Network File System (nfs)", "remarks": "rule_set_076" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "postfix_network_listening_disabled", + "value": "service_rpcbind_disabled", "remarks": "rule_set_077" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Postfix Network Listening", + "value": "Disable rpcbind Service", "remarks": "rule_set_077" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "postfix_network_listening_disabled", + "value": "service_rpcbind_disabled", "remarks": "rule_set_077" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Postfix Network Listening", + "value": "Disable rpcbind Service", "remarks": "rule_set_077" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "has_nonlocal_mta", + "value": "package_rsync_removed", "remarks": "rule_set_078" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Mail Transfer Agent is not Listening on any non-loopback Address", + "value": "Uninstall rsync Package", "remarks": "rule_set_078" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "has_nonlocal_mta", + "value": "package_rsync_removed", "remarks": "rule_set_078" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Mail Transfer Agent is not Listening on any non-loopback Address", + "value": "Uninstall rsync Package", "remarks": "rule_set_078" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_ftp_removed", + "value": "package_samba_removed", "remarks": "rule_set_079" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Remove ftp Package", + "value": "Uninstall Samba Package", "remarks": "rule_set_079" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_ftp_removed", + "value": "package_samba_removed", "remarks": "rule_set_079" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Remove ftp Package", + "value": "Uninstall Samba Package", "remarks": "rule_set_079" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_telnet_removed", + "value": "package_net-snmp_removed", "remarks": "rule_set_080" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Remove telnet Clients", + "value": "Uninstall net-snmp Package", "remarks": "rule_set_080" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_telnet_removed", + "value": "package_net-snmp_removed", "remarks": "rule_set_080" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Remove telnet Clients", + "value": "Uninstall net-snmp Package", "remarks": "rule_set_080" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_tftp_removed", + "value": "package_telnet-server_removed", "remarks": "rule_set_081" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Remove tftp Daemon", + "value": "Uninstall telnet-server Package", "remarks": "rule_set_081" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_tftp_removed", + "value": "package_telnet-server_removed", "remarks": "rule_set_081" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Remove tftp Daemon", + "value": "Uninstall telnet-server Package", "remarks": "rule_set_081" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "chronyd_specify_remote_server", + "value": "package_tftp-server_removed", "remarks": "rule_set_082" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "A remote time server for Chrony is configured", + "value": "Uninstall tftp-server Package", "remarks": "rule_set_082" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "chronyd_specify_remote_server", + "value": "package_tftp-server_removed", "remarks": "rule_set_082" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "A remote time server for Chrony is configured", + "value": "Uninstall tftp-server Package", "remarks": "rule_set_082" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "chronyd_run_as_chrony_user", + "value": "package_squid_removed", "remarks": "rule_set_083" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that chronyd is running under chrony user account", + "value": "Uninstall squid Package", "remarks": "rule_set_083" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "chronyd_run_as_chrony_user", + "value": "package_squid_removed", "remarks": "rule_set_083" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that chronyd is running under chrony user account", + "value": "Uninstall squid Package", "remarks": "rule_set_083" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_cron_installed", + "value": "package_httpd_removed", "remarks": "rule_set_084" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install the cron service", + "value": "Uninstall httpd Package", "remarks": "rule_set_084" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_cron_installed", + "value": "package_httpd_removed", "remarks": "rule_set_084" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install the cron service", + "value": "Uninstall httpd Package", "remarks": "rule_set_084" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_crond_enabled", + "value": "package_nginx_removed", "remarks": "rule_set_085" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable cron Service", + "value": "Uninstall nginx Package", "remarks": "rule_set_085" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_crond_enabled", + "value": "package_nginx_removed", "remarks": "rule_set_085" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable cron Service", + "value": "Uninstall nginx Package", "remarks": "rule_set_085" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_crontab", + "value": "postfix_network_listening_disabled", "remarks": "rule_set_086" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns Crontab", + "value": "Disable Postfix Network Listening", "remarks": "rule_set_086" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_crontab", + "value": "postfix_network_listening_disabled", "remarks": "rule_set_086" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns Crontab", + "value": "Disable Postfix Network Listening", "remarks": "rule_set_086" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_crontab", + "value": "has_nonlocal_mta", "remarks": "rule_set_087" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on crontab", + "value": "Ensure Mail Transfer Agent is not Listening on any non-loopback Address", "remarks": "rule_set_087" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_crontab", + "value": "has_nonlocal_mta", "remarks": "rule_set_087" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on crontab", + "value": "Ensure Mail Transfer Agent is not Listening on any non-loopback Address", "remarks": "rule_set_087" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_crontab", + "value": "package_ftp_removed", "remarks": "rule_set_088" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on crontab", + "value": "Remove ftp Package", "remarks": "rule_set_088" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_crontab", + "value": "package_ftp_removed", "remarks": "rule_set_088" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on crontab", + "value": "Remove ftp Package", "remarks": "rule_set_088" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_hourly", + "value": "package_telnet_removed", "remarks": "rule_set_089" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns cron.hourly", + "value": "Remove telnet Clients", "remarks": "rule_set_089" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_hourly", + "value": "package_telnet_removed", "remarks": "rule_set_089" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns cron.hourly", + "value": "Remove telnet Clients", "remarks": "rule_set_089" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_hourly", + "value": "package_tftp_removed", "remarks": "rule_set_090" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on cron.hourly", + "value": "Remove tftp Daemon", "remarks": "rule_set_090" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_hourly", + "value": "package_tftp_removed", "remarks": "rule_set_090" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on cron.hourly", + "value": "Remove tftp Daemon", "remarks": "rule_set_090" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_hourly", + "value": "chronyd_specify_remote_server", "remarks": "rule_set_091" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on cron.hourly", + "value": "A remote time server for Chrony is configured", "remarks": "rule_set_091" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_hourly", + "value": "chronyd_specify_remote_server", "remarks": "rule_set_091" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on cron.hourly", + "value": "A remote time server for Chrony is configured", "remarks": "rule_set_091" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_daily", + "value": "chronyd_run_as_chrony_user", "remarks": "rule_set_092" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns cron.daily", + "value": "Ensure that chronyd is running under chrony user account", "remarks": "rule_set_092" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_daily", + "value": "chronyd_run_as_chrony_user", "remarks": "rule_set_092" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns cron.daily", + "value": "Ensure that chronyd is running under chrony user account", "remarks": "rule_set_092" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_daily", + "value": "package_cron_installed", "remarks": "rule_set_093" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on cron.daily", + "value": "Install the cron service", "remarks": "rule_set_093" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_daily", + "value": "package_cron_installed", "remarks": "rule_set_093" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on cron.daily", + "value": "Install the cron service", "remarks": "rule_set_093" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_daily", + "value": "service_crond_enabled", "remarks": "rule_set_094" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on cron.daily", + "value": "Enable cron Service", "remarks": "rule_set_094" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_daily", + "value": "service_crond_enabled", "remarks": "rule_set_094" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on cron.daily", + "value": "Enable cron Service", "remarks": "rule_set_094" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_weekly", + "value": "file_groupowner_crontab", "remarks": "rule_set_095" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns cron.weekly", + "value": "Verify Group Who Owns Crontab", "remarks": "rule_set_095" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_weekly", + "value": "file_groupowner_crontab", "remarks": "rule_set_095" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns cron.weekly", + "value": "Verify Group Who Owns Crontab", "remarks": "rule_set_095" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_weekly", + "value": "file_owner_crontab", "remarks": "rule_set_096" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on cron.weekly", + "value": "Verify Owner on crontab", "remarks": "rule_set_096" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_weekly", + "value": "file_owner_crontab", "remarks": "rule_set_096" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on cron.weekly", + "value": "Verify Owner on crontab", "remarks": "rule_set_096" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_weekly", + "value": "file_permissions_crontab", "remarks": "rule_set_097" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on cron.weekly", + "value": "Verify Permissions on crontab", "remarks": "rule_set_097" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_weekly", + "value": "file_permissions_crontab", "remarks": "rule_set_097" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on cron.weekly", + "value": "Verify Permissions on crontab", "remarks": "rule_set_097" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_monthly", + "value": "file_groupowner_cron_hourly", "remarks": "rule_set_098" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns cron.monthly", + "value": "Verify Group Who Owns cron.hourly", "remarks": "rule_set_098" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_monthly", + "value": "file_groupowner_cron_hourly", "remarks": "rule_set_098" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns cron.monthly", + "value": "Verify Group Who Owns cron.hourly", "remarks": "rule_set_098" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_monthly", + "value": "file_owner_cron_hourly", "remarks": "rule_set_099" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on cron.monthly", + "value": "Verify Owner on cron.hourly", "remarks": "rule_set_099" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_monthly", + "value": "file_owner_cron_hourly", "remarks": "rule_set_099" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on cron.monthly", + "value": "Verify Owner on cron.hourly", "remarks": "rule_set_099" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_monthly", + "value": "file_permissions_cron_hourly", "remarks": "rule_set_100" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on cron.monthly", + "value": "Verify Permissions on cron.hourly", "remarks": "rule_set_100" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_monthly", + "value": "file_permissions_cron_hourly", "remarks": "rule_set_100" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on cron.monthly", + "value": "Verify Permissions on cron.hourly", "remarks": "rule_set_100" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_d", + "value": "file_groupowner_cron_daily", "remarks": "rule_set_101" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns cron.d", + "value": "Verify Group Who Owns cron.daily", "remarks": "rule_set_101" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_d", + "value": "file_groupowner_cron_daily", "remarks": "rule_set_101" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns cron.d", + "value": "Verify Group Who Owns cron.daily", "remarks": "rule_set_101" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_d", + "value": "file_owner_cron_daily", "remarks": "rule_set_102" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on cron.d", + "value": "Verify Owner on cron.daily", "remarks": "rule_set_102" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_d", + "value": "file_owner_cron_daily", "remarks": "rule_set_102" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on cron.d", + "value": "Verify Owner on cron.daily", "remarks": "rule_set_102" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_d", + "value": "file_permissions_cron_daily", "remarks": "rule_set_103" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on cron.d", + "value": "Verify Permissions on cron.daily", "remarks": "rule_set_103" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_d", + "value": "file_permissions_cron_daily", "remarks": "rule_set_103" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on cron.d", + "value": "Verify Permissions on cron.daily", "remarks": "rule_set_103" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_cron_deny_not_exist", + "value": "file_groupowner_cron_weekly", "remarks": "rule_set_104" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that /etc/cron.deny does not exist", + "value": "Verify Group Who Owns cron.weekly", "remarks": "rule_set_104" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_cron_deny_not_exist", + "value": "file_groupowner_cron_weekly", "remarks": "rule_set_104" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that /etc/cron.deny does not exist", + "value": "Verify Group Who Owns cron.weekly", "remarks": "rule_set_104" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_cron_allow_exists", + "value": "file_owner_cron_weekly", "remarks": "rule_set_105" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that /etc/cron.allow exists", + "value": "Verify Owner on cron.weekly", "remarks": "rule_set_105" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_cron_allow_exists", + "value": "file_owner_cron_weekly", "remarks": "rule_set_105" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that /etc/cron.allow exists", + "value": "Verify Owner on cron.weekly", "remarks": "rule_set_105" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_allow", + "value": "file_permissions_cron_weekly", "remarks": "rule_set_106" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns /etc/cron.allow file", + "value": "Verify Permissions on cron.weekly", "remarks": "rule_set_106" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_allow", + "value": "file_permissions_cron_weekly", "remarks": "rule_set_106" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns /etc/cron.allow file", + "value": "Verify Permissions on cron.weekly", "remarks": "rule_set_106" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_allow", + "value": "file_groupowner_cron_monthly", "remarks": "rule_set_107" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns /etc/cron.allow file", + "value": "Verify Group Who Owns cron.monthly", "remarks": "rule_set_107" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_allow", + "value": "file_groupowner_cron_monthly", "remarks": "rule_set_107" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns /etc/cron.allow file", + "value": "Verify Group Who Owns cron.monthly", "remarks": "rule_set_107" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_allow", + "value": "file_owner_cron_monthly", "remarks": "rule_set_108" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on /etc/cron.allow file", + "value": "Verify Owner on cron.monthly", "remarks": "rule_set_108" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_allow", + "value": "file_owner_cron_monthly", "remarks": "rule_set_108" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on /etc/cron.allow file", + "value": "Verify Owner on cron.monthly", "remarks": "rule_set_108" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_at_deny_not_exist", + "value": "file_permissions_cron_monthly", "remarks": "rule_set_109" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that /etc/at.deny does not exist", + "value": "Verify Permissions on cron.monthly", "remarks": "rule_set_109" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_at_deny_not_exist", + "value": "file_permissions_cron_monthly", "remarks": "rule_set_109" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that /etc/at.deny does not exist", + "value": "Verify Permissions on cron.monthly", "remarks": "rule_set_109" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_at_allow", + "value": "file_groupowner_cron_d", "remarks": "rule_set_110" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns /etc/at.allow file", + "value": "Verify Group Who Owns cron.d", "remarks": "rule_set_110" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_at_allow", + "value": "file_groupowner_cron_d", "remarks": "rule_set_110" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns /etc/at.allow file", + "value": "Verify Group Who Owns cron.d", "remarks": "rule_set_110" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_at_allow", + "value": "file_owner_cron_d", "remarks": "rule_set_111" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns /etc/at.allow file", + "value": "Verify Owner on cron.d", "remarks": "rule_set_111" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_at_allow", + "value": "file_owner_cron_d", "remarks": "rule_set_111" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns /etc/at.allow file", + "value": "Verify Owner on cron.d", "remarks": "rule_set_111" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_at_allow", + "value": "file_permissions_cron_d", "remarks": "rule_set_112" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on /etc/at.allow file", + "value": "Verify Permissions on cron.d", "remarks": "rule_set_112" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_at_allow", + "value": "file_permissions_cron_d", "remarks": "rule_set_112" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on /etc/at.allow file", + "value": "Verify Permissions on cron.d", "remarks": "rule_set_112" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_ip_forward", + "value": "file_cron_deny_not_exist", "remarks": "rule_set_113" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for IP Forwarding on IPv4 Interfaces", + "value": "Ensure that /etc/cron.deny does not exist", "remarks": "rule_set_113" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_ip_forward", + "value": "file_cron_deny_not_exist", "remarks": "rule_set_113" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for IP Forwarding on IPv4 Interfaces", + "value": "Ensure that /etc/cron.deny does not exist", "remarks": "rule_set_113" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_forwarding", + "value": "file_cron_allow_exists", "remarks": "rule_set_114" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for IPv6 Forwarding", + "value": "Ensure that /etc/cron.allow exists", "remarks": "rule_set_114" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_forwarding", + "value": "file_cron_allow_exists", "remarks": "rule_set_114" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for IPv6 Forwarding", + "value": "Ensure that /etc/cron.allow exists", "remarks": "rule_set_114" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_send_redirects", + "value": "file_groupowner_cron_allow", "remarks": "rule_set_115" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces", + "value": "Verify Group Who Owns /etc/cron.allow file", "remarks": "rule_set_115" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_send_redirects", + "value": "file_groupowner_cron_allow", "remarks": "rule_set_115" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces", + "value": "Verify Group Who Owns /etc/cron.allow file", "remarks": "rule_set_115" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_send_redirects", + "value": "file_owner_cron_allow", "remarks": "rule_set_116" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces by Default", + "value": "Verify User Who Owns /etc/cron.allow file", "remarks": "rule_set_116" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_send_redirects", + "value": "file_owner_cron_allow", "remarks": "rule_set_116" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces by Default", + "value": "Verify User Who Owns /etc/cron.allow file", "remarks": "rule_set_116" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses", + "value": "file_permissions_cron_allow", "remarks": "rule_set_117" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Ignore Bogus ICMP Error Responses on IPv4 Interfaces", + "value": "Verify Permissions on /etc/cron.allow file", "remarks": "rule_set_117" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses", + "value": "file_permissions_cron_allow", "remarks": "rule_set_117" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Ignore Bogus ICMP Error Responses on IPv4 Interfaces", + "value": "Verify Permissions on /etc/cron.allow file", "remarks": "rule_set_117" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts", + "value": "file_at_deny_not_exist", "remarks": "rule_set_118" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Ignore ICMP Broadcast Echo Requests on IPv4 Interfaces", + "value": "Ensure that /etc/at.deny does not exist", "remarks": "rule_set_118" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts", + "value": "file_at_deny_not_exist", "remarks": "rule_set_118" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Ignore ICMP Broadcast Echo Requests on IPv4 Interfaces", + "value": "Ensure that /etc/at.deny does not exist", "remarks": "rule_set_118" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_accept_redirects", + "value": "file_groupowner_at_allow", "remarks": "rule_set_119" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Accepting ICMP Redirects for All IPv4 Interfaces", + "value": "Verify Group Who Owns /etc/at.allow file", "remarks": "rule_set_119" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_accept_redirects", + "value": "file_groupowner_at_allow", "remarks": "rule_set_119" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Accepting ICMP Redirects for All IPv4 Interfaces", + "value": "Verify Group Who Owns /etc/at.allow file", "remarks": "rule_set_119" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_accept_redirects", + "value": "file_owner_at_allow", "remarks": "rule_set_120" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 Interfaces", + "value": "Verify User Who Owns /etc/at.allow file", "remarks": "rule_set_120" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_accept_redirects", + "value": "file_owner_at_allow", "remarks": "rule_set_120" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 Interfaces", + "value": "Verify User Who Owns /etc/at.allow file", "remarks": "rule_set_120" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_redirects", + "value": "file_permissions_at_allow", "remarks": "rule_set_121" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Accepting ICMP Redirects for All IPv6 Interfaces", + "value": "Verify Permissions on /etc/at.allow file", "remarks": "rule_set_121" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_redirects", + "value": "file_permissions_at_allow", "remarks": "rule_set_121" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Accepting ICMP Redirects for All IPv6 Interfaces", + "value": "Verify Permissions on /etc/at.allow file", "remarks": "rule_set_121" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_redirects", + "value": "kernel_module_atm_disabled", "remarks": "rule_set_122" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces", + "value": "Disable ATM Support", "remarks": "rule_set_122" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_redirects", + "value": "kernel_module_atm_disabled", "remarks": "rule_set_122" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces", + "value": "Disable ATM Support", "remarks": "rule_set_122" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_secure_redirects", + "value": "kernel_module_can_disabled", "remarks": "rule_set_123" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces", + "value": "Disable CAN Support", "remarks": "rule_set_123" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_secure_redirects", + "value": "kernel_module_can_disabled", "remarks": "rule_set_123" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces", + "value": "Disable CAN Support", "remarks": "rule_set_123" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_secure_redirects", + "value": "kernel_module_dccp_disabled", "remarks": "rule_set_124" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Kernel Parameter for Accepting Secure Redirects By Default", + "value": "Disable DCCP Support", "remarks": "rule_set_124" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_secure_redirects", + "value": "kernel_module_dccp_disabled", "remarks": "rule_set_124" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Kernel Parameter for Accepting Secure Redirects By Default", + "value": "Disable DCCP Support", "remarks": "rule_set_124" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_rp_filter", + "value": "kernel_module_tipc_disabled", "remarks": "rule_set_125" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces", + "value": "Disable TIPC Support", "remarks": "rule_set_125" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_rp_filter", + "value": "kernel_module_tipc_disabled", "remarks": "rule_set_125" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces", + "value": "Disable TIPC Support", "remarks": "rule_set_125" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_rp_filter", + "value": "kernel_module_rds_disabled", "remarks": "rule_set_126" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces by Default", + "value": "Disable RDS Support", "remarks": "rule_set_126" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_rp_filter", + "value": "kernel_module_rds_disabled", "remarks": "rule_set_126" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces by Default", + "value": "Disable RDS Support", "remarks": "rule_set_126" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_accept_source_route", + "value": "kernel_module_sctp_disabled", "remarks": "rule_set_127" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces", + "value": "Disable SCTP Support", "remarks": "rule_set_127" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_accept_source_route", + "value": "kernel_module_sctp_disabled", "remarks": "rule_set_127" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces", + "value": "Disable SCTP Support", "remarks": "rule_set_127" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_accept_source_route", + "value": "sysctl_net_ipv4_ip_forward", "remarks": "rule_set_128" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces by Default", + "value": "Disable Kernel Parameter for IP Forwarding on IPv4 Interfaces", "remarks": "rule_set_128" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_accept_source_route", + "value": "sysctl_net_ipv4_ip_forward", "remarks": "rule_set_128" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces by Default", + "value": "Disable Kernel Parameter for IP Forwarding on IPv4 Interfaces", "remarks": "rule_set_128" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_source_route", + "value": "sysctl_net_ipv4_conf_all_forwarding", "remarks": "rule_set_129" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces", + "value": "Disable Kernel Parameter for IPv4 Forwarding on all IPv4 Interfaces", "remarks": "rule_set_129" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_source_route", + "value": "sysctl_net_ipv4_conf_all_forwarding", "remarks": "rule_set_129" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces", + "value": "Disable Kernel Parameter for IPv4 Forwarding on all IPv4 Interfaces", "remarks": "rule_set_129" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_source_route", + "value": "sysctl_net_ipv4_conf_all_send_redirects", "remarks": "rule_set_130" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces by Default", + "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces", "remarks": "rule_set_130" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_source_route", + "value": "sysctl_net_ipv4_conf_all_send_redirects", "remarks": "rule_set_130" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces by Default", + "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces", "remarks": "rule_set_130" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_log_martians", + "value": "sysctl_net_ipv4_conf_default_send_redirects", "remarks": "rule_set_131" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces", + "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces by Default", "remarks": "rule_set_131" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_log_martians", + "value": "sysctl_net_ipv4_conf_default_send_redirects", "remarks": "rule_set_131" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces", + "value": "Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces by Default", "remarks": "rule_set_131" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_log_martians", + "value": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses", "remarks": "rule_set_132" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Paremeter to Log Martian Packets on all IPv4 Interfaces by Default", + "value": "Enable Kernel Parameter to Ignore Bogus ICMP Error Responses on IPv4 Interfaces", "remarks": "rule_set_132" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_log_martians", + "value": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses", "remarks": "rule_set_132" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Paremeter to Log Martian Packets on all IPv4 Interfaces by Default", + "value": "Enable Kernel Parameter to Ignore Bogus ICMP Error Responses on IPv4 Interfaces", "remarks": "rule_set_132" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_tcp_syncookies", + "value": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts", "remarks": "rule_set_133" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces", + "value": "Enable Kernel Parameter to Ignore ICMP Broadcast Echo Requests on IPv4 Interfaces", "remarks": "rule_set_133" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_tcp_syncookies", + "value": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts", "remarks": "rule_set_133" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces", + "value": "Enable Kernel Parameter to Ignore ICMP Broadcast Echo Requests on IPv4 Interfaces", "remarks": "rule_set_133" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_ra", + "value": "sysctl_net_ipv4_conf_all_accept_redirects", "remarks": "rule_set_134" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Accepting Router Advertisements on All IPv6 Interfaces", + "value": "Disable Accepting ICMP Redirects for All IPv4 Interfaces", "remarks": "rule_set_134" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_ra", + "value": "sysctl_net_ipv4_conf_all_accept_redirects", "remarks": "rule_set_134" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Accepting Router Advertisements on All IPv6 Interfaces", + "value": "Disable Accepting ICMP Redirects for All IPv4 Interfaces", "remarks": "rule_set_134" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_ra", + "value": "sysctl_net_ipv4_conf_default_accept_redirects", "remarks": "rule_set_135" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Accepting Router Advertisements on all IPv6 Interfaces by Default", + "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 Interfaces", "remarks": "rule_set_135" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_ra", + "value": "sysctl_net_ipv4_conf_default_accept_redirects", "remarks": "rule_set_135" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Accepting Router Advertisements on all IPv6 Interfaces by Default", + "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 Interfaces", "remarks": "rule_set_135" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_nftables_installed", + "value": "sysctl_net_ipv4_conf_all_secure_redirects", "remarks": "rule_set_136" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install nftables Package", + "value": "Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces", "remarks": "rule_set_136" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_nftables_installed", + "value": "sysctl_net_ipv4_conf_all_secure_redirects", "remarks": "rule_set_136" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install nftables Package", + "value": "Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces", "remarks": "rule_set_136" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_firewalld_enabled", + "value": "sysctl_net_ipv4_conf_default_secure_redirects", "remarks": "rule_set_137" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify firewalld Enabled", + "value": "Configure Kernel Parameter for Accepting Secure Redirects By Default", "remarks": "rule_set_137" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_firewalld_enabled", + "value": "sysctl_net_ipv4_conf_default_secure_redirects", "remarks": "rule_set_137" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify firewalld Enabled", + "value": "Configure Kernel Parameter for Accepting Secure Redirects By Default", "remarks": "rule_set_137" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_firewalld_installed", + "value": "sysctl_net_ipv4_conf_all_rp_filter", "remarks": "rule_set_138" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install firewalld Package", + "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces", "remarks": "rule_set_138" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_firewalld_installed", + "value": "sysctl_net_ipv4_conf_all_rp_filter", "remarks": "rule_set_138" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install firewalld Package", + "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces", "remarks": "rule_set_138" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_nftables_disabled", + "value": "sysctl_net_ipv4_conf_default_rp_filter", "remarks": "rule_set_139" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify nftables Service is Disabled", + "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces by Default", "remarks": "rule_set_139" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_nftables_disabled", + "value": "sysctl_net_ipv4_conf_default_rp_filter", "remarks": "rule_set_139" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify nftables Service is Disabled", + "value": "Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces by Default", "remarks": "rule_set_139" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "firewalld_loopback_traffic_trusted", + "value": "sysctl_net_ipv4_conf_all_accept_source_route", "remarks": "rule_set_140" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Firewalld to Trust Loopback Traffic", + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces", "remarks": "rule_set_140" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "firewalld_loopback_traffic_trusted", + "value": "sysctl_net_ipv4_conf_all_accept_source_route", "remarks": "rule_set_140" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Firewalld to Trust Loopback Traffic", + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces", "remarks": "rule_set_140" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "firewalld_loopback_traffic_restricted", + "value": "sysctl_net_ipv4_conf_default_accept_source_route", "remarks": "rule_set_141" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Firewalld to Restrict Loopback Traffic", + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces by Default", "remarks": "rule_set_141" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "firewalld_loopback_traffic_restricted", + "value": "sysctl_net_ipv4_conf_default_accept_source_route", "remarks": "rule_set_141" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Firewalld to Restrict Loopback Traffic", + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces by Default", "remarks": "rule_set_141" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_sshd_config", + "value": "sysctl_net_ipv4_conf_all_log_martians", "remarks": "rule_set_142" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns SSH Server config file", + "value": "Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces", "remarks": "rule_set_142" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_sshd_config", + "value": "sysctl_net_ipv4_conf_all_log_martians", "remarks": "rule_set_142" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns SSH Server config file", + "value": "Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces", "remarks": "rule_set_142" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_sshd_config", + "value": "sysctl_net_ipv4_conf_default_log_martians", "remarks": "rule_set_143" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on SSH Server config file", + "value": "Enable Kernel Paremeter to Log Martian Packets on all IPv4 Interfaces by Default", "remarks": "rule_set_143" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_sshd_config", + "value": "sysctl_net_ipv4_conf_default_log_martians", "remarks": "rule_set_143" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Owner on SSH Server config file", + "value": "Enable Kernel Paremeter to Log Martian Packets on all IPv4 Interfaces by Default", "remarks": "rule_set_143" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_config", + "value": "sysctl_net_ipv4_tcp_syncookies", "remarks": "rule_set_144" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on SSH Server config file", + "value": "Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces", "remarks": "rule_set_144" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_config", + "value": "sysctl_net_ipv4_tcp_syncookies", "remarks": "rule_set_144" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on SSH Server config file", + "value": "Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces", "remarks": "rule_set_144" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_private_key", + "value": "sysctl_net_ipv6_conf_all_forwarding", "remarks": "rule_set_145" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on SSH Server Private *_key Key Files", + "value": "Disable Kernel Parameter for IPv6 Forwarding", "remarks": "rule_set_145" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_private_key", + "value": "sysctl_net_ipv6_conf_all_forwarding", "remarks": "rule_set_145" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on SSH Server Private *_key Key Files", + "value": "Disable Kernel Parameter for IPv6 Forwarding", "remarks": "rule_set_145" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_private_key", + "value": "sysctl_net_ipv6_conf_default_forwarding", "remarks": "rule_set_146" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Ownership on SSH Server Private *_key Key Files", + "value": "Disable Kernel Parameter for IPv6 Forwarding by default", "remarks": "rule_set_146" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_private_key", + "value": "sysctl_net_ipv6_conf_default_forwarding", "remarks": "rule_set_146" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Ownership on SSH Server Private *_key Key Files", + "value": "Disable Kernel Parameter for IPv6 Forwarding by default", "remarks": "rule_set_146" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_sshd_private_key", + "value": "sysctl_net_ipv6_conf_all_accept_redirects", "remarks": "rule_set_147" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Ownership on SSH Server Private *_key Key Files", + "value": "Disable Accepting ICMP Redirects for All IPv6 Interfaces", "remarks": "rule_set_147" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_sshd_private_key", + "value": "sysctl_net_ipv6_conf_all_accept_redirects", "remarks": "rule_set_147" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Ownership on SSH Server Private *_key Key Files", + "value": "Disable Accepting ICMP Redirects for All IPv6 Interfaces", "remarks": "rule_set_147" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_pub_key", + "value": "sysctl_net_ipv6_conf_default_accept_redirects", "remarks": "rule_set_148" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on SSH Server Public *.pub Key Files", + "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces", "remarks": "rule_set_148" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_pub_key", + "value": "sysctl_net_ipv6_conf_default_accept_redirects", "remarks": "rule_set_148" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on SSH Server Public *.pub Key Files", + "value": "Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces", "remarks": "rule_set_148" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_pub_key", + "value": "sysctl_net_ipv6_conf_all_accept_source_route", "remarks": "rule_set_149" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Ownership on SSH Server Public *.pub Key Files", + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces", "remarks": "rule_set_149" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_pub_key", + "value": "sysctl_net_ipv6_conf_all_accept_source_route", "remarks": "rule_set_149" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Ownership on SSH Server Public *.pub Key Files", + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces", "remarks": "rule_set_149" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_sshd_pub_key", + "value": "sysctl_net_ipv6_conf_default_accept_source_route", "remarks": "rule_set_150" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Ownership on SSH Server Public *.pub Key Files", + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces by Default", "remarks": "rule_set_150" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_sshd_pub_key", + "value": "sysctl_net_ipv6_conf_default_accept_source_route", "remarks": "rule_set_150" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Ownership on SSH Server Public *.pub Key Files", + "value": "Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces by Default", "remarks": "rule_set_150" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_kex", + "value": "sysctl_net_ipv6_conf_all_accept_ra", "remarks": "rule_set_151" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Use Only Strong Key Exchange algorithms", + "value": "Configure Accepting Router Advertisements on All IPv6 Interfaces", "remarks": "rule_set_151" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_kex", + "value": "sysctl_net_ipv6_conf_all_accept_ra", "remarks": "rule_set_151" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Use Only Strong Key Exchange algorithms", + "value": "Configure Accepting Router Advertisements on All IPv6 Interfaces", "remarks": "rule_set_151" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_macs", + "value": "sysctl_net_ipv6_conf_default_accept_ra", "remarks": "rule_set_152" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Use Only Strong MACs", + "value": "Disable Accepting Router Advertisements on all IPv6 Interfaces by Default", "remarks": "rule_set_152" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_macs", + "value": "sysctl_net_ipv6_conf_default_accept_ra", "remarks": "rule_set_152" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Use Only Strong MACs", + "value": "Disable Accepting Router Advertisements on all IPv6 Interfaces by Default", "remarks": "rule_set_152" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_limit_user_access", + "value": "package_firewalld_installed", "remarks": "rule_set_153" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Limit Users' SSH Access", + "value": "Install firewalld Package", "remarks": "rule_set_153" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_limit_user_access", + "value": "package_firewalld_installed", "remarks": "rule_set_153" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Limit Users' SSH Access", + "value": "Install firewalld Package", "remarks": "rule_set_153" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_enable_warning_banner_net", + "value": "service_firewalld_enabled", "remarks": "rule_set_154" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable SSH Warning Banner", + "value": "Verify firewalld Enabled", "remarks": "rule_set_154" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_enable_warning_banner_net", + "value": "service_firewalld_enabled", "remarks": "rule_set_154" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable SSH Warning Banner", + "value": "Verify firewalld Enabled", "remarks": "rule_set_154" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_idle_timeout", + "value": "firewalld_loopback_traffic_trusted", "remarks": "rule_set_155" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set SSH Client Alive Interval", + "value": "Configure Firewalld to Trust Loopback Traffic", "remarks": "rule_set_155" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_idle_timeout", + "value": "firewalld_loopback_traffic_trusted", "remarks": "rule_set_155" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set SSH Client Alive Interval", + "value": "Configure Firewalld to Trust Loopback Traffic", "remarks": "rule_set_155" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_keepalive", + "value": "firewalld_loopback_traffic_restricted", "remarks": "rule_set_156" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set SSH Client Alive Count Max", + "value": "Configure Firewalld to Restrict Loopback Traffic", "remarks": "rule_set_156" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_keepalive", + "value": "firewalld_loopback_traffic_restricted", "remarks": "rule_set_156" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set SSH Client Alive Count Max", + "value": "Configure Firewalld to Restrict Loopback Traffic", "remarks": "rule_set_156" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_gssapi_auth", + "value": "file_groupowner_sshd_config", "remarks": "rule_set_157" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable GSSAPI Authentication", + "value": "Verify Group Who Owns SSH Server config file", "remarks": "rule_set_157" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_gssapi_auth", + "value": "file_groupowner_sshd_config", "remarks": "rule_set_157" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable GSSAPI Authentication", + "value": "Verify Group Who Owns SSH Server config file", "remarks": "rule_set_157" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "disable_host_auth", + "value": "file_owner_sshd_config", "remarks": "rule_set_158" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Host-Based Authentication", + "value": "Verify Owner on SSH Server config file", "remarks": "rule_set_158" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "disable_host_auth", + "value": "file_owner_sshd_config", "remarks": "rule_set_158" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Host-Based Authentication", + "value": "Verify Owner on SSH Server config file", "remarks": "rule_set_158" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_rhosts", + "value": "file_permissions_sshd_config", "remarks": "rule_set_159" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable SSH Support for .rhosts Files", + "value": "Verify Permissions on SSH Server config file", "remarks": "rule_set_159" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_rhosts", + "value": "file_permissions_sshd_config", "remarks": "rule_set_159" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable SSH Support for .rhosts Files", + "value": "Verify Permissions on SSH Server config file", "remarks": "rule_set_159" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_login_grace_time", + "value": "file_groupownership_sshd_private_key", "remarks": "rule_set_160" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure SSH LoginGraceTime is configured", + "value": "Verify Group Ownership on SSH Server Private *_key Key Files", "remarks": "rule_set_160" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_login_grace_time", + "value": "file_groupownership_sshd_private_key", "remarks": "rule_set_160" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure SSH LoginGraceTime is configured", + "value": "Verify Group Ownership on SSH Server Private *_key Key Files", "remarks": "rule_set_160" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_loglevel_verbose", + "value": "file_ownership_sshd_private_key", "remarks": "rule_set_161" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set SSH Daemon LogLevel to VERBOSE", + "value": "Verify Ownership on SSH Server Private *_key Key Files", "remarks": "rule_set_161" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_loglevel_verbose", + "value": "file_ownership_sshd_private_key", "remarks": "rule_set_161" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set SSH Daemon LogLevel to VERBOSE", + "value": "Verify Ownership on SSH Server Private *_key Key Files", "remarks": "rule_set_161" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_max_auth_tries", + "value": "file_permissions_sshd_private_key", "remarks": "rule_set_162" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set SSH authentication attempt limit", + "value": "Verify Permissions on SSH Server Private *_key Key Files", "remarks": "rule_set_162" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_max_auth_tries", + "value": "file_permissions_sshd_private_key", "remarks": "rule_set_162" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set SSH authentication attempt limit", + "value": "Verify Permissions on SSH Server Private *_key Key Files", "remarks": "rule_set_162" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_maxstartups", + "value": "file_groupownership_sshd_pub_key", "remarks": "rule_set_163" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure SSH MaxStartups is configured", + "value": "Verify Group Ownership on SSH Server Public *.pub Key Files", "remarks": "rule_set_163" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_maxstartups", + "value": "file_groupownership_sshd_pub_key", "remarks": "rule_set_163" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure SSH MaxStartups is configured", + "value": "Verify Group Ownership on SSH Server Public *.pub Key Files", "remarks": "rule_set_163" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_max_sessions", + "value": "file_ownership_sshd_pub_key", "remarks": "rule_set_164" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set SSH MaxSessions limit", + "value": "Verify Ownership on SSH Server Public *.pub Key Files", "remarks": "rule_set_164" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_max_sessions", + "value": "file_ownership_sshd_pub_key", "remarks": "rule_set_164" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set SSH MaxSessions limit", + "value": "Verify Ownership on SSH Server Public *.pub Key Files", "remarks": "rule_set_164" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_empty_passwords", + "value": "file_permissions_sshd_pub_key", "remarks": "rule_set_165" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable SSH Access via Empty Passwords", + "value": "Verify Permissions on SSH Server Public *.pub Key Files", "remarks": "rule_set_165" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_empty_passwords", + "value": "file_permissions_sshd_pub_key", "remarks": "rule_set_165" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable SSH Access via Empty Passwords", + "value": "Verify Permissions on SSH Server Public *.pub Key Files", "remarks": "rule_set_165" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_root_login", + "value": "sshd_limit_user_access", "remarks": "rule_set_166" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable SSH Root Login", + "value": "Limit Users' SSH Access", "remarks": "rule_set_166" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_root_login", + "value": "sshd_limit_user_access", "remarks": "rule_set_166" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable SSH Root Login", + "value": "Limit Users' SSH Access", "remarks": "rule_set_166" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_do_not_permit_user_env", + "value": "sshd_enable_warning_banner_net", "remarks": "rule_set_167" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Do Not Allow SSH Environment Options", + "value": "Enable SSH Warning Banner", "remarks": "rule_set_167" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_do_not_permit_user_env", + "value": "sshd_enable_warning_banner_net", "remarks": "rule_set_167" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Do Not Allow SSH Environment Options", + "value": "Enable SSH Warning Banner", "remarks": "rule_set_167" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_enable_pam", + "value": "sshd_set_idle_timeout", "remarks": "rule_set_168" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable PAM", + "value": "Set SSH Client Alive Interval", "remarks": "rule_set_168" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_enable_pam", + "value": "sshd_set_idle_timeout", "remarks": "rule_set_168" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable PAM", + "value": "Set SSH Client Alive Interval", "remarks": "rule_set_168" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_sudo_installed", + "value": "sshd_set_keepalive", "remarks": "rule_set_169" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install sudo Package", + "value": "Set SSH Client Alive Count Max", "remarks": "rule_set_169" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_sudo_installed", + "value": "sshd_set_keepalive", "remarks": "rule_set_169" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install sudo Package", + "value": "Set SSH Client Alive Count Max", "remarks": "rule_set_169" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_add_use_pty", + "value": "sshd_disable_forwarding", "remarks": "rule_set_170" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Only Users Logged In To Real tty Can Execute Sudo - sudo use_pty", + "value": "Disable SSH Forwarding", "remarks": "rule_set_170" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_add_use_pty", + "value": "sshd_disable_forwarding", "remarks": "rule_set_170" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Only Users Logged In To Real tty Can Execute Sudo - sudo use_pty", + "value": "Disable SSH Forwarding", "remarks": "rule_set_170" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_custom_logfile", + "value": "sshd_disable_gssapi_auth", "remarks": "rule_set_171" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Sudo Logfile Exists - sudo logfile", + "value": "Disable GSSAPI Authentication", "remarks": "rule_set_171" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_custom_logfile", + "value": "sshd_disable_gssapi_auth", "remarks": "rule_set_171" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Sudo Logfile Exists - sudo logfile", + "value": "Disable GSSAPI Authentication", "remarks": "rule_set_171" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_require_reauthentication", + "value": "disable_host_auth", "remarks": "rule_set_172" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Require Re-Authentication When Using the sudo Command", + "value": "Disable Host-Based Authentication", "remarks": "rule_set_172" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_require_reauthentication", + "value": "disable_host_auth", "remarks": "rule_set_172" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Require Re-Authentication When Using the sudo Command", + "value": "Disable Host-Based Authentication", "remarks": "rule_set_172" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "use_pam_wheel_group_for_su", + "value": "sshd_disable_rhosts", "remarks": "rule_set_173" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enforce Usage of pam_wheel with Group Parameter for su Authentication", + "value": "Disable SSH Support for .rhosts Files", "remarks": "rule_set_173" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "use_pam_wheel_group_for_su", + "value": "sshd_disable_rhosts", "remarks": "rule_set_173" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enforce Usage of pam_wheel with Group Parameter for su Authentication", + "value": "Disable SSH Support for .rhosts Files", "remarks": "rule_set_173" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_pam_wheel_group_empty", + "value": "sshd_use_strong_kex", "remarks": "rule_set_174" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure the Group Used by pam_wheel.so Module Exists on System and is Empty", + "value": "Use Only Strong Key Exchange algorithms", "remarks": "rule_set_174" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_pam_wheel_group_empty", + "value": "sshd_use_strong_kex", "remarks": "rule_set_174" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure the Group Used by pam_wheel.so Module Exists on System and is Empty", + "value": "Use Only Strong Key Exchange algorithms", "remarks": "rule_set_174" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_pam_pwquality_installed", + "value": "sshd_set_login_grace_time", "remarks": "rule_set_175" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install pam_pwquality Package", + "value": "Ensure SSH LoginGraceTime is configured", "remarks": "rule_set_175" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_pam_pwquality_installed", + "value": "sshd_set_login_grace_time", "remarks": "rule_set_175" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install pam_pwquality Package", + "value": "Ensure SSH LoginGraceTime is configured", "remarks": "rule_set_175" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_password_auth", + "value": "sshd_set_loglevel_verbose", "remarks": "rule_set_176" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth File.", + "value": "Set SSH Daemon LogLevel to VERBOSE", "remarks": "rule_set_176" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_password_auth", + "value": "sshd_set_loglevel_verbose", "remarks": "rule_set_176" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth File.", + "value": "Set SSH Daemon LogLevel to VERBOSE", "remarks": "rule_set_176" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_system_auth", + "value": "sshd_use_strong_macs", "remarks": "rule_set_177" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth File.", + "value": "Use Only Strong MACs", "remarks": "rule_set_177" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_system_auth", + "value": "sshd_use_strong_macs", "remarks": "rule_set_177" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth File.", + "value": "Use Only Strong MACs", "remarks": "rule_set_177" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_deny", + "value": "sshd_set_max_auth_tries", "remarks": "rule_set_178" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Lock Accounts After Failed Password Attempts", + "value": "Set SSH authentication attempt limit", "remarks": "rule_set_178" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_deny", + "value": "sshd_set_max_auth_tries", "remarks": "rule_set_178" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Lock Accounts After Failed Password Attempts", + "value": "Set SSH authentication attempt limit", "remarks": "rule_set_178" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_unlock_time", + "value": "sshd_set_maxstartups", "remarks": "rule_set_179" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Lockout Time for Failed Password Attempts", + "value": "Ensure SSH MaxStartups is configured", "remarks": "rule_set_179" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_unlock_time", + "value": "sshd_set_maxstartups", "remarks": "rule_set_179" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Lockout Time for Failed Password Attempts", + "value": "Ensure SSH MaxStartups is configured", "remarks": "rule_set_179" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_difok", + "value": "sshd_set_max_sessions", "remarks": "rule_set_180" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure PAM Enforces Password Requirements - Minimum Different Characters", + "value": "Set SSH MaxSessions limit", "remarks": "rule_set_180" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_difok", + "value": "sshd_set_max_sessions", "remarks": "rule_set_180" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure PAM Enforces Password Requirements - Minimum Different Characters", + "value": "Set SSH MaxSessions limit", "remarks": "rule_set_180" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_minlen", + "value": "sshd_disable_empty_passwords", "remarks": "rule_set_181" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure PAM Enforces Password Requirements - Minimum Length", + "value": "Disable SSH Access via Empty Passwords", "remarks": "rule_set_181" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_minlen", + "value": "sshd_disable_empty_passwords", "remarks": "rule_set_181" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure PAM Enforces Password Requirements - Minimum Length", + "value": "Disable SSH Access via Empty Passwords", "remarks": "rule_set_181" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_minclass", + "value": "sshd_disable_root_login", "remarks": "rule_set_182" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure PAM Enforces Password Requirements - Minimum Different Categories", + "value": "Disable SSH Root Login", "remarks": "rule_set_182" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_minclass", + "value": "sshd_disable_root_login", "remarks": "rule_set_182" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure PAM Enforces Password Requirements - Minimum Different Categories", + "value": "Disable SSH Root Login", "remarks": "rule_set_182" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_maxrepeat", + "value": "sshd_do_not_permit_user_env", "remarks": "rule_set_183" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Password Maximum Consecutive Repeating Characters", + "value": "Do Not Allow SSH Environment Options", "remarks": "rule_set_183" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_maxrepeat", + "value": "sshd_do_not_permit_user_env", "remarks": "rule_set_183" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Password Maximum Consecutive Repeating Characters", + "value": "Do Not Allow SSH Environment Options", "remarks": "rule_set_183" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_dictcheck", + "value": "sshd_enable_pam", "remarks": "rule_set_184" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure PAM Enforces Password Requirements - Prevent the Use of Dictionary Words", + "value": "Enable PAM", "remarks": "rule_set_184" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_dictcheck", + "value": "sshd_enable_pam", "remarks": "rule_set_184" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure PAM Enforces Password Requirements - Prevent the Use of Dictionary Words", + "value": "Enable PAM", "remarks": "rule_set_184" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_enforce_root", + "value": "package_sudo_installed", "remarks": "rule_set_185" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure PAM Enforces Password Requirements - Enforce for root User", + "value": "Install sudo Package", "remarks": "rule_set_185" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_enforce_root", + "value": "package_sudo_installed", "remarks": "rule_set_185" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure PAM Enforces Password Requirements - Enforce for root User", + "value": "Install sudo Package", "remarks": "rule_set_185" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_pwhistory_remember_password_auth", + "value": "sudo_add_use_pty", "remarks": "rule_set_186" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Limit Password Reuse: password-auth", + "value": "Ensure Only Users Logged In To Real tty Can Execute Sudo - sudo use_pty", "remarks": "rule_set_186" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_pwhistory_remember_password_auth", + "value": "sudo_add_use_pty", "remarks": "rule_set_186" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Limit Password Reuse: password-auth", + "value": "Ensure Only Users Logged In To Real tty Can Execute Sudo - sudo use_pty", "remarks": "rule_set_186" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_pwhistory_remember_system_auth", + "value": "sudo_custom_logfile", "remarks": "rule_set_187" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Limit Password Reuse: system-auth", + "value": "Ensure Sudo Logfile Exists - sudo logfile", "remarks": "rule_set_187" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_pwhistory_remember_system_auth", + "value": "sudo_custom_logfile", "remarks": "rule_set_187" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Limit Password Reuse: system-auth", + "value": "Ensure Sudo Logfile Exists - sudo logfile", "remarks": "rule_set_187" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_empty_passwords", + "value": "sudo_require_authentication", "remarks": "rule_set_188" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Prevent Login to Accounts With Empty Password", + "value": "Ensure Users Re-Authenticate for Privilege Escalation - sudo", "remarks": "rule_set_188" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_empty_passwords", + "value": "sudo_require_authentication", "remarks": "rule_set_188" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Prevent Login to Accounts With Empty Password", + "value": "Ensure Users Re-Authenticate for Privilege Escalation - sudo", "remarks": "rule_set_188" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_systemauth", + "value": "sudo_require_reauthentication", "remarks": "rule_set_189" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set PAM''s Password Hashing Algorithm", + "value": "Require Re-Authentication When Using the sudo Command", "remarks": "rule_set_189" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_systemauth", + "value": "sudo_require_reauthentication", "remarks": "rule_set_189" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set PAM''s Password Hashing Algorithm", + "value": "Require Re-Authentication When Using the sudo Command", "remarks": "rule_set_189" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_passwordauth", + "value": "use_pam_wheel_group_for_su", "remarks": "rule_set_190" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set PAM''s Password Hashing Algorithm - password-auth", + "value": "Enforce Usage of pam_wheel with Group Parameter for su Authentication", "remarks": "rule_set_190" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_passwordauth", + "value": "use_pam_wheel_group_for_su", "remarks": "rule_set_190" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set PAM''s Password Hashing Algorithm - password-auth", + "value": "Enforce Usage of pam_wheel with Group Parameter for su Authentication", "remarks": "rule_set_190" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_maximum_age_login_defs", + "value": "ensure_pam_wheel_group_empty", "remarks": "rule_set_191" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Password Maximum Age", + "value": "Ensure the Group Used by pam_wheel.so Module Exists on System and is Empty", "remarks": "rule_set_191" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_maximum_age_login_defs", + "value": "ensure_pam_wheel_group_empty", "remarks": "rule_set_191" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Password Maximum Age", + "value": "Ensure the Group Used by pam_wheel.so Module Exists on System and is Empty", "remarks": "rule_set_191" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_set_max_life_existing", + "value": "account_password_pam_faillock_password_auth", "remarks": "rule_set_192" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Existing Passwords Maximum Age", + "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth File.", "remarks": "rule_set_192" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_set_max_life_existing", + "value": "account_password_pam_faillock_password_auth", "remarks": "rule_set_192" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Existing Passwords Maximum Age", + "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth File.", "remarks": "rule_set_192" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_warn_age_login_defs", + "value": "account_password_pam_faillock_system_auth", "remarks": "rule_set_193" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Password Warning Age", + "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth File.", "remarks": "rule_set_193" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_warn_age_login_defs", + "value": "account_password_pam_faillock_system_auth", "remarks": "rule_set_193" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Password Warning Age", + "value": "Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth File.", "remarks": "rule_set_193" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_set_warn_age_existing", + "value": "package_pam_pwquality_installed", "remarks": "rule_set_194" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Existing Passwords Warning Age", + "value": "Install pam_pwquality Package", "remarks": "rule_set_194" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_set_warn_age_existing", + "value": "package_pam_pwquality_installed", "remarks": "rule_set_194" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Existing Passwords Warning Age", + "value": "Install pam_pwquality Package", "remarks": "rule_set_194" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_libuserconf", + "value": "accounts_passwords_pam_faillock_deny", "remarks": "rule_set_195" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Password Hashing Algorithm in /etc/libuser.conf", + "value": "Lock Accounts After Failed Password Attempts", "remarks": "rule_set_195" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_libuserconf", + "value": "accounts_passwords_pam_faillock_deny", "remarks": "rule_set_195" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Password Hashing Algorithm in /etc/libuser.conf", + "value": "Lock Accounts After Failed Password Attempts", "remarks": "rule_set_195" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_logindefs", + "value": "accounts_passwords_pam_faillock_unlock_time", "remarks": "rule_set_196" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Password Hashing Algorithm in /etc/login.defs", + "value": "Set Lockout Time for Failed Password Attempts", "remarks": "rule_set_196" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_logindefs", + "value": "accounts_passwords_pam_faillock_unlock_time", "remarks": "rule_set_196" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Password Hashing Algorithm in /etc/login.defs", + "value": "Set Lockout Time for Failed Password Attempts", "remarks": "rule_set_196" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_disable_post_pw_expiration", + "value": "accounts_password_pam_difok", "remarks": "rule_set_197" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Account Expiration Following Inactivity", + "value": "Ensure PAM Enforces Password Requirements - Minimum Different Characters", "remarks": "rule_set_197" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_disable_post_pw_expiration", + "value": "accounts_password_pam_difok", "remarks": "rule_set_197" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Account Expiration Following Inactivity", + "value": "Ensure PAM Enforces Password Requirements - Minimum Different Characters", "remarks": "rule_set_197" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_set_post_pw_existing", + "value": "accounts_password_pam_minlen", "remarks": "rule_set_198" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set existing passwords a period of inactivity before they been locked", + "value": "Ensure PAM Enforces Password Requirements - Minimum Length", "remarks": "rule_set_198" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_set_post_pw_existing", + "value": "accounts_password_pam_minlen", "remarks": "rule_set_198" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set existing passwords a period of inactivity before they been locked", + "value": "Ensure PAM Enforces Password Requirements - Minimum Length", "remarks": "rule_set_198" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_last_change_is_in_past", + "value": "accounts_password_pam_minclass", "remarks": "rule_set_199" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure all users last password change date is in the past", + "value": "Ensure PAM Enforces Password Requirements - Minimum Different Categories", "remarks": "rule_set_199" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_last_change_is_in_past", + "value": "accounts_password_pam_minclass", "remarks": "rule_set_199" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure all users last password change date is in the past", + "value": "Ensure PAM Enforces Password Requirements - Minimum Different Categories", "remarks": "rule_set_199" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_no_uid_except_zero", + "value": "accounts_password_pam_maxrepeat", "remarks": "rule_set_200" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Only Root Has UID 0", + "value": "Set Password Maximum Consecutive Repeating Characters", "remarks": "rule_set_200" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_no_uid_except_zero", + "value": "accounts_password_pam_maxrepeat", "remarks": "rule_set_200" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Only Root Has UID 0", + "value": "Set Password Maximum Consecutive Repeating Characters", "remarks": "rule_set_200" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_root_gid_zero", + "value": "accounts_password_pam_dictcheck", "remarks": "rule_set_201" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Root Has A Primary GID 0", + "value": "Ensure PAM Enforces Password Requirements - Prevent the Use of Dictionary Words", "remarks": "rule_set_201" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_root_gid_zero", + "value": "accounts_password_pam_dictcheck", "remarks": "rule_set_201" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Root Has A Primary GID 0", + "value": "Ensure PAM Enforces Password Requirements - Prevent the Use of Dictionary Words", "remarks": "rule_set_201" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_root_password_configured", + "value": "accounts_password_pam_enforce_root", "remarks": "rule_set_202" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Authentication Required for Single User Mode", + "value": "Ensure PAM Enforces Password Requirements - Enforce for root User", "remarks": "rule_set_202" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_root_password_configured", + "value": "accounts_password_pam_enforce_root", "remarks": "rule_set_202" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Authentication Required for Single User Mode", + "value": "Ensure PAM Enforces Password Requirements - Enforce for root User", "remarks": "rule_set_202" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_root_path_dirs_no_write", + "value": "accounts_password_pam_pwhistory_remember_password_auth", "remarks": "rule_set_203" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that Root's Path Does Not Include World or Group-Writable Directories", + "value": "Limit Password Reuse: password-auth", "remarks": "rule_set_203" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_root_path_dirs_no_write", + "value": "accounts_password_pam_pwhistory_remember_password_auth", "remarks": "rule_set_203" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that Root's Path Does Not Include World or Group-Writable Directories", + "value": "Limit Password Reuse: password-auth", "remarks": "rule_set_203" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "root_path_no_dot", + "value": "accounts_password_pam_pwhistory_remember_system_auth", "remarks": "rule_set_204" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that Root's Path Does Not Include Relative Paths or Null Directories", + "value": "Limit Password Reuse: system-auth", "remarks": "rule_set_204" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "root_path_no_dot", + "value": "accounts_password_pam_pwhistory_remember_system_auth", "remarks": "rule_set_204" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that Root's Path Does Not Include Relative Paths or Null Directories", + "value": "Limit Password Reuse: system-auth", "remarks": "rule_set_204" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_password_auth_for_systemaccounts", + "value": "no_empty_passwords", "remarks": "rule_set_205" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that System Accounts Are Locked", + "value": "Prevent Login to Accounts With Empty Password", "remarks": "rule_set_205" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_password_auth_for_systemaccounts", + "value": "no_empty_passwords", "remarks": "rule_set_205" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that System Accounts Are Locked", + "value": "Prevent Login to Accounts With Empty Password", "remarks": "rule_set_205" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_shelllogin_for_systemaccounts", + "value": "set_password_hashing_algorithm_systemauth", "remarks": "rule_set_206" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that System Accounts Do Not Run a Shell Upon Login", + "value": "Set PAM''s Password Hashing Algorithm", "remarks": "rule_set_206" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_shelllogin_for_systemaccounts", + "value": "set_password_hashing_algorithm_systemauth", "remarks": "rule_set_206" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure that System Accounts Do Not Run a Shell Upon Login", + "value": "Set PAM''s Password Hashing Algorithm", "remarks": "rule_set_206" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_tmout", + "value": "set_password_hashing_algorithm_passwordauth", "remarks": "rule_set_207" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Interactive Session Timeout", + "value": "Set PAM''s Password Hashing Algorithm - password-auth", "remarks": "rule_set_207" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_tmout", + "value": "set_password_hashing_algorithm_passwordauth", "remarks": "rule_set_207" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Interactive Session Timeout", + "value": "Set PAM''s Password Hashing Algorithm - password-auth", "remarks": "rule_set_207" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_umask_etc_bashrc", + "value": "accounts_maximum_age_login_defs", "remarks": "rule_set_208" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure the Default Bash Umask is Set Correctly", + "value": "Set Password Maximum Age", "remarks": "rule_set_208" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_umask_etc_bashrc", + "value": "accounts_maximum_age_login_defs", "remarks": "rule_set_208" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure the Default Bash Umask is Set Correctly", + "value": "Set Password Maximum Age", "remarks": "rule_set_208" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_umask_etc_login_defs", + "value": "accounts_password_set_max_life_existing", "remarks": "rule_set_209" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure the Default Umask is Set Correctly in login.defs", + "value": "Set Existing Passwords Maximum Age", "remarks": "rule_set_209" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_umask_etc_login_defs", + "value": "accounts_password_set_max_life_existing", "remarks": "rule_set_209" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure the Default Umask is Set Correctly in login.defs", + "value": "Set Existing Passwords Maximum Age", "remarks": "rule_set_209" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_umask_etc_profile", + "value": "accounts_password_warn_age_login_defs", "remarks": "rule_set_210" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure the Default Umask is Set Correctly in /etc/profile", + "value": "Set Password Warning Age", "remarks": "rule_set_210" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_umask_etc_profile", + "value": "accounts_password_warn_age_login_defs", "remarks": "rule_set_210" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure the Default Umask is Set Correctly in /etc/profile", + "value": "Set Password Warning Age", "remarks": "rule_set_210" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_aide_installed", + "value": "accounts_password_set_warn_age_existing", "remarks": "rule_set_211" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install AIDE", + "value": "Set Existing Passwords Warning Age", "remarks": "rule_set_211" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_aide_installed", + "value": "accounts_password_set_warn_age_existing", "remarks": "rule_set_211" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install AIDE", + "value": "Set Existing Passwords Warning Age", "remarks": "rule_set_211" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "aide_build_database", + "value": "set_password_hashing_algorithm_libuserconf", "remarks": "rule_set_212" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Build and Test AIDE Database", + "value": "Set Password Hashing Algorithm in /etc/libuser.conf", "remarks": "rule_set_212" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "aide_build_database", + "value": "set_password_hashing_algorithm_libuserconf", "remarks": "rule_set_212" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Build and Test AIDE Database", + "value": "Set Password Hashing Algorithm in /etc/libuser.conf", "remarks": "rule_set_212" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "aide_periodic_cron_checking", + "value": "set_password_hashing_algorithm_logindefs", "remarks": "rule_set_213" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Periodic Execution of AIDE", + "value": "Set Password Hashing Algorithm in /etc/login.defs", "remarks": "rule_set_213" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "aide_periodic_cron_checking", + "value": "set_password_hashing_algorithm_logindefs", "remarks": "rule_set_213" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure Periodic Execution of AIDE", + "value": "Set Password Hashing Algorithm in /etc/login.defs", "remarks": "rule_set_213" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "aide_check_audit_tools", + "value": "account_disable_post_pw_expiration", "remarks": "rule_set_214" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure AIDE to Verify the Audit Tools", + "value": "Set Account Expiration Following Inactivity", "remarks": "rule_set_214" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "aide_check_audit_tools", + "value": "account_disable_post_pw_expiration", "remarks": "rule_set_214" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure AIDE to Verify the Audit Tools", + "value": "Set Account Expiration Following Inactivity", "remarks": "rule_set_214" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_systemd-journald_enabled", + "value": "accounts_set_post_pw_existing", "remarks": "rule_set_215" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable systemd-journald Service", + "value": "Set existing passwords a period of inactivity before they been locked", "remarks": "rule_set_215" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_systemd-journald_enabled", + "value": "accounts_set_post_pw_existing", "remarks": "rule_set_215" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable systemd-journald Service", + "value": "Set existing passwords a period of inactivity before they been locked", "remarks": "rule_set_215" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_systemd-journal-remote_installed", + "value": "accounts_password_last_change_is_in_past", "remarks": "rule_set_216" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install systemd-journal-remote Package", + "value": "Ensure all users last password change date is in the past", "remarks": "rule_set_216" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_systemd-journal-remote_installed", + "value": "accounts_password_last_change_is_in_past", "remarks": "rule_set_216" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Install systemd-journal-remote Package", + "value": "Ensure all users last password change date is in the past", "remarks": "rule_set_216" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "socket_systemd-journal-remote_disabled", + "value": "accounts_no_uid_except_zero", "remarks": "rule_set_217" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable systemd-journal-remote Socket", + "value": "Verify Only Root Has UID 0", "remarks": "rule_set_217" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "socket_systemd-journal-remote_disabled", + "value": "accounts_no_uid_except_zero", "remarks": "rule_set_217" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable systemd-journal-remote Socket", + "value": "Verify Only Root Has UID 0", "remarks": "rule_set_217" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_compress", + "value": "accounts_root_gid_zero", "remarks": "rule_set_218" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure journald is configured to compress large log files", + "value": "Verify Root Has A Primary GID 0", "remarks": "rule_set_218" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_compress", + "value": "accounts_root_gid_zero", "remarks": "rule_set_218" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure journald is configured to compress large log files", + "value": "Verify Root Has A Primary GID 0", "remarks": "rule_set_218" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_storage", + "value": "groups_no_zero_gid_except_root", "remarks": "rule_set_219" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure journald is configured to write log files to persistent disk", + "value": "Verify Only Group Root Has GID 0", "remarks": "rule_set_219" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_storage", + "value": "groups_no_zero_gid_except_root", "remarks": "rule_set_219" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure journald is configured to write log files to persistent disk", + "value": "Verify Only Group Root Has GID 0", "remarks": "rule_set_219" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "rsyslog_files_groupownership", + "value": "ensure_root_password_configured", "remarks": "rule_set_220" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Log Files Are Owned By Appropriate Group", + "value": "Ensure Authentication Required for Single User Mode", "remarks": "rule_set_220" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "rsyslog_files_groupownership", + "value": "ensure_root_password_configured", "remarks": "rule_set_220" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Log Files Are Owned By Appropriate Group", + "value": "Ensure Authentication Required for Single User Mode", "remarks": "rule_set_220" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "rsyslog_files_ownership", + "value": "accounts_root_path_dirs_no_write", "remarks": "rule_set_221" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Log Files Are Owned By Appropriate User", + "value": "Ensure that Root's Path Does Not Include World or Group-Writable Directories", "remarks": "rule_set_221" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "rsyslog_files_ownership", + "value": "accounts_root_path_dirs_no_write", "remarks": "rule_set_221" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Log Files Are Owned By Appropriate User", + "value": "Ensure that Root's Path Does Not Include World or Group-Writable Directories", "remarks": "rule_set_221" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "rsyslog_files_permissions", + "value": "root_path_no_dot", "remarks": "rule_set_222" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure System Log Files Have Correct Permissions", + "value": "Ensure that Root's Path Does Not Include Relative Paths or Null Directories", "remarks": "rule_set_222" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "rsyslog_files_permissions", + "value": "root_path_no_dot", "remarks": "rule_set_222" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure System Log Files Have Correct Permissions", + "value": "Ensure that Root's Path Does Not Include Relative Paths or Null Directories", "remarks": "rule_set_222" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_passwd", + "value": "accounts_umask_root", "remarks": "rule_set_223" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns passwd File", + "value": "Ensure the Root Bash Umask is Set Correctly", "remarks": "rule_set_223" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_passwd", + "value": "accounts_umask_root", "remarks": "rule_set_223" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns passwd File", + "value": "Ensure the Root Bash Umask is Set Correctly", "remarks": "rule_set_223" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_passwd", + "value": "no_password_auth_for_systemaccounts", "remarks": "rule_set_224" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns passwd File", + "value": "Ensure that System Accounts Are Locked", "remarks": "rule_set_224" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_passwd", + "value": "no_password_auth_for_systemaccounts", "remarks": "rule_set_224" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns passwd File", + "value": "Ensure that System Accounts Are Locked", "remarks": "rule_set_224" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_passwd", + "value": "no_shelllogin_for_systemaccounts", "remarks": "rule_set_225" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on passwd File", + "value": "Ensure that System Accounts Do Not Run a Shell Upon Login", "remarks": "rule_set_225" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_passwd", + "value": "no_shelllogin_for_systemaccounts", "remarks": "rule_set_225" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on passwd File", + "value": "Ensure that System Accounts Do Not Run a Shell Upon Login", "remarks": "rule_set_225" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_passwd", + "value": "accounts_tmout", "remarks": "rule_set_226" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns Backup passwd File", + "value": "Set Interactive Session Timeout", "remarks": "rule_set_226" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_passwd", + "value": "accounts_tmout", "remarks": "rule_set_226" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns Backup passwd File", + "value": "Set Interactive Session Timeout", "remarks": "rule_set_226" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_passwd", + "value": "accounts_umask_etc_bashrc", "remarks": "rule_set_227" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns Backup passwd File", + "value": "Ensure the Default Bash Umask is Set Correctly", "remarks": "rule_set_227" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_passwd", + "value": "accounts_umask_etc_bashrc", "remarks": "rule_set_227" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns Backup passwd File", + "value": "Ensure the Default Bash Umask is Set Correctly", "remarks": "rule_set_227" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_passwd", + "value": "accounts_umask_etc_login_defs", "remarks": "rule_set_228" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on Backup passwd File", + "value": "Ensure the Default Umask is Set Correctly in login.defs", "remarks": "rule_set_228" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_passwd", + "value": "accounts_umask_etc_login_defs", "remarks": "rule_set_228" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on Backup passwd File", + "value": "Ensure the Default Umask is Set Correctly in login.defs", "remarks": "rule_set_228" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_group", + "value": "accounts_umask_etc_profile", "remarks": "rule_set_229" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns group File", + "value": "Ensure the Default Umask is Set Correctly in /etc/profile", "remarks": "rule_set_229" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_group", + "value": "accounts_umask_etc_profile", "remarks": "rule_set_229" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns group File", + "value": "Ensure the Default Umask is Set Correctly in /etc/profile", "remarks": "rule_set_229" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_group", + "value": "package_aide_installed", "remarks": "rule_set_230" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns group File", + "value": "Install AIDE", "remarks": "rule_set_230" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_group", + "value": "package_aide_installed", "remarks": "rule_set_230" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns group File", + "value": "Install AIDE", "remarks": "rule_set_230" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_group", + "value": "aide_build_database", "remarks": "rule_set_231" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on group File", + "value": "Build and Test AIDE Database", "remarks": "rule_set_231" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_group", + "value": "aide_build_database", "remarks": "rule_set_231" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on group File", + "value": "Build and Test AIDE Database", "remarks": "rule_set_231" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_group", + "value": "aide_periodic_cron_checking", "remarks": "rule_set_232" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns Backup group File", + "value": "Configure Periodic Execution of AIDE", "remarks": "rule_set_232" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_group", + "value": "aide_periodic_cron_checking", "remarks": "rule_set_232" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns Backup group File", + "value": "Configure Periodic Execution of AIDE", "remarks": "rule_set_232" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_group", + "value": "aide_check_audit_tools", "remarks": "rule_set_233" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns Backup group File", + "value": "Configure AIDE to Verify the Audit Tools", "remarks": "rule_set_233" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_group", + "value": "aide_check_audit_tools", "remarks": "rule_set_233" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns Backup group File", + "value": "Configure AIDE to Verify the Audit Tools", "remarks": "rule_set_233" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_group", + "value": "service_systemd-journald_enabled", "remarks": "rule_set_234" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on Backup group File", + "value": "Enable systemd-journald Service", "remarks": "rule_set_234" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_group", + "value": "service_systemd-journald_enabled", "remarks": "rule_set_234" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on Backup group File", + "value": "Enable systemd-journald Service", "remarks": "rule_set_234" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_shadow", + "value": "journald_compress", "remarks": "rule_set_235" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns shadow File", + "value": "Ensure journald is configured to compress large log files", "remarks": "rule_set_235" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_shadow", + "value": "journald_compress", "remarks": "rule_set_235" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns shadow File", + "value": "Ensure journald is configured to compress large log files", "remarks": "rule_set_235" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_shadow", + "value": "journald_storage", "remarks": "rule_set_236" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns shadow File", + "value": "Ensure journald is configured to write log files to persistent disk", "remarks": "rule_set_236" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_shadow", + "value": "journald_storage", "remarks": "rule_set_236" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns shadow File", + "value": "Ensure journald is configured to write log files to persistent disk", "remarks": "rule_set_236" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_shadow", + "value": "package_systemd-journal-remote_installed", "remarks": "rule_set_237" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on shadow File", + "value": "Install systemd-journal-remote Package", "remarks": "rule_set_237" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_shadow", + "value": "package_systemd-journal-remote_installed", "remarks": "rule_set_237" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on shadow File", + "value": "Install systemd-journal-remote Package", "remarks": "rule_set_237" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_shadow", + "value": "socket_systemd-journal-remote_disabled", "remarks": "rule_set_238" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns Backup shadow File", + "value": "Disable systemd-journal-remote Socket", "remarks": "rule_set_238" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_shadow", + "value": "socket_systemd-journal-remote_disabled", "remarks": "rule_set_238" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns Backup shadow File", + "value": "Disable systemd-journal-remote Socket", "remarks": "rule_set_238" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_shadow", + "value": "rsyslog_files_groupownership", "remarks": "rule_set_239" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns Backup shadow File", + "value": "Ensure Log Files Are Owned By Appropriate Group", "remarks": "rule_set_239" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_shadow", + "value": "rsyslog_files_groupownership", "remarks": "rule_set_239" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns Backup shadow File", + "value": "Ensure Log Files Are Owned By Appropriate Group", "remarks": "rule_set_239" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_shadow", + "value": "rsyslog_files_ownership", "remarks": "rule_set_240" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on Backup shadow File", + "value": "Ensure Log Files Are Owned By Appropriate User", "remarks": "rule_set_240" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_shadow", + "value": "rsyslog_files_ownership", "remarks": "rule_set_240" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on Backup shadow File", + "value": "Ensure Log Files Are Owned By Appropriate User", "remarks": "rule_set_240" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_gshadow", + "value": "rsyslog_files_permissions", "remarks": "rule_set_241" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns gshadow File", + "value": "Ensure System Log Files Have Correct Permissions", "remarks": "rule_set_241" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_gshadow", + "value": "rsyslog_files_permissions", "remarks": "rule_set_241" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns gshadow File", + "value": "Ensure System Log Files Have Correct Permissions", "remarks": "rule_set_241" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_gshadow", + "value": "file_groupowner_etc_passwd", "remarks": "rule_set_242" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns gshadow File", + "value": "Verify Group Who Owns passwd File", "remarks": "rule_set_242" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_gshadow", + "value": "file_groupowner_etc_passwd", "remarks": "rule_set_242" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns gshadow File", + "value": "Verify Group Who Owns passwd File", "remarks": "rule_set_242" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_gshadow", + "value": "file_owner_etc_passwd", "remarks": "rule_set_243" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on gshadow File", + "value": "Verify User Who Owns passwd File", "remarks": "rule_set_243" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_gshadow", + "value": "file_owner_etc_passwd", "remarks": "rule_set_243" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on gshadow File", + "value": "Verify User Who Owns passwd File", "remarks": "rule_set_243" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_gshadow", + "value": "file_permissions_etc_passwd", "remarks": "rule_set_244" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns Backup gshadow File", + "value": "Verify Permissions on passwd File", "remarks": "rule_set_244" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_backup_etc_gshadow", + "value": "file_permissions_etc_passwd", "remarks": "rule_set_244" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns Backup gshadow File", + "value": "Verify Permissions on passwd File", "remarks": "rule_set_244" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_gshadow", + "value": "file_groupowner_backup_etc_passwd", "remarks": "rule_set_245" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns Backup gshadow File", + "value": "Verify Group Who Owns Backup passwd File", "remarks": "rule_set_245" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_backup_etc_gshadow", + "value": "file_groupowner_backup_etc_passwd", "remarks": "rule_set_245" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify User Who Owns Backup gshadow File", + "value": "Verify Group Who Owns Backup passwd File", "remarks": "rule_set_245" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_gshadow", + "value": "file_owner_backup_etc_passwd", "remarks": "rule_set_246" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on Backup gshadow File", + "value": "Verify User Who Owns Backup passwd File", "remarks": "rule_set_246" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_backup_etc_gshadow", + "value": "file_owner_backup_etc_passwd", "remarks": "rule_set_246" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on Backup gshadow File", + "value": "Verify User Who Owns Backup passwd File", "remarks": "rule_set_246" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_shells", + "value": "file_permissions_backup_etc_passwd", "remarks": "rule_set_247" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns /etc/shells File", + "value": "Verify Permissions on Backup passwd File", "remarks": "rule_set_247" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_shells", + "value": "file_permissions_backup_etc_passwd", "remarks": "rule_set_247" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Group Who Owns /etc/shells File", + "value": "Verify Permissions on Backup passwd File", "remarks": "rule_set_247" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_shells", + "value": "file_groupowner_etc_group", "remarks": "rule_set_248" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Who Owns /etc/shells File", + "value": "Verify Group Who Owns group File", "remarks": "rule_set_248" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_shells", + "value": "file_groupowner_etc_group", "remarks": "rule_set_248" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Who Owns /etc/shells File", + "value": "Verify Group Who Owns group File", "remarks": "rule_set_248" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_shells", + "value": "file_owner_etc_group", "remarks": "rule_set_249" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on /etc/shells File", + "value": "Verify User Who Owns group File", "remarks": "rule_set_249" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_shells", + "value": "file_owner_etc_group", "remarks": "rule_set_249" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions on /etc/shells File", + "value": "Verify User Who Owns group File", "remarks": "rule_set_249" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_etc_security_opasswd", + "value": "file_permissions_etc_group", "remarks": "rule_set_250" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions and Ownership of Old Passwords File", + "value": "Verify Permissions on group File", "remarks": "rule_set_250" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_etc_security_opasswd", + "value": "file_permissions_etc_group", "remarks": "rule_set_250" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify Permissions and Ownership of Old Passwords File", + "value": "Verify Permissions on group File", "remarks": "rule_set_250" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_unauthorized_world_writable", + "value": "file_groupowner_backup_etc_group", "remarks": "rule_set_251" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure No World-Writable Files Exist", + "value": "Verify Group Who Owns Backup group File", "remarks": "rule_set_251" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_unauthorized_world_writable", + "value": "file_groupowner_backup_etc_group", "remarks": "rule_set_251" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure No World-Writable Files Exist", + "value": "Verify Group Who Owns Backup group File", "remarks": "rule_set_251" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dir_perms_world_writable_sticky_bits", + "value": "file_owner_backup_etc_group", "remarks": "rule_set_252" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify that All World-Writable Directories Have Sticky Bits Set", + "value": "Verify User Who Owns Backup group File", "remarks": "rule_set_252" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dir_perms_world_writable_sticky_bits", + "value": "file_owner_backup_etc_group", "remarks": "rule_set_252" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify that All World-Writable Directories Have Sticky Bits Set", + "value": "Verify User Who Owns Backup group File", "remarks": "rule_set_252" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_files_unowned_by_user", + "value": "file_permissions_backup_etc_group", "remarks": "rule_set_253" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Files Are Owned by a User", + "value": "Verify Permissions on Backup group File", "remarks": "rule_set_253" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_files_unowned_by_user", + "value": "file_permissions_backup_etc_group", "remarks": "rule_set_253" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Files Are Owned by a User", + "value": "Verify Permissions on Backup group File", "remarks": "rule_set_253" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_ungroupowned", + "value": "file_owner_etc_shadow", "remarks": "rule_set_254" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Files Are Owned by a Group", + "value": "Verify User Who Owns shadow File", "remarks": "rule_set_254" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_ungroupowned", + "value": "file_owner_etc_shadow", "remarks": "rule_set_254" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Files Are Owned by a Group", + "value": "Verify User Who Owns shadow File", "remarks": "rule_set_254" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_all_shadowed", + "value": "file_groupowner_etc_shadow", "remarks": "rule_set_255" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify All Account Password Hashes are Shadowed", + "value": "Verify Group Who Owns shadow File", "remarks": "rule_set_255" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_all_shadowed", + "value": "file_groupowner_etc_shadow", "remarks": "rule_set_255" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify All Account Password Hashes are Shadowed", + "value": "Verify Group Who Owns shadow File", "remarks": "rule_set_255" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_empty_passwords_etc_shadow", + "value": "file_permissions_etc_shadow", "remarks": "rule_set_256" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure There Are No Accounts With Blank or Null Passwords", + "value": "Verify Permissions on shadow File", "remarks": "rule_set_256" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_empty_passwords_etc_shadow", + "value": "file_permissions_etc_shadow", "remarks": "rule_set_256" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure There Are No Accounts With Blank or Null Passwords", + "value": "Verify Permissions on shadow File", "remarks": "rule_set_256" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "gid_passwd_group_same", + "value": "file_groupowner_backup_etc_shadow", "remarks": "rule_set_257" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "All GIDs referenced in /etc/passwd must be defined in /etc/group", + "value": "Verify User Who Owns Backup shadow File", "remarks": "rule_set_257" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "gid_passwd_group_same", + "value": "file_groupowner_backup_etc_shadow", "remarks": "rule_set_257" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "All GIDs referenced in /etc/passwd must be defined in /etc/group", + "value": "Verify User Who Owns Backup shadow File", "remarks": "rule_set_257" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_unique_id", + "value": "file_owner_backup_etc_shadow", "remarks": "rule_set_258" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Accounts on the System Have Unique User IDs", + "value": "Verify Group Who Owns Backup shadow File", "remarks": "rule_set_258" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_unique_id", + "value": "file_owner_backup_etc_shadow", "remarks": "rule_set_258" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Accounts on the System Have Unique User IDs", + "value": "Verify Group Who Owns Backup shadow File", "remarks": "rule_set_258" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "group_unique_id", + "value": "file_permissions_backup_etc_shadow", "remarks": "rule_set_259" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Groups on the System Have Unique Group ID", + "value": "Verify Permissions on Backup shadow File", "remarks": "rule_set_259" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "group_unique_id", + "value": "file_permissions_backup_etc_shadow", "remarks": "rule_set_259" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Groups on the System Have Unique Group ID", + "value": "Verify Permissions on Backup shadow File", "remarks": "rule_set_259" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_unique_name", + "value": "file_groupowner_etc_gshadow", "remarks": "rule_set_260" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Accounts on the System Have Unique Names", + "value": "Verify Group Who Owns gshadow File", "remarks": "rule_set_260" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_unique_name", + "value": "file_groupowner_etc_gshadow", "remarks": "rule_set_260" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Accounts on the System Have Unique Names", + "value": "Verify Group Who Owns gshadow File", "remarks": "rule_set_260" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "group_unique_name", + "value": "file_owner_etc_gshadow", "remarks": "rule_set_261" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Groups on the System Have Unique Group Names", + "value": "Verify User Who Owns gshadow File", "remarks": "rule_set_261" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "group_unique_name", + "value": "file_owner_etc_gshadow", "remarks": "rule_set_261" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All Groups on the System Have Unique Group Names", + "value": "Verify User Who Owns gshadow File", "remarks": "rule_set_261" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_user_interactive_home_directory_exists", + "value": "file_permissions_etc_gshadow", "remarks": "rule_set_262" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "All Interactive Users Home Directories Must Exist", + "value": "Verify Permissions on gshadow File", "remarks": "rule_set_262" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_user_interactive_home_directory_exists", + "value": "file_permissions_etc_gshadow", "remarks": "rule_set_262" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "All Interactive Users Home Directories Must Exist", + "value": "Verify Permissions on gshadow File", "remarks": "rule_set_262" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_home_directories", + "value": "file_groupowner_backup_etc_gshadow", "remarks": "rule_set_263" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "All Interactive User Home Directories Must Be Owned By The Primary User", + "value": "Verify Group Who Owns Backup gshadow File", "remarks": "rule_set_263" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_home_directories", + "value": "file_groupowner_backup_etc_gshadow", "remarks": "rule_set_263" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "All Interactive User Home Directories Must Be Owned By The Primary User", + "value": "Verify Group Who Owns Backup gshadow File", "remarks": "rule_set_263" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_home_directories", + "value": "file_owner_backup_etc_gshadow", "remarks": "rule_set_264" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "All Interactive User Home Directories Must Have mode 0750 Or Less Permissive", + "value": "Verify User Who Owns Backup gshadow File", "remarks": "rule_set_264" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_home_directories", + "value": "file_owner_backup_etc_gshadow", "remarks": "rule_set_264" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "All Interactive User Home Directories Must Have mode 0750 Or Less Permissive", + "value": "Verify User Who Owns Backup gshadow File", "remarks": "rule_set_264" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_user_dot_group_ownership", + "value": "file_permissions_backup_etc_gshadow", "remarks": "rule_set_265" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "User Initialization Files Must Be Group-Owned By The Primary Group", + "value": "Verify Permissions on Backup gshadow File", "remarks": "rule_set_265" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_user_dot_group_ownership", + "value": "file_permissions_backup_etc_gshadow", "remarks": "rule_set_265" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "User Initialization Files Must Be Group-Owned By The Primary Group", + "value": "Verify Permissions on Backup gshadow File", "remarks": "rule_set_265" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_user_dot_user_ownership", + "value": "file_groupowner_etc_shells", "remarks": "rule_set_266" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "User Initialization Files Must Be Owned By the Primary User", + "value": "Verify Group Who Owns /etc/shells File", "remarks": "rule_set_266" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_user_dot_user_ownership", + "value": "file_groupowner_etc_shells", "remarks": "rule_set_266" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "User Initialization Files Must Be Owned By the Primary User", + "value": "Verify Group Who Owns /etc/shells File", "remarks": "rule_set_266" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_user_dot_no_world_writable_programs", + "value": "file_owner_etc_shells", "remarks": "rule_set_267" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "User Initialization Files Must Not Run World-Writable Programs", + "value": "Verify Who Owns /etc/shells File", "remarks": "rule_set_267" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_user_dot_no_world_writable_programs", + "value": "file_owner_etc_shells", "remarks": "rule_set_267" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "User Initialization Files Must Not Run World-Writable Programs", + "value": "Verify Who Owns /etc/shells File", "remarks": "rule_set_267" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permission_user_init_files", + "value": "file_permissions_etc_shells", "remarks": "rule_set_268" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All User Initialization Files Have Mode 0740 Or Less Permissive", + "value": "Verify Permissions on /etc/shells File", "remarks": "rule_set_268" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permission_user_init_files", + "value": "file_permissions_etc_shells", "remarks": "rule_set_268" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure All User Initialization Files Have Mode 0740 Or Less Permissive", + "value": "Verify Permissions on /etc/shells File", "remarks": "rule_set_268" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_forward_files", + "value": "file_etc_security_opasswd", "remarks": "rule_set_269" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify No .forward Files Exist", + "value": "Verify Permissions and Ownership of Old Passwords File", "remarks": "rule_set_269" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_forward_files", + "value": "file_etc_security_opasswd", "remarks": "rule_set_269" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify No .forward Files Exist", + "value": "Verify Permissions and Ownership of Old Passwords File", "remarks": "rule_set_269" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_netrc_files", + "value": "file_permissions_unauthorized_world_writable", "remarks": "rule_set_270" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify No netrc Files Exist", + "value": "Ensure No World-Writable Files Exist", "remarks": "rule_set_270" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_netrc_files", + "value": "file_permissions_unauthorized_world_writable", "remarks": "rule_set_270" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify No netrc Files Exist", + "value": "Ensure No World-Writable Files Exist", "remarks": "rule_set_270" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_squashfs_disabled", + "value": "dir_perms_world_writable_sticky_bits", "remarks": "rule_set_271" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Mounting of squashfs", + "value": "Verify that All World-Writable Directories Have Sticky Bits Set", "remarks": "rule_set_271" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_squashfs_disabled", + "value": "dir_perms_world_writable_sticky_bits", "remarks": "rule_set_271" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Mounting of squashfs", + "value": "Verify that All World-Writable Directories Have Sticky Bits Set", "remarks": "rule_set_271" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_udf_disabled", + "value": "no_files_unowned_by_user", "remarks": "rule_set_272" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Mounting of udf", + "value": "Ensure All Files Are Owned by a User", "remarks": "rule_set_272" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_udf_disabled", + "value": "no_files_unowned_by_user", "remarks": "rule_set_272" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Mounting of udf", + "value": "Ensure All Files Are Owned by a User", "remarks": "rule_set_272" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_usb-storage_disabled", + "value": "file_permissions_ungroupowned", "remarks": "rule_set_273" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Modprobe Loading of USB Storage Driver", + "value": "Ensure All Files Are Owned by a Group", "remarks": "rule_set_273" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_usb-storage_disabled", + "value": "file_permissions_ungroupowned", "remarks": "rule_set_273" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Modprobe Loading of USB Storage Driver", + "value": "Ensure All Files Are Owned by a Group", "remarks": "rule_set_273" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_home", + "value": "accounts_password_all_shadowed", "remarks": "rule_set_274" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /home Located On Separate Partition", + "value": "Verify All Account Password Hashes are Shadowed", "remarks": "rule_set_274" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_home", + "value": "accounts_password_all_shadowed", "remarks": "rule_set_274" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /home Located On Separate Partition", + "value": "Verify All Account Password Hashes are Shadowed", "remarks": "rule_set_274" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_var", + "value": "no_empty_passwords_etc_shadow", "remarks": "rule_set_275" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /var Located On Separate Partition", + "value": "Ensure There Are No Accounts With Blank or Null Passwords", "remarks": "rule_set_275" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_var", + "value": "no_empty_passwords_etc_shadow", "remarks": "rule_set_275" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /var Located On Separate Partition", + "value": "Ensure There Are No Accounts With Blank or Null Passwords", "remarks": "rule_set_275" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_var_tmp", + "value": "gid_passwd_group_same", "remarks": "rule_set_276" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /var/tmp Located On Separate Partition", + "value": "All GIDs referenced in /etc/passwd must be defined in /etc/group", "remarks": "rule_set_276" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_var_tmp", + "value": "gid_passwd_group_same", "remarks": "rule_set_276" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /var/tmp Located On Separate Partition", + "value": "All GIDs referenced in /etc/passwd must be defined in /etc/group", "remarks": "rule_set_276" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_var_log", + "value": "account_unique_id", "remarks": "rule_set_277" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /var/log Located On Separate Partition", + "value": "Ensure All Accounts on the System Have Unique User IDs", "remarks": "rule_set_277" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_var_log", + "value": "account_unique_id", "remarks": "rule_set_277" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /var/log Located On Separate Partition", + "value": "Ensure All Accounts on the System Have Unique User IDs", "remarks": "rule_set_277" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_var_log_audit", + "value": "group_unique_id", "remarks": "rule_set_278" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /var/log/audit Located On Separate Partition", + "value": "Ensure All Groups on the System Have Unique Group ID", "remarks": "rule_set_278" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_var_log_audit", + "value": "group_unique_id", "remarks": "rule_set_278" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure /var/log/audit Located On Separate Partition", + "value": "Ensure All Groups on the System Have Unique Group ID", "remarks": "rule_set_278" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "selinux_state", + "value": "account_unique_name", "remarks": "rule_set_279" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure SELinux State is Enforcing", + "value": "Ensure All Accounts on the System Have Unique Names", "remarks": "rule_set_279" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "selinux_state", + "value": "account_unique_name", "remarks": "rule_set_279" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure SELinux State is Enforcing", + "value": "Ensure All Accounts on the System Have Unique Names", "remarks": "rule_set_279" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_automount", + "value": "group_unique_name", "remarks": "rule_set_280" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable GNOME3 Automounting", + "value": "Ensure All Groups on the System Have Unique Group Names", "remarks": "rule_set_280" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_automount", + "value": "group_unique_name", "remarks": "rule_set_280" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable GNOME3 Automounting", + "value": "Ensure All Groups on the System Have Unique Group Names", "remarks": "rule_set_280" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_automount_open", + "value": "accounts_user_interactive_home_directory_exists", "remarks": "rule_set_281" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable GNOME3 Automount Opening", + "value": "All Interactive Users Home Directories Must Exist", "remarks": "rule_set_281" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_automount_open", + "value": "accounts_user_interactive_home_directory_exists", "remarks": "rule_set_281" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable GNOME3 Automount Opening", + "value": "All Interactive Users Home Directories Must Exist", "remarks": "rule_set_281" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_autofs_disabled", + "value": "file_ownership_home_directories", "remarks": "rule_set_282" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable the Automounter", + "value": "All Interactive User Home Directories Must Be Owned By The Primary User", "remarks": "rule_set_282" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_autofs_disabled", + "value": "file_ownership_home_directories", "remarks": "rule_set_282" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable the Automounter", + "value": "All Interactive User Home Directories Must Be Owned By The Primary User", "remarks": "rule_set_282" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_avahi-daemon_disabled", + "value": "file_permissions_home_directories", "remarks": "rule_set_283" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Avahi Server Software", + "value": "All Interactive User Home Directories Must Have mode 0750 Or Less Permissive", "remarks": "rule_set_283" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_avahi-daemon_disabled", + "value": "file_permissions_home_directories", "remarks": "rule_set_283" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Avahi Server Software", + "value": "All Interactive User Home Directories Must Have mode 0750 Or Less Permissive", "remarks": "rule_set_283" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_openldap-clients_removed", + "value": "accounts_user_dot_group_ownership", "remarks": "rule_set_284" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure LDAP client is not installed", + "value": "User Initialization Files Must Be Group-Owned By The Primary Group", "remarks": "rule_set_284" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_openldap-clients_removed", + "value": "accounts_user_dot_group_ownership", "remarks": "rule_set_284" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure LDAP client is not installed", + "value": "User Initialization Files Must Be Group-Owned By The Primary Group", "remarks": "rule_set_284" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_bluetooth_disabled", + "value": "accounts_user_dot_user_ownership", "remarks": "rule_set_285" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Bluetooth Service", + "value": "User Initialization Files Must Be Owned By the Primary User", "remarks": "rule_set_285" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_bluetooth_disabled", + "value": "accounts_user_dot_user_ownership", "remarks": "rule_set_285" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable Bluetooth Service", + "value": "User Initialization Files Must Be Owned By the Primary User", "remarks": "rule_set_285" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_tipc_disabled", + "value": "accounts_user_dot_no_world_writable_programs", "remarks": "rule_set_286" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable TIPC Support", + "value": "User Initialization Files Must Not Run World-Writable Programs", "remarks": "rule_set_286" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_tipc_disabled", + "value": "accounts_user_dot_no_world_writable_programs", "remarks": "rule_set_286" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable TIPC Support", + "value": "User Initialization Files Must Not Run World-Writable Programs", "remarks": "rule_set_286" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_sctp_disabled", + "value": "file_permission_user_init_files", "remarks": "rule_set_287" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable SCTP Support", + "value": "Ensure All User Initialization Files Have Mode 0740 Or Less Permissive", "remarks": "rule_set_287" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_sctp_disabled", + "value": "file_permission_user_init_files", "remarks": "rule_set_287" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Disable SCTP Support", + "value": "Ensure All User Initialization Files Have Mode 0740 Or Less Permissive", "remarks": "rule_set_287" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_require_authentication", + "value": "no_forward_files", "remarks": "rule_set_288" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Users Re-Authenticate for Privilege Escalation - sudo", + "value": "Verify No .forward Files Exist", "remarks": "rule_set_288" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_require_authentication", + "value": "no_forward_files", "remarks": "rule_set_288" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure Users Re-Authenticate for Privilege Escalation - sudo", + "value": "Verify No .forward Files Exist", "remarks": "rule_set_288" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_deny_root", + "value": "no_netrc_files", "remarks": "rule_set_289" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure the root Account for Failed Password Attempts", + "value": "Verify No netrc Files Exist", "remarks": "rule_set_289" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_deny_root", + "value": "no_netrc_files", "remarks": "rule_set_289" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure the root Account for Failed Password Attempts", + "value": "Verify No netrc Files Exist", "remarks": "rule_set_289" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_minimum_age_login_defs", + "value": "kernel_module_overlayfs_disabled", "remarks": "rule_set_290" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Password Minimum Age", + "value": "Ensure overlayfs kernel module is not available", "remarks": "rule_set_290" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_minimum_age_login_defs", + "value": "kernel_module_overlayfs_disabled", "remarks": "rule_set_290" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Password Minimum Age", + "value": "Ensure overlayfs kernel module is not available", "remarks": "rule_set_290" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_set_min_life_existing", + "value": "kernel_module_squashfs_disabled", "remarks": "rule_set_291" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Existing Passwords Minimum Age", + "value": "Disable Mounting of squashfs", "remarks": "rule_set_291" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_set_min_life_existing", + "value": "kernel_module_squashfs_disabled", "remarks": "rule_set_291" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Set Existing Passwords Minimum Age", + "value": "Disable Mounting of squashfs", "remarks": "rule_set_291" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_audit_installed", + "value": "kernel_module_udf_disabled", "remarks": "rule_set_292" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure the audit Subsystem is Installed", + "value": "Disable Mounting of udf", "remarks": "rule_set_292" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_audit_installed", + "value": "kernel_module_udf_disabled", "remarks": "rule_set_292" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure the audit Subsystem is Installed", + "value": "Disable Mounting of udf", "remarks": "rule_set_292" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_audit-libs_installed", + "value": "kernel_module_firewire-core_disabled", "remarks": "rule_set_293" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure the audit-libs package as a part of audit Subsystem is Installed", + "value": "Disable IEEE 1394 (FireWire) Support", "remarks": "rule_set_293" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_audit-libs_installed", + "value": "kernel_module_firewire-core_disabled", "remarks": "rule_set_293" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure the audit-libs package as a part of audit Subsystem is Installed", + "value": "Disable IEEE 1394 (FireWire) Support", "remarks": "rule_set_293" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "grub2_audit_argument", + "value": "kernel_module_usb-storage_disabled", "remarks": "rule_set_294" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Auditing for Processes Which Start Prior to the Audit Daemon", + "value": "Disable Modprobe Loading of USB Storage Driver", "remarks": "rule_set_294" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "grub2_audit_argument", + "value": "kernel_module_usb-storage_disabled", "remarks": "rule_set_294" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable Auditing for Processes Which Start Prior to the Audit Daemon", + "value": "Disable Modprobe Loading of USB Storage Driver", "remarks": "rule_set_294" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "grub2_audit_backlog_limit_argument", + "value": "partition_for_home", "remarks": "rule_set_295" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Extend Audit Backlog Limit for the Audit Daemon", + "value": "Ensure /home Located On Separate Partition", "remarks": "rule_set_295" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "grub2_audit_backlog_limit_argument", + "value": "partition_for_home", "remarks": "rule_set_295" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Extend Audit Backlog Limit for the Audit Daemon", + "value": "Ensure /home Located On Separate Partition", "remarks": "rule_set_295" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_auditd_enabled", + "value": "partition_for_var", "remarks": "rule_set_296" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable auditd Service", + "value": "Ensure /var Located On Separate Partition", "remarks": "rule_set_296" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_auditd_enabled", + "value": "partition_for_var", "remarks": "rule_set_296" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Enable auditd Service", + "value": "Ensure /var Located On Separate Partition", "remarks": "rule_set_296" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_retention_max_log_file", + "value": "partition_for_var_tmp", "remarks": "rule_set_297" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure auditd Max Log File Size", + "value": "Ensure /var/tmp Located On Separate Partition", "remarks": "rule_set_297" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_retention_max_log_file", + "value": "partition_for_var_tmp", "remarks": "rule_set_297" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure auditd Max Log File Size", + "value": "Ensure /var/tmp Located On Separate Partition", "remarks": "rule_set_297" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_retention_max_log_file_action", + "value": "partition_for_var_log", "remarks": "rule_set_298" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure auditd max_log_file_action Upon Reaching Maximum Log Size", + "value": "Ensure /var/log Located On Separate Partition", "remarks": "rule_set_298" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_retention_max_log_file_action", + "value": "partition_for_var_log", "remarks": "rule_set_298" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure auditd max_log_file_action Upon Reaching Maximum Log Size", + "value": "Ensure /var/log Located On Separate Partition", "remarks": "rule_set_298" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_disk_error_action", + "value": "partition_for_var_log_audit", "remarks": "rule_set_299" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure auditd Disk Error Action on Disk Error", + "value": "Ensure /var/log/audit Located On Separate Partition", "remarks": "rule_set_299" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_disk_error_action", + "value": "partition_for_var_log_audit", "remarks": "rule_set_299" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure auditd Disk Error Action on Disk Error", + "value": "Ensure /var/log/audit Located On Separate Partition", "remarks": "rule_set_299" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_disk_full_action", + "value": "selinux_state", "remarks": "rule_set_300" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure auditd Disk Full Action when Disk Space Is Full", + "value": "Ensure SELinux State is Enforcing", "remarks": "rule_set_300" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_disk_full_action", + "value": "selinux_state", "remarks": "rule_set_300" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure auditd Disk Full Action when Disk Space Is Full", + "value": "Ensure SELinux State is Enforcing", "remarks": "rule_set_300" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_retention_action_mail_acct", + "value": "sysctl_fs_protected_symlinks", "remarks": "rule_set_301" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure auditd mail_acct Action on Low Disk Space", + "value": "Enable Kernel Parameter to Enforce DAC on Symlinks", "remarks": "rule_set_301" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_retention_action_mail_acct", + "value": "sysctl_fs_protected_symlinks", "remarks": "rule_set_301" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure auditd mail_acct Action on Low Disk Space", + "value": "Enable Kernel Parameter to Enforce DAC on Symlinks", "remarks": "rule_set_301" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_retention_admin_space_left_action", + "value": "dconf_gnome_disable_automount", "remarks": "rule_set_302" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure auditd admin_space_left Action on Low Disk Space", + "value": "Disable GNOME3 Automounting", "remarks": "rule_set_302" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_retention_admin_space_left_action", + "value": "dconf_gnome_disable_automount", "remarks": "rule_set_302" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure auditd admin_space_left Action on Low Disk Space", + "value": "Disable GNOME3 Automounting", "remarks": "rule_set_302" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_retention_space_left_action", + "value": "dconf_gnome_disable_automount_open", "remarks": "rule_set_303" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure auditd space_left Action on Low Disk Space", + "value": "Disable GNOME3 Automount Opening", "remarks": "rule_set_303" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_retention_space_left_action", + "value": "dconf_gnome_disable_automount_open", "remarks": "rule_set_303" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Configure auditd space_left Action on Low Disk Space", + "value": "Disable GNOME3 Automount Opening", "remarks": "rule_set_303" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_sysadmin_actions", + "value": "service_autofs_disabled", "remarks": "rule_set_304" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects System Administrator Actions", + "value": "Disable the Automounter", "remarks": "rule_set_304" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_sysadmin_actions", + "value": "service_autofs_disabled", "remarks": "rule_set_304" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects System Administrator Actions", + "value": "Disable the Automounter", "remarks": "rule_set_304" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_suid_auid_privilege_function", + "value": "service_avahi-daemon_disabled", "remarks": "rule_set_305" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events When Executables Are Run As Another User", + "value": "Disable Avahi Server Software", "remarks": "rule_set_305" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_suid_auid_privilege_function", + "value": "service_avahi-daemon_disabled", "remarks": "rule_set_305" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events When Executables Are Run As Another User", + "value": "Disable Avahi Server Software", "remarks": "rule_set_305" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_sudo_log_events", + "value": "service_cockpit_disabled", "remarks": "rule_set_306" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Attempts to perform maintenance activities", + "value": "Disable Cockpit Management Server", "remarks": "rule_set_306" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_sudo_log_events", + "value": "service_cockpit_disabled", "remarks": "rule_set_306" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Attempts to perform maintenance activities", + "value": "Disable Cockpit Management Server", "remarks": "rule_set_306" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_time_adjtimex", + "value": "package_openldap-clients_removed", "remarks": "rule_set_307" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record attempts to alter time through adjtimex", + "value": "Ensure LDAP client is not installed", "remarks": "rule_set_307" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_time_adjtimex", + "value": "package_openldap-clients_removed", "remarks": "rule_set_307" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record attempts to alter time through adjtimex", + "value": "Ensure LDAP client is not installed", "remarks": "rule_set_307" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_time_settimeofday", + "value": "service_bluetooth_disabled", "remarks": "rule_set_308" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record attempts to alter time through settimeofday", + "value": "Disable Bluetooth Service", "remarks": "rule_set_308" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_time_settimeofday", + "value": "service_bluetooth_disabled", "remarks": "rule_set_308" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record attempts to alter time through settimeofday", + "value": "Disable Bluetooth Service", "remarks": "rule_set_308" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_time_clock_settime", + "value": "accounts_passwords_pam_faillock_deny_root", "remarks": "rule_set_309" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Attempts to Alter Time Through clock_settime", + "value": "Configure the root Account for Failed Password Attempts", "remarks": "rule_set_309" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_time_clock_settime", + "value": "accounts_passwords_pam_faillock_deny_root", "remarks": "rule_set_309" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Attempts to Alter Time Through clock_settime", + "value": "Configure the root Account for Failed Password Attempts", "remarks": "rule_set_309" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_time_watch_localtime", + "value": "accounts_minimum_age_login_defs", "remarks": "rule_set_310" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Attempts to Alter the localtime File", + "value": "Set Password Minimum Age", "remarks": "rule_set_310" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_time_watch_localtime", + "value": "accounts_minimum_age_login_defs", "remarks": "rule_set_310" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Attempts to Alter the localtime File", + "value": "Set Password Minimum Age", "remarks": "rule_set_310" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_networkconfig_modification", + "value": "accounts_password_set_min_life_existing", "remarks": "rule_set_311" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Network Environment", + "value": "Set Existing Passwords Minimum Age", "remarks": "rule_set_311" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_networkconfig_modification", + "value": "accounts_password_set_min_life_existing", "remarks": "rule_set_311" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Network Environment", + "value": "Set Existing Passwords Minimum Age", "remarks": "rule_set_311" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_networkconfig_modification_network_scripts", + "value": "no_nologin_in_shells", "remarks": "rule_set_312" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Network Environment", + "value": "Ensure nologin Shell is Not Listed in /etc/shells", "remarks": "rule_set_312" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_networkconfig_modification_network_scripts", + "value": "no_nologin_in_shells", "remarks": "rule_set_312" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Network Environment", + "value": "Ensure nologin Shell is Not Listed in /etc/shells", "remarks": "rule_set_312" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_privileged_commands", + "value": "package_audit_installed", "remarks": "rule_set_313" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on the Use of Privileged Commands", + "value": "Ensure the audit Subsystem is Installed", "remarks": "rule_set_313" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_privileged_commands", + "value": "package_audit_installed", "remarks": "rule_set_313" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on the Use of Privileged Commands", + "value": "Ensure the audit Subsystem is Installed", "remarks": "rule_set_313" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_unsuccessful_file_modification_creat", + "value": "package_audit-libs_installed", "remarks": "rule_set_314" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Unsuccessful Access Attempts to Files - creat", + "value": "Ensure the audit-libs package as a part of audit Subsystem is Installed", "remarks": "rule_set_314" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_unsuccessful_file_modification_creat", + "value": "package_audit-libs_installed", "remarks": "rule_set_314" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Unsuccessful Access Attempts to Files - creat", + "value": "Ensure the audit-libs package as a part of audit Subsystem is Installed", "remarks": "rule_set_314" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_unsuccessful_file_modification_ftruncate", + "value": "grub2_audit_argument", "remarks": "rule_set_315" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Unsuccessful Access Attempts to Files - ftruncate", + "value": "Enable Auditing for Processes Which Start Prior to the Audit Daemon", "remarks": "rule_set_315" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_unsuccessful_file_modification_ftruncate", + "value": "grub2_audit_argument", "remarks": "rule_set_315" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Unsuccessful Access Attempts to Files - ftruncate", + "value": "Enable Auditing for Processes Which Start Prior to the Audit Daemon", "remarks": "rule_set_315" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_unsuccessful_file_modification_open", + "value": "grub2_audit_backlog_limit_argument", "remarks": "rule_set_316" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Unsuccessful Access Attempts to Files - open", + "value": "Extend Audit Backlog Limit for the Audit Daemon", "remarks": "rule_set_316" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_unsuccessful_file_modification_open", + "value": "grub2_audit_backlog_limit_argument", "remarks": "rule_set_316" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Unsuccessful Access Attempts to Files - open", + "value": "Extend Audit Backlog Limit for the Audit Daemon", "remarks": "rule_set_316" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_unsuccessful_file_modification_openat", + "value": "service_auditd_enabled", "remarks": "rule_set_317" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Unsuccessful Access Attempts to Files - openat", + "value": "Enable auditd Service", "remarks": "rule_set_317" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_unsuccessful_file_modification_openat", + "value": "service_auditd_enabled", "remarks": "rule_set_317" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Unsuccessful Access Attempts to Files - openat", + "value": "Enable auditd Service", "remarks": "rule_set_317" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_unsuccessful_file_modification_truncate", + "value": "auditd_data_retention_max_log_file", "remarks": "rule_set_318" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Unsuccessful Access Attempts to Files - truncate", + "value": "Configure auditd Max Log File Size", "remarks": "rule_set_318" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_unsuccessful_file_modification_truncate", + "value": "auditd_data_retention_max_log_file", "remarks": "rule_set_318" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Unsuccessful Access Attempts to Files - truncate", + "value": "Configure auditd Max Log File Size", "remarks": "rule_set_318" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_group", + "value": "auditd_data_retention_max_log_file_action", "remarks": "rule_set_319" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify User/Group Information - /etc/group", + "value": "Configure auditd max_log_file_action Upon Reaching Maximum Log Size", "remarks": "rule_set_319" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_group", + "value": "auditd_data_retention_max_log_file_action", "remarks": "rule_set_319" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify User/Group Information - /etc/group", + "value": "Configure auditd max_log_file_action Upon Reaching Maximum Log Size", "remarks": "rule_set_319" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_gshadow", + "value": "auditd_data_disk_error_action", "remarks": "rule_set_320" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify User/Group Information - /etc/gshadow", + "value": "Configure auditd Disk Error Action on Disk Error", "remarks": "rule_set_320" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_gshadow", + "value": "auditd_data_disk_error_action", "remarks": "rule_set_320" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify User/Group Information - /etc/gshadow", + "value": "Configure auditd Disk Error Action on Disk Error", "remarks": "rule_set_320" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_opasswd", + "value": "auditd_data_disk_full_action", "remarks": "rule_set_321" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify User/Group Information - /etc/security/opasswd", + "value": "Configure auditd Disk Full Action when Disk Space Is Full", "remarks": "rule_set_321" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_opasswd", + "value": "auditd_data_disk_full_action", "remarks": "rule_set_321" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify User/Group Information - /etc/security/opasswd", + "value": "Configure auditd Disk Full Action when Disk Space Is Full", "remarks": "rule_set_321" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_passwd", + "value": "auditd_data_retention_action_mail_acct", "remarks": "rule_set_322" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify User/Group Information - /etc/passwd", + "value": "Configure auditd mail_acct Action on Low Disk Space", "remarks": "rule_set_322" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_passwd", + "value": "auditd_data_retention_action_mail_acct", "remarks": "rule_set_322" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify User/Group Information - /etc/passwd", + "value": "Configure auditd mail_acct Action on Low Disk Space", "remarks": "rule_set_322" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_shadow", + "value": "auditd_data_retention_admin_space_left_action", "remarks": "rule_set_323" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify User/Group Information - /etc/shadow", + "value": "Configure auditd admin_space_left Action on Low Disk Space", "remarks": "rule_set_323" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_shadow", + "value": "auditd_data_retention_admin_space_left_action", "remarks": "rule_set_323" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify User/Group Information - /etc/shadow", + "value": "Configure auditd admin_space_left Action on Low Disk Space", "remarks": "rule_set_323" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_chmod", + "value": "auditd_data_retention_space_left_action", "remarks": "rule_set_324" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - chmod", + "value": "Configure auditd space_left Action on Low Disk Space", "remarks": "rule_set_324" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_chmod", + "value": "auditd_data_retention_space_left_action", "remarks": "rule_set_324" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - chmod", + "value": "Configure auditd space_left Action on Low Disk Space", "remarks": "rule_set_324" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_chown", + "value": "audit_rules_sysadmin_actions", "remarks": "rule_set_325" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - chown", + "value": "Ensure auditd Collects System Administrator Actions", "remarks": "rule_set_325" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_chown", + "value": "audit_rules_sysadmin_actions", "remarks": "rule_set_325" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - chown", + "value": "Ensure auditd Collects System Administrator Actions", "remarks": "rule_set_325" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchmod", + "value": "audit_rules_suid_auid_privilege_function", "remarks": "rule_set_326" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fchmod", + "value": "Record Events When Executables Are Run As Another User", "remarks": "rule_set_326" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchmod", + "value": "audit_rules_suid_auid_privilege_function", "remarks": "rule_set_326" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fchmod", + "value": "Record Events When Executables Are Run As Another User", "remarks": "rule_set_326" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchmodat", + "value": "audit_sudo_log_events", "remarks": "rule_set_327" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fchmodat", + "value": "Record Attempts to perform maintenance activities", "remarks": "rule_set_327" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchmodat", + "value": "audit_sudo_log_events", "remarks": "rule_set_327" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fchmodat", + "value": "Record Attempts to perform maintenance activities", "remarks": "rule_set_327" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchmodat2", + "value": "audit_rules_time_adjtimex", "remarks": "rule_set_328" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fchmodat2", + "value": "Record attempts to alter time through adjtimex", "remarks": "rule_set_328" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchmodat2", + "value": "audit_rules_time_adjtimex", "remarks": "rule_set_328" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fchmodat2", + "value": "Record attempts to alter time through adjtimex", "remarks": "rule_set_328" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchown", + "value": "audit_rules_time_settimeofday", "remarks": "rule_set_329" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fchown", + "value": "Record attempts to alter time through settimeofday", "remarks": "rule_set_329" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchown", + "value": "audit_rules_time_settimeofday", "remarks": "rule_set_329" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fchown", + "value": "Record attempts to alter time through settimeofday", "remarks": "rule_set_329" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchownat", + "value": "audit_rules_time_clock_settime", "remarks": "rule_set_330" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fchownat", + "value": "Record Attempts to Alter Time Through clock_settime", "remarks": "rule_set_330" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchownat", + "value": "audit_rules_time_clock_settime", "remarks": "rule_set_330" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fchownat", + "value": "Record Attempts to Alter Time Through clock_settime", "remarks": "rule_set_330" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fremovexattr", + "value": "audit_rules_time_watch_localtime", "remarks": "rule_set_331" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fremovexattr", + "value": "Record Attempts to Alter the localtime File", "remarks": "rule_set_331" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fremovexattr", + "value": "audit_rules_time_watch_localtime", "remarks": "rule_set_331" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fremovexattr", + "value": "Record Attempts to Alter the localtime File", "remarks": "rule_set_331" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fsetxattr", + "value": "audit_rules_networkconfig_modification", "remarks": "rule_set_332" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fsetxattr", + "value": "Record Events that Modify the System's Network Environment", "remarks": "rule_set_332" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fsetxattr", + "value": "audit_rules_networkconfig_modification", "remarks": "rule_set_332" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - fsetxattr", + "value": "Record Events that Modify the System's Network Environment", "remarks": "rule_set_332" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_lchown", + "value": "audit_rules_networkconfig_modification_network_scripts", "remarks": "rule_set_333" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - lchown", + "value": "Record Events that Modify the System's Network Environment", "remarks": "rule_set_333" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_lchown", + "value": "audit_rules_networkconfig_modification_network_scripts", "remarks": "rule_set_333" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - lchown", + "value": "Record Events that Modify the System's Network Environment", "remarks": "rule_set_333" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_lremovexattr", + "value": "audit_rules_privileged_commands", "remarks": "rule_set_334" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - lremovexattr", + "value": "Ensure auditd Collects Information on the Use of Privileged Commands", "remarks": "rule_set_334" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_lremovexattr", + "value": "audit_rules_privileged_commands", "remarks": "rule_set_334" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - lremovexattr", + "value": "Ensure auditd Collects Information on the Use of Privileged Commands", "remarks": "rule_set_334" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_lsetxattr", + "value": "audit_rules_unsuccessful_file_modification_creat", "remarks": "rule_set_335" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - lsetxattr", + "value": "Record Unsuccessful Access Attempts to Files - creat", "remarks": "rule_set_335" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_lsetxattr", + "value": "audit_rules_unsuccessful_file_modification_creat", "remarks": "rule_set_335" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - lsetxattr", + "value": "Record Unsuccessful Access Attempts to Files - creat", "remarks": "rule_set_335" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_removexattr", + "value": "audit_rules_unsuccessful_file_modification_ftruncate", "remarks": "rule_set_336" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - removexattr", + "value": "Record Unsuccessful Access Attempts to Files - ftruncate", "remarks": "rule_set_336" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_removexattr", + "value": "audit_rules_unsuccessful_file_modification_ftruncate", "remarks": "rule_set_336" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - removexattr", + "value": "Record Unsuccessful Access Attempts to Files - ftruncate", "remarks": "rule_set_336" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_setxattr", + "value": "audit_rules_unsuccessful_file_modification_open", "remarks": "rule_set_337" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - setxattr", + "value": "Record Unsuccessful Access Attempts to Files - open", "remarks": "rule_set_337" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_setxattr", + "value": "audit_rules_unsuccessful_file_modification_open", "remarks": "rule_set_337" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Discretionary Access Controls - setxattr", + "value": "Record Unsuccessful Access Attempts to Files - open", "remarks": "rule_set_337" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_media_export", + "value": "audit_rules_unsuccessful_file_modification_openat", "remarks": "rule_set_338" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on Exporting to Media (successful)", + "value": "Record Unsuccessful Access Attempts to Files - openat", "remarks": "rule_set_338" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_media_export", + "value": "audit_rules_unsuccessful_file_modification_openat", "remarks": "rule_set_338" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on Exporting to Media (successful)", + "value": "Record Unsuccessful Access Attempts to Files - openat", "remarks": "rule_set_338" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_session_events_utmp", + "value": "audit_rules_unsuccessful_file_modification_truncate", "remarks": "rule_set_339" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Attempts to Alter Process and Session Initiation Information utmp", + "value": "Record Unsuccessful Access Attempts to Files - truncate", "remarks": "rule_set_339" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_session_events_utmp", + "value": "audit_rules_unsuccessful_file_modification_truncate", "remarks": "rule_set_339" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Attempts to Alter Process and Session Initiation Information utmp", + "value": "Record Unsuccessful Access Attempts to Files - truncate", "remarks": "rule_set_339" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_session_events_btmp", + "value": "audit_rules_usergroup_modification_group", "remarks": "rule_set_340" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Attempts to Alter Process and Session Initiation Information btmp", + "value": "Record Events that Modify User/Group Information - /etc/group", "remarks": "rule_set_340" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_session_events_btmp", + "value": "audit_rules_usergroup_modification_group", "remarks": "rule_set_340" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Attempts to Alter Process and Session Initiation Information btmp", + "value": "Record Events that Modify User/Group Information - /etc/group", "remarks": "rule_set_340" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_session_events_wtmp", + "value": "audit_rules_usergroup_modification_passwd", "remarks": "rule_set_341" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Attempts to Alter Process and Session Initiation Information wtmp", + "value": "Record Events that Modify User/Group Information - /etc/passwd", "remarks": "rule_set_341" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_session_events_wtmp", + "value": "audit_rules_usergroup_modification_passwd", "remarks": "rule_set_341" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Attempts to Alter Process and Session Initiation Information wtmp", + "value": "Record Events that Modify User/Group Information - /etc/passwd", "remarks": "rule_set_341" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_login_events_faillock", + "value": "audit_rules_usergroup_modification_gshadow", "remarks": "rule_set_342" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Attempts to Alter Logon and Logout Events - faillock", + "value": "Record Events that Modify User/Group Information - /etc/gshadow", "remarks": "rule_set_342" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_login_events_faillock", + "value": "audit_rules_usergroup_modification_gshadow", "remarks": "rule_set_342" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Attempts to Alter Logon and Logout Events - faillock", + "value": "Record Events that Modify User/Group Information - /etc/gshadow", "remarks": "rule_set_342" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_login_events_lastlog", + "value": "audit_rules_usergroup_modification_shadow", "remarks": "rule_set_343" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Attempts to Alter Logon and Logout Events - lastlog", + "value": "Record Events that Modify User/Group Information - /etc/shadow", "remarks": "rule_set_343" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_login_events_lastlog", + "value": "audit_rules_usergroup_modification_shadow", "remarks": "rule_set_343" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Attempts to Alter Logon and Logout Events - lastlog", + "value": "Record Events that Modify User/Group Information - /etc/shadow", "remarks": "rule_set_343" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_rename", + "value": "audit_rules_usergroup_modification_opasswd", "remarks": "rule_set_344" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects File Deletion Events by User - rename", + "value": "Record Events that Modify User/Group Information - /etc/security/opasswd", "remarks": "rule_set_344" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_rename", + "value": "audit_rules_usergroup_modification_opasswd", "remarks": "rule_set_344" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects File Deletion Events by User - rename", + "value": "Record Events that Modify User/Group Information - /etc/security/opasswd", "remarks": "rule_set_344" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_renameat", + "value": "audit_rules_dac_modification_chmod", "remarks": "rule_set_345" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects File Deletion Events by User - renameat", + "value": "Record Events that Modify the System's Discretionary Access Controls - chmod", "remarks": "rule_set_345" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_renameat", + "value": "audit_rules_dac_modification_chmod", "remarks": "rule_set_345" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects File Deletion Events by User - renameat", + "value": "Record Events that Modify the System's Discretionary Access Controls - chmod", "remarks": "rule_set_345" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_renameat2", + "value": "audit_rules_dac_modification_fchmod", "remarks": "rule_set_346" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects File Deletion Events by User - renameat2", + "value": "Record Events that Modify the System's Discretionary Access Controls - fchmod", "remarks": "rule_set_346" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_renameat2", + "value": "audit_rules_dac_modification_fchmod", "remarks": "rule_set_346" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects File Deletion Events by User - renameat2", + "value": "Record Events that Modify the System's Discretionary Access Controls - fchmod", "remarks": "rule_set_346" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_unlink", + "value": "audit_rules_dac_modification_fchmodat", "remarks": "rule_set_347" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects File Deletion Events by User - unlink", + "value": "Record Events that Modify the System's Discretionary Access Controls - fchmodat", "remarks": "rule_set_347" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_unlink", + "value": "audit_rules_dac_modification_fchmodat", "remarks": "rule_set_347" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects File Deletion Events by User - unlink", + "value": "Record Events that Modify the System's Discretionary Access Controls - fchmodat", "remarks": "rule_set_347" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_unlinkat", + "value": "audit_rules_dac_modification_fchmodat2", "remarks": "rule_set_348" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects File Deletion Events by User - unlinkat", + "value": "Record Events that Modify the System's Discretionary Access Controls - fchmodat2", "remarks": "rule_set_348" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_unlinkat", + "value": "audit_rules_dac_modification_fchmodat2", "remarks": "rule_set_348" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects File Deletion Events by User - unlinkat", + "value": "Record Events that Modify the System's Discretionary Access Controls - fchmodat2", "remarks": "rule_set_348" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_mac_modification_etc_selinux", + "value": "audit_rules_dac_modification_chown", "remarks": "rule_set_349" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Mandatory Access Controls (/etc/selinux)", + "value": "Record Events that Modify the System's Discretionary Access Controls - chown", "remarks": "rule_set_349" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_mac_modification_etc_selinux", + "value": "audit_rules_dac_modification_chown", "remarks": "rule_set_349" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Mandatory Access Controls (/etc/selinux)", + "value": "Record Events that Modify the System's Discretionary Access Controls - chown", "remarks": "rule_set_349" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_mac_modification_usr_share", + "value": "audit_rules_dac_modification_fchown", "remarks": "rule_set_350" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Mandatory Access Controls in usr/share", + "value": "Record Events that Modify the System's Discretionary Access Controls - fchown", "remarks": "rule_set_350" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_mac_modification_usr_share", + "value": "audit_rules_dac_modification_fchown", "remarks": "rule_set_350" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Events that Modify the System's Mandatory Access Controls in usr/share", + "value": "Record Events that Modify the System's Discretionary Access Controls - fchown", "remarks": "rule_set_350" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_execution_chcon", + "value": "audit_rules_dac_modification_fchownat", "remarks": "rule_set_351" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Any Attempts to Run chcon", + "value": "Record Events that Modify the System's Discretionary Access Controls - fchownat", "remarks": "rule_set_351" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_execution_chcon", + "value": "audit_rules_dac_modification_fchownat", "remarks": "rule_set_351" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Any Attempts to Run chcon", + "value": "Record Events that Modify the System's Discretionary Access Controls - fchownat", "remarks": "rule_set_351" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_execution_setfacl", + "value": "audit_rules_dac_modification_lchown", "remarks": "rule_set_352" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Any Attempts to Run setfacl", + "value": "Record Events that Modify the System's Discretionary Access Controls - lchown", "remarks": "rule_set_352" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_execution_setfacl", + "value": "audit_rules_dac_modification_lchown", "remarks": "rule_set_352" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Any Attempts to Run setfacl", + "value": "Record Events that Modify the System's Discretionary Access Controls - lchown", "remarks": "rule_set_352" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_execution_chacl", + "value": "audit_rules_dac_modification_fremovexattr", "remarks": "rule_set_353" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Any Attempts to Run chacl", + "value": "Record Events that Modify the System's Discretionary Access Controls - fremovexattr", "remarks": "rule_set_353" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_execution_chacl", + "value": "audit_rules_dac_modification_fremovexattr", "remarks": "rule_set_353" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Record Any Attempts to Run chacl", + "value": "Record Events that Modify the System's Discretionary Access Controls - fremovexattr", "remarks": "rule_set_353" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_privileged_commands_usermod", + "value": "audit_rules_dac_modification_fsetxattr", "remarks": "rule_set_354" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on the Use of Privileged Commands - usermod", + "value": "Record Events that Modify the System's Discretionary Access Controls - fsetxattr", "remarks": "rule_set_354" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_privileged_commands_usermod", + "value": "audit_rules_dac_modification_fsetxattr", "remarks": "rule_set_354" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on the Use of Privileged Commands - usermod", + "value": "Record Events that Modify the System's Discretionary Access Controls - fsetxattr", "remarks": "rule_set_354" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_delete", + "value": "audit_rules_dac_modification_lremovexattr", "remarks": "rule_set_355" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on Kernel Module Unloading - delete_module", + "value": "Record Events that Modify the System's Discretionary Access Controls - lremovexattr", "remarks": "rule_set_355" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_delete", + "value": "audit_rules_dac_modification_lremovexattr", "remarks": "rule_set_355" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on Kernel Module Unloading - delete_module", + "value": "Record Events that Modify the System's Discretionary Access Controls - lremovexattr", "remarks": "rule_set_355" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_finit", + "value": "audit_rules_dac_modification_lsetxattr", "remarks": "rule_set_356" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on Kernel Module Loading and Unloading - finit_module", + "value": "Record Events that Modify the System's Discretionary Access Controls - lsetxattr", "remarks": "rule_set_356" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_finit", + "value": "audit_rules_dac_modification_lsetxattr", "remarks": "rule_set_356" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on Kernel Module Loading and Unloading - finit_module", + "value": "Record Events that Modify the System's Discretionary Access Controls - lsetxattr", "remarks": "rule_set_356" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_init", + "value": "audit_rules_dac_modification_removexattr", "remarks": "rule_set_357" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on Kernel Module Loading - init_module", + "value": "Record Events that Modify the System's Discretionary Access Controls - removexattr", "remarks": "rule_set_357" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_init", + "value": "audit_rules_dac_modification_removexattr", "remarks": "rule_set_357" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on Kernel Module Loading - init_module", + "value": "Record Events that Modify the System's Discretionary Access Controls - removexattr", "remarks": "rule_set_357" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_query", + "value": "audit_rules_dac_modification_setxattr", "remarks": "rule_set_358" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on Kernel Module Loading and Unloading - query_module", + "value": "Record Events that Modify the System's Discretionary Access Controls - setxattr", "remarks": "rule_set_358" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_query", + "value": "audit_rules_dac_modification_setxattr", "remarks": "rule_set_358" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on Kernel Module Loading and Unloading - query_module", + "value": "Record Events that Modify the System's Discretionary Access Controls - setxattr", "remarks": "rule_set_358" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_privileged_commands_kmod", + "value": "audit_rules_media_export", "remarks": "rule_set_359" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on the Use of Privileged Commands - kmod", + "value": "Ensure auditd Collects Information on Exporting to Media (successful)", "remarks": "rule_set_359" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_privileged_commands_kmod", + "value": "audit_rules_media_export", "remarks": "rule_set_359" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Ensure auditd Collects Information on the Use of Privileged Commands - kmod", + "value": "Ensure auditd Collects Information on Exporting to Media (successful)", "remarks": "rule_set_359" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_immutable", + "value": "audit_rules_session_events_utmp", "remarks": "rule_set_360" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Make the auditd Configuration Immutable", + "value": "Record Attempts to Alter Process and Session Initiation Information utmp", "remarks": "rule_set_360" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_immutable", + "value": "audit_rules_session_events_utmp", "remarks": "rule_set_360" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Make the auditd Configuration Immutable", + "value": "Record Attempts to Alter Process and Session Initiation Information utmp", "remarks": "rule_set_360" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "directory_permissions_var_log_audit", + "value": "audit_rules_session_events_btmp", "remarks": "rule_set_361" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "System Audit Logs Must Have Mode 0750 or Less Permissive", + "value": "Record Attempts to Alter Process and Session Initiation Information btmp", "remarks": "rule_set_361" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "directory_permissions_var_log_audit", + "value": "audit_rules_session_events_btmp", "remarks": "rule_set_361" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "System Audit Logs Must Have Mode 0750 or Less Permissive", + "value": "Record Attempts to Alter Process and Session Initiation Information btmp", "remarks": "rule_set_361" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_var_log_audit", + "value": "audit_rules_session_events_wtmp", "remarks": "rule_set_362" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "System Audit Logs Must Have Mode 0640 or Less Permissive", + "value": "Record Attempts to Alter Process and Session Initiation Information wtmp", "remarks": "rule_set_362" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_var_log_audit", + "value": "audit_rules_session_events_wtmp", "remarks": "rule_set_362" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "System Audit Logs Must Have Mode 0640 or Less Permissive", + "value": "Record Attempts to Alter Process and Session Initiation Information wtmp", "remarks": "rule_set_362" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_var_log_audit_stig", + "value": "audit_rules_login_events_faillock", "remarks": "rule_set_363" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "System Audit Logs Must Be Owned By Root", + "value": "Record Attempts to Alter Logon and Logout Events - faillock", "remarks": "rule_set_363" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_var_log_audit_stig", + "value": "audit_rules_login_events_faillock", "remarks": "rule_set_363" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "System Audit Logs Must Be Owned By Root", + "value": "Record Attempts to Alter Logon and Logout Events - faillock", "remarks": "rule_set_363" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_group_ownership_var_log_audit", + "value": "audit_rules_login_events_lastlog", "remarks": "rule_set_364" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "System Audit Logs Must Be Group Owned By Root", + "value": "Record Attempts to Alter Logon and Logout Events - lastlog", "remarks": "rule_set_364" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_group_ownership_var_log_audit", + "value": "audit_rules_login_events_lastlog", "remarks": "rule_set_364" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "System Audit Logs Must Be Group Owned By Root", + "value": "Record Attempts to Alter Logon and Logout Events - lastlog", "remarks": "rule_set_364" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_audit_configuration", + "value": "audit_rules_file_deletion_events_unlink", "remarks": "rule_set_365" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Audit Configuration Files Permissions are 640 or More Restrictive", + "value": "Ensure auditd Collects File Deletion Events by User - unlink", "remarks": "rule_set_365" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_audit_configuration", + "value": "audit_rules_file_deletion_events_unlink", "remarks": "rule_set_365" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Audit Configuration Files Permissions are 640 or More Restrictive", + "value": "Ensure auditd Collects File Deletion Events by User - unlink", "remarks": "rule_set_365" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_audit_configuration", + "value": "audit_rules_file_deletion_events_unlinkat", "remarks": "rule_set_366" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Audit Configuration Files Must Be Owned By Root", + "value": "Ensure auditd Collects File Deletion Events by User - unlinkat", "remarks": "rule_set_366" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_audit_configuration", + "value": "audit_rules_file_deletion_events_unlinkat", "remarks": "rule_set_366" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Audit Configuration Files Must Be Owned By Root", + "value": "Ensure auditd Collects File Deletion Events by User - unlinkat", "remarks": "rule_set_366" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_audit_configuration", + "value": "audit_rules_file_deletion_events_rename", "remarks": "rule_set_367" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Audit Configuration Files Must Be Owned By Group root", + "value": "Ensure auditd Collects File Deletion Events by User - rename", "remarks": "rule_set_367" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_audit_configuration", + "value": "audit_rules_file_deletion_events_rename", "remarks": "rule_set_367" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Audit Configuration Files Must Be Owned By Group root", + "value": "Ensure auditd Collects File Deletion Events by User - rename", "remarks": "rule_set_367" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_audit_binaries", + "value": "audit_rules_file_deletion_events_renameat", "remarks": "rule_set_368" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify that audit tools Have Mode 0755 or less", + "value": "Ensure auditd Collects File Deletion Events by User - renameat", "remarks": "rule_set_368" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_audit_binaries", + "value": "audit_rules_file_deletion_events_renameat", "remarks": "rule_set_368" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify that audit tools Have Mode 0755 or less", + "value": "Ensure auditd Collects File Deletion Events by User - renameat", "remarks": "rule_set_368" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_audit_binaries", + "value": "audit_rules_file_deletion_events_renameat2", "remarks": "rule_set_369" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify that audit tools are owned by root", + "value": "Ensure auditd Collects File Deletion Events by User - renameat2", "remarks": "rule_set_369" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_audit_binaries", + "value": "audit_rules_file_deletion_events_renameat2", "remarks": "rule_set_369" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify that audit tools are owned by root", + "value": "Ensure auditd Collects File Deletion Events by User - renameat2", "remarks": "rule_set_369" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_audit_binaries", + "value": "audit_rules_mac_modification_etc_selinux", "remarks": "rule_set_370" }, { "name": "Rule_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify that audit tools are owned by group root", + "value": "Record Events that Modify the System's Mandatory Access Controls (/etc/selinux)", "remarks": "rule_set_370" }, { "name": "Check_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_audit_binaries", + "value": "audit_rules_mac_modification_etc_selinux", "remarks": "rule_set_370" }, { "name": "Check_Description", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "Verify that audit tools are owned by group root", + "value": "Record Events that Modify the System's Mandatory Access Controls (/etc/selinux)", "remarks": "rule_set_370" - } - ], - "control-implementations": [ + }, { - "uuid": "fa5e987f-6921-418b-9e2d-781e3a477e75", - "source": "trestle://profiles/rhel10-cis_rhel10-l2_workstation/profile.json", - "description": "REPLACE_ME", - "props": [ - { - "name": "Framework_Short_Name", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal", - "value": "cis_workstation_l2" - } - ], - "set-parameters": [ - { - "param-id": "cis_banner_text", - "values": [ - "cis" - ] - }, - { - "param-id": "inactivity_timeout_value", - "values": [ - "15_minutes" - ] - }, - { - "param-id": "login_banner_text", - "values": [ - "cis_banners" - ] - }, - { - "param-id": "sshd_idle_timeout_value", - "values": [ - "5_minutes" - ] - }, - { - "param-id": "sshd_max_auth_tries_value", - "values": [ - "4" - ] - }, - { - "param-id": "sshd_strong_kex", - "values": [ - "cis_rhel8" - ] - }, - { - "param-id": "sshd_strong_macs", - "values": [ - "cis_rhel8" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_all_accept_redirects_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_all_accept_source_route_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_all_log_martians_value", - "values": [ - "enabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_all_rp_filter_value", - "values": [ - "enabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_all_secure_redirects_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_default_accept_redirects_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_default_accept_source_route_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_default_log_martians_value", - "values": [ - "enabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_default_rp_filter_value", - "values": [ - "enabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_conf_default_secure_redirects_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts_value", - "values": [ - "enabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses_value", - "values": [ - "enabled" - ] - }, - { - "param-id": "sysctl_net_ipv4_tcp_syncookies_value", - "values": [ - "enabled" - ] - }, - { - "param-id": "sysctl_net_ipv6_conf_all_accept_ra_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv6_conf_all_accept_redirects_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv6_conf_all_accept_source_route_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv6_conf_all_forwarding_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv6_conf_default_accept_ra_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv6_conf_default_accept_redirects_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "sysctl_net_ipv6_conf_default_accept_source_route_value", - "values": [ - "disabled" - ] - }, - { - "param-id": "var_account_disable_post_pw_expiration", - "values": [ - "30" - ] - }, - { - "param-id": "var_accounts_maximum_age_login_defs", - "values": [ - "365" - ] - }, - { - "param-id": "var_accounts_minimum_age_login_defs", - "values": [ - "1" - ] - }, - { - "param-id": "var_accounts_password_warn_age_login_defs", - "values": [ - "7" - ] - }, - { - "param-id": "var_accounts_passwords_pam_faillock_deny", - "values": [ - "5" - ] - }, - { - "param-id": "var_accounts_passwords_pam_faillock_dir", - "values": [ - "run" - ] - }, - { - "param-id": "var_accounts_passwords_pam_faillock_unlock_time", - "values": [ - "900" - ] - }, - { - "param-id": "var_accounts_tmout", - "values": [ - "15_min" - ] - }, - { - "param-id": "var_accounts_user_umask", - "values": [ - "027" - ] - }, - { - "param-id": "var_auditd_action_mail_acct", - "values": [ - "root" - ] - }, - { - "param-id": "var_auditd_admin_space_left_action", - "values": [ - "cis_rhel8" - ] - }, - { - "param-id": "var_auditd_disk_error_action", - "values": [ - "cis_rhel8" - ] - }, - { - "param-id": "var_auditd_disk_full_action", - "values": [ - "cis_rhel8" - ] - }, - { - "param-id": "var_auditd_max_log_file", - "values": [ - "6" - ] - }, - { - "param-id": "var_auditd_max_log_file_action", - "values": [ - "keep_logs" - ] - }, - { - "param-id": "var_auditd_space_left_action", - "values": [ - "cis_rhel8" - ] - }, - { - "param-id": "var_authselect_profile", - "values": [ - "local" - ] - }, + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_mac_modification_usr_share", + "remarks": "rule_set_371" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Record Events that Modify the System's Mandatory Access Controls in usr/share", + "remarks": "rule_set_371" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_mac_modification_usr_share", + "remarks": "rule_set_371" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Record Events that Modify the System's Mandatory Access Controls in usr/share", + "remarks": "rule_set_371" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_execution_chcon", + "remarks": "rule_set_372" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Record Any Attempts to Run chcon", + "remarks": "rule_set_372" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_execution_chcon", + "remarks": "rule_set_372" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Record Any Attempts to Run chcon", + "remarks": "rule_set_372" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_execution_setfacl", + "remarks": "rule_set_373" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Record Any Attempts to Run setfacl", + "remarks": "rule_set_373" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_execution_setfacl", + "remarks": "rule_set_373" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Record Any Attempts to Run setfacl", + "remarks": "rule_set_373" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_execution_chacl", + "remarks": "rule_set_374" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Record Any Attempts to Run chacl", + "remarks": "rule_set_374" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_execution_chacl", + "remarks": "rule_set_374" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Record Any Attempts to Run chacl", + "remarks": "rule_set_374" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_privileged_commands_usermod", + "remarks": "rule_set_375" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure auditd Collects Information on the Use of Privileged Commands - usermod", + "remarks": "rule_set_375" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_privileged_commands_usermod", + "remarks": "rule_set_375" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure auditd Collects Information on the Use of Privileged Commands - usermod", + "remarks": "rule_set_375" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_privileged_commands_kmod", + "remarks": "rule_set_376" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure auditd Collects Information on the Use of Privileged Commands - kmod", + "remarks": "rule_set_376" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_privileged_commands_kmod", + "remarks": "rule_set_376" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure auditd Collects Information on the Use of Privileged Commands - kmod", + "remarks": "rule_set_376" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_kernel_module_loading_init", + "remarks": "rule_set_377" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure auditd Collects Information on Kernel Module Loading - init_module", + "remarks": "rule_set_377" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_kernel_module_loading_init", + "remarks": "rule_set_377" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure auditd Collects Information on Kernel Module Loading - init_module", + "remarks": "rule_set_377" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_kernel_module_loading_finit", + "remarks": "rule_set_378" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure auditd Collects Information on Kernel Module Loading and Unloading - finit_module", + "remarks": "rule_set_378" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_kernel_module_loading_finit", + "remarks": "rule_set_378" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure auditd Collects Information on Kernel Module Loading and Unloading - finit_module", + "remarks": "rule_set_378" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_kernel_module_loading_delete", + "remarks": "rule_set_379" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure auditd Collects Information on Kernel Module Unloading - delete_module", + "remarks": "rule_set_379" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_kernel_module_loading_delete", + "remarks": "rule_set_379" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure auditd Collects Information on Kernel Module Unloading - delete_module", + "remarks": "rule_set_379" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_kernel_module_loading_create", + "remarks": "rule_set_380" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure auditd Collects Information on Kernel Module Unloading - create_module", + "remarks": "rule_set_380" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_kernel_module_loading_create", + "remarks": "rule_set_380" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure auditd Collects Information on Kernel Module Unloading - create_module", + "remarks": "rule_set_380" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_kernel_module_loading_query", + "remarks": "rule_set_381" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure auditd Collects Information on Kernel Module Loading and Unloading - query_module", + "remarks": "rule_set_381" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_kernel_module_loading_query", + "remarks": "rule_set_381" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Ensure auditd Collects Information on Kernel Module Loading and Unloading - query_module", + "remarks": "rule_set_381" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_immutable", + "remarks": "rule_set_382" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Make the auditd Configuration Immutable", + "remarks": "rule_set_382" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_immutable", + "remarks": "rule_set_382" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Make the auditd Configuration Immutable", + "remarks": "rule_set_382" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "directory_permissions_var_log_audit", + "remarks": "rule_set_383" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "System Audit Logs Must Have Mode 0750 or Less Permissive", + "remarks": "rule_set_383" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "directory_permissions_var_log_audit", + "remarks": "rule_set_383" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "System Audit Logs Must Have Mode 0750 or Less Permissive", + "remarks": "rule_set_383" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_var_log_audit", + "remarks": "rule_set_384" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "System Audit Logs Must Have Mode 0640 or Less Permissive", + "remarks": "rule_set_384" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_var_log_audit", + "remarks": "rule_set_384" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "System Audit Logs Must Have Mode 0640 or Less Permissive", + "remarks": "rule_set_384" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_ownership_var_log_audit_stig", + "remarks": "rule_set_385" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "System Audit Logs Must Be Owned By Root", + "remarks": "rule_set_385" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_ownership_var_log_audit_stig", + "remarks": "rule_set_385" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "System Audit Logs Must Be Owned By Root", + "remarks": "rule_set_385" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_group_ownership_var_log_audit", + "remarks": "rule_set_386" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "System Audit Logs Must Be Group Owned By Root", + "remarks": "rule_set_386" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_group_ownership_var_log_audit", + "remarks": "rule_set_386" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "System Audit Logs Must Be Group Owned By Root", + "remarks": "rule_set_386" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_audit_configuration", + "remarks": "rule_set_387" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Audit Configuration Files Permissions are 640 or More Restrictive", + "remarks": "rule_set_387" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_audit_configuration", + "remarks": "rule_set_387" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Audit Configuration Files Permissions are 640 or More Restrictive", + "remarks": "rule_set_387" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_ownership_audit_configuration", + "remarks": "rule_set_388" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Audit Configuration Files Must Be Owned By Root", + "remarks": "rule_set_388" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_ownership_audit_configuration", + "remarks": "rule_set_388" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Audit Configuration Files Must Be Owned By Root", + "remarks": "rule_set_388" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_groupownership_audit_configuration", + "remarks": "rule_set_389" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Audit Configuration Files Must Be Owned By Group root", + "remarks": "rule_set_389" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_groupownership_audit_configuration", + "remarks": "rule_set_389" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Audit Configuration Files Must Be Owned By Group root", + "remarks": "rule_set_389" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_audit_binaries", + "remarks": "rule_set_390" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify that audit tools Have Mode 0755 or less", + "remarks": "rule_set_390" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_audit_binaries", + "remarks": "rule_set_390" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify that audit tools Have Mode 0755 or less", + "remarks": "rule_set_390" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_ownership_audit_binaries", + "remarks": "rule_set_391" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify that audit tools are owned by root", + "remarks": "rule_set_391" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_ownership_audit_binaries", + "remarks": "rule_set_391" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify that audit tools are owned by root", + "remarks": "rule_set_391" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_groupownership_audit_binaries", + "remarks": "rule_set_392" + }, + { + "name": "Rule_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify that audit tools are owned by group root", + "remarks": "rule_set_392" + }, + { + "name": "Check_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_groupownership_audit_binaries", + "remarks": "rule_set_392" + }, + { + "name": "Check_Description", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "Verify that audit tools are owned by group root", + "remarks": "rule_set_392" + } + ], + "control-implementations": [ + { + "uuid": "105f9df7-9be8-4887-94e1-dfde3fe79295", + "source": "trestle://profiles/rhel10-cis_rhel10-l2_workstation/profile.json", + "description": "REPLACE_ME", + "props": [ { - "param-id": "var_multiple_time_servers", - "values": [ - "rhel" - ] - }, + "name": "Framework_Short_Name", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal", + "value": "cis_workstation_l2" + } + ], + "set-parameters": [ { - "param-id": "var_pam_wheel_group_for_su", + "param-id": "cis_banner_text", "values": [ "cis" ] }, { - "param-id": "var_password_hashing_algorithm", - "values": [ - "yescrypt" - ] - }, - { - "param-id": "var_password_hashing_algorithm_pam", - "values": [ - "yescrypt" - ] - }, - { - "param-id": "var_password_pam_dictcheck", + "param-id": "inactivity_timeout_value", "values": [ - "1" + "15_minutes" ] }, { - "param-id": "var_password_pam_difok", + "param-id": "login_banner_text", "values": [ - "2" + "cis_banners" ] }, { - "param-id": "var_password_pam_maxrepeat", + "param-id": "sshd_idle_timeout_value", "values": [ - "3" + "5_minutes" ] }, { - "param-id": "var_password_pam_minclass", + "param-id": "sshd_max_auth_tries_value", "values": [ "4" ] }, { - "param-id": "var_password_pam_minlen", + "param-id": "sshd_strong_kex", "values": [ - "14" + "cis_rhel10" ] }, { - "param-id": "var_password_pam_remember", + "param-id": "sshd_strong_macs", "values": [ - "24" + "cis_rhel10" ] }, { - "param-id": "var_password_pam_remember_control_flag", + "param-id": "sysctl_net_ipv4_conf_all_accept_redirects_value", "values": [ - "requisite_or_required" + "disabled" ] }, { - "param-id": "var_postfix_inet_interfaces", + "param-id": "sysctl_net_ipv4_conf_all_accept_source_route_value", "values": [ - "loopback-only" + "disabled" ] }, { - "param-id": "var_screensaver_lock_delay", + "param-id": "sysctl_net_ipv4_conf_all_log_martians_value", "values": [ - "5_seconds" + "enabled" ] }, { - "param-id": "var_selinux_policy_name", + "param-id": "sysctl_net_ipv4_conf_all_rp_filter_value", "values": [ - "targeted" + "enabled" ] }, { - "param-id": "var_selinux_state", + "param-id": "sysctl_net_ipv4_conf_all_secure_redirects_value", "values": [ - "enforcing" + "disabled" ] }, { - "param-id": "var_sshd_max_sessions", + "param-id": "sysctl_net_ipv4_conf_default_accept_redirects_value", "values": [ - "10" + "disabled" ] }, { - "param-id": "var_sshd_set_keepalive", + "param-id": "sysctl_net_ipv4_conf_default_accept_source_route_value", "values": [ - "1" + "disabled" ] }, { - "param-id": "var_sshd_set_login_grace_time", + "param-id": "sysctl_net_ipv4_conf_default_log_martians_value", "values": [ - "60" + "enabled" ] }, { - "param-id": "var_sshd_set_maxstartups", + "param-id": "sysctl_net_ipv4_conf_default_rp_filter_value", "values": [ - "10:30:60" + "enabled" ] }, { - "param-id": "var_system_crypto_policy", + "param-id": "sysctl_net_ipv4_conf_default_secure_redirects_value", "values": [ - "default_policy" + "disabled" ] }, { - "param-id": "var_user_initialization_files_regex", + "param-id": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts_value", "values": [ - "all_dotfiles" + "enabled" ] - } - ], - "implemented-requirements": [ + }, { - "uuid": "049d6839-4d7b-476d-b0ef-25c08e29b692", - "control-id": "cis_rhel10_1-1.1.6", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_squashfs_disabled" - } + "param-id": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses_value", + "values": [ + "enabled" ] }, { - "uuid": "bd266604-1aea-4a0f-ab21-da25f6bb138a", - "control-id": "cis_rhel10_1-1.1.7", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_udf_disabled" - } + "param-id": "sysctl_net_ipv4_tcp_syncookies_value", + "values": [ + "enabled" ] }, { - "uuid": "5663a8ae-2897-4fae-a41c-d7a23742106f", - "control-id": "cis_rhel10_1-1.1.8", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_usb-storage_disabled" - } + "param-id": "sysctl_net_ipv6_conf_all_accept_ra_value", + "values": [ + "disabled" ] }, { - "uuid": "8f966d38-87df-40ee-87ab-f58ce959cc41", - "control-id": "cis_rhel10_1-1.1.9", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } + "param-id": "sysctl_net_ipv6_conf_all_accept_redirects_value", + "values": [ + "disabled" ] }, { - "uuid": "189a0cb0-2f57-4c33-bbcf-17156039de2e", - "control-id": "cis_rhel10_1-1.2.3.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_home" - } + "param-id": "sysctl_net_ipv6_conf_all_accept_source_route_value", + "values": [ + "disabled" ] }, { - "uuid": "00f6217a-7f55-4bfd-83f9-803e6d8bf1ec", - "control-id": "cis_rhel10_1-1.2.4.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_var" - } + "param-id": "sysctl_net_ipv6_conf_all_forwarding_value", + "values": [ + "disabled" ] }, { - "uuid": "7c06606c-ef74-4389-822f-0dbc59d755b3", - "control-id": "cis_rhel10_1-1.2.5.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_var_tmp" - } + "param-id": "sysctl_net_ipv6_conf_default_accept_ra_value", + "values": [ + "disabled" ] }, { - "uuid": "ef91849d-bc70-4670-9843-a5a6b01cec8c", - "control-id": "cis_rhel10_1-1.2.6.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_var_log" - } + "param-id": "sysctl_net_ipv6_conf_default_accept_redirects_value", + "values": [ + "disabled" ] }, { - "uuid": "f6aa36a6-acfd-4439-8b9e-058ef00e6798", - "control-id": "cis_rhel10_1-1.2.7.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_var_log_audit" - } + "param-id": "sysctl_net_ipv6_conf_default_accept_source_route_value", + "values": [ + "disabled" ] }, { - "uuid": "40962161-a05a-4621-8aa2-72be712edf4d", - "control-id": "cis_rhel10_1-2.1.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } + "param-id": "sysctl_net_ipv6_conf_default_forwarding_value", + "values": [ + "disabled" ] }, { - "uuid": "9eb9cfd7-5e84-46ab-86db-128f08e0c76e", - "control-id": "cis_rhel10_1-3.1.5", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "selinux_state" - } + "param-id": "var_account_disable_post_pw_expiration", + "values": [ + "30" ] }, { - "uuid": "13de156d-6f30-414d-a46f-572c38a7daa1", - "control-id": "cis_rhel10_1-3.1.6", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } + "param-id": "var_accounts_maximum_age_login_defs", + "values": [ + "365" ] }, { - "uuid": "d0149d21-495f-42a2-8e9d-65ec2f0b67a4", - "control-id": "cis_rhel10_1-8.6", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_automount" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_automount_open" - } + "param-id": "var_accounts_minimum_age_login_defs", + "values": [ + "1" ] }, { - "uuid": "c9fc3949-76fa-4f1a-a01a-af237756afbb", - "control-id": "cis_rhel10_1-8.7", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_automount" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_automount_open" - } + "param-id": "var_accounts_password_warn_age_login_defs", + "values": [ + "7" ] }, { - "uuid": "51b86226-1446-4566-8d88-ba9e65e2bd52", - "control-id": "cis_rhel10_2-1.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_autofs_disabled" - } + "param-id": "var_accounts_passwords_pam_faillock_deny", + "values": [ + "5" ] }, { - "uuid": "aceea8e3-2d8b-4a13-9f1e-6259e9c1aa26", - "control-id": "cis_rhel10_2-1.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_avahi-daemon_disabled" - } + "param-id": "var_accounts_passwords_pam_faillock_dir", + "values": [ + "run" ] }, { - "uuid": "d23f5ab7-8293-4fa8-bbdd-dd9823bfac83", - "control-id": "cis_rhel10_2-2.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_openldap-clients_removed" - } + "param-id": "var_accounts_passwords_pam_faillock_unlock_time", + "values": [ + "900" + ] + }, + { + "param-id": "var_accounts_tmout", + "values": [ + "15_min" ] }, { - "uuid": "ad51d733-3125-44f4-a320-eb0bef0de703", - "control-id": "cis_rhel10_3-1.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_bluetooth_disabled" - } + "param-id": "var_accounts_user_umask", + "values": [ + "027" ] }, { - "uuid": "57e450c6-c241-4d3b-9453-b88685fa3d70", - "control-id": "cis_rhel10_3-2.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_tipc_disabled" - } + "param-id": "var_auditd_action_mail_acct", + "values": [ + "root" ] }, { - "uuid": "2c763d72-f91f-4a7b-b932-21fc413c5864", - "control-id": "cis_rhel10_3-2.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "kernel_module_sctp_disabled" - } + "param-id": "var_auditd_admin_space_left_action", + "values": [ + "cis_rhel10" ] }, { - "uuid": "6a0f0d78-1b63-4315-b54d-6f6d0cfd8389", - "control-id": "cis_rhel10_5-2.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_require_authentication" - } + "param-id": "var_auditd_disk_error_action", + "values": [ + "cis_rhel10" ] }, { - "uuid": "b6798b7b-d915-42d1-9967-3340853bb9a4", - "control-id": "cis_rhel10_5-3.3.1.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_deny_root" - } + "param-id": "var_auditd_disk_full_action", + "values": [ + "cis_rhel10" ] }, { - "uuid": "d874aeb5-61f9-461b-a8fd-d3423e97b8c9", - "control-id": "cis_rhel10_5-4.1.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_minimum_age_login_defs" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_set_min_life_existing" - } + "param-id": "var_auditd_max_log_file", + "values": [ + "6" ] }, { - "uuid": "6ca604f3-00c6-4955-a336-77d50488f51f", - "control-id": "cis_rhel10_5-4.3.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary to create a new rule to check and remove nologin from /etc/shells.\nThe no_tmux_in_shells rule can be used as referece." - } + "param-id": "var_auditd_max_log_file_action", + "values": [ + "keep_logs" ] }, { - "uuid": "a40e7631-66ac-4aa5-aba9-2a5718a2503c", - "control-id": "cis_rhel10_6-3.1.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_audit_installed" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_audit-libs_installed" - } + "param-id": "var_auditd_space_left_action", + "values": [ + "cis_rhel10" ] }, { - "uuid": "7954728d-3e86-42e3-ab2f-449e1bfc040d", - "control-id": "cis_rhel10_6-3.1.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "grub2_audit_argument" - } + "param-id": "var_authselect_profile", + "values": [ + "local" ] }, { - "uuid": "e4b992dc-7ca3-4818-a422-461f2bbc6ec7", - "control-id": "cis_rhel10_6-3.1.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "grub2_audit_backlog_limit_argument" - } + "param-id": "var_multiple_time_servers", + "values": [ + "rhel" ] }, { - "uuid": "88d00e7e-c1ee-4542-a6a6-3ada4b5b5295", - "control-id": "cis_rhel10_6-3.1.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_auditd_enabled" - } + "param-id": "var_pam_wheel_group_for_su", + "values": [ + "cis" ] }, { - "uuid": "c5455a67-74b4-4886-a808-72f94c39e6f5", - "control-id": "cis_rhel10_6-3.2.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_retention_max_log_file" - } + "param-id": "var_password_hashing_algorithm", + "values": [ + "yescrypt" ] }, { - "uuid": "2f14677b-4745-4b1a-a277-3ceaff257a08", - "control-id": "cis_rhel10_6-3.2.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_retention_max_log_file_action" - } + "param-id": "var_password_hashing_algorithm_pam", + "values": [ + "yescrypt" ] }, { - "uuid": "9f3c2eeb-9b46-4aea-8ba2-1a99ebdd467a", - "control-id": "cis_rhel10_6-3.2.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_disk_error_action" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_disk_full_action" - } + "param-id": "var_password_pam_dictcheck", + "values": [ + "1" ] }, { - "uuid": "97614c4d-a135-4038-a7cf-9493440fcb04", - "control-id": "cis_rhel10_6-3.2.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_retention_action_mail_acct" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_retention_admin_space_left_action" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "auditd_data_retention_space_left_action" - } + "param-id": "var_password_pam_difok", + "values": [ + "2" ] }, { - "uuid": "f849daca-b218-435b-b21f-4bdd080beca1", - "control-id": "cis_rhel10_6-3.3.1", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_sysadmin_actions" - } + "param-id": "var_password_pam_maxrepeat", + "values": [ + "3" ] }, { - "uuid": "fede1611-fd34-421b-b731-8ff05e28cd71", - "control-id": "cis_rhel10_6-3.3.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_suid_auid_privilege_function" - } + "param-id": "var_password_pam_minclass", + "values": [ + "4" ] }, { - "uuid": "f4229996-63f2-437e-8032-7efacc054a9c", - "control-id": "cis_rhel10_6-3.3.3", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_sudo_log_events" - } + "param-id": "var_password_pam_minlen", + "values": [ + "14" ] }, { - "uuid": "ae28ccc8-8a08-48d6-8561-08415206ba44", - "control-id": "cis_rhel10_6-3.3.4", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_time_adjtimex" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_time_settimeofday" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_time_clock_settime" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_time_watch_localtime" - } + "param-id": "var_password_pam_remember", + "values": [ + "24" ] }, { - "uuid": "8194b64b-2b93-494b-a69c-f4f35f8c1373", - "control-id": "cis_rhel10_6-3.3.5", - "description": "These rules are not covering \"/etc/hostname\" and \"/etc/NetworkManager/\".", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_networkconfig_modification" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_networkconfig_modification_network_scripts" - } + "param-id": "var_password_pam_remember_control_flag", + "values": [ + "requisite_or_required" ] }, { - "uuid": "9bcbe194-3598-4e06-b080-995d54423a33", - "control-id": "cis_rhel10_6-3.3.6", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_privileged_commands" - } + "param-id": "var_postfix_inet_interfaces", + "values": [ + "loopback-only" ] }, { - "uuid": "376cecea-fd32-4dcb-9d45-03545180787c", - "control-id": "cis_rhel10_6-3.3.7", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_unsuccessful_file_modification_creat" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_unsuccessful_file_modification_ftruncate" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_unsuccessful_file_modification_open" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_unsuccessful_file_modification_openat" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_unsuccessful_file_modification_truncate" - } + "param-id": "var_screensaver_lock_delay", + "values": [ + "5_seconds" ] }, { - "uuid": "cc1fe71a-36b0-4794-af37-a8b5215c1335", - "control-id": "cis_rhel10_6-3.3.8", - "description": "Missing rules to check \"/etc/nsswitch.conf\", \"/etc/pam.conf\" and \"/etc/pam.d\"", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_group" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_gshadow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_opasswd" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_passwd" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_usergroup_modification_shadow" - } + "param-id": "var_selinux_policy_name", + "values": [ + "targeted" ] }, - { - "uuid": "0bc28fff-7004-40b0-a242-4a25709901e9", - "control-id": "cis_rhel10_6-3.3.9", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_chmod" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_chown" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchmod" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchmodat" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchmodat2" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchown" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fchownat" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fremovexattr" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_fsetxattr" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_lchown" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_lremovexattr" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_lsetxattr" - }, + { + "param-id": "var_selinux_state", + "values": [ + "enforcing" + ] + }, + { + "param-id": "var_sshd_max_sessions", + "values": [ + "10" + ] + }, + { + "param-id": "var_sshd_set_keepalive", + "values": [ + "1" + ] + }, + { + "param-id": "var_sshd_set_login_grace_time", + "values": [ + "60" + ] + }, + { + "param-id": "var_sshd_set_maxstartups", + "values": [ + "10:30:60" + ] + }, + { + "param-id": "var_system_crypto_policy", + "values": [ + "default_policy" + ] + }, + { + "param-id": "var_user_initialization_files_regex", + "values": [ + "all_dotfiles" + ] + } + ], + "implemented-requirements": [ + { + "uuid": "ffe71fdb-b388-4df9-8c5c-d5f8fe410197", + "control-id": "cis_rhel10_1-1.1.6", + "description": "REPLACE_ME", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_removexattr" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_dac_modification_setxattr" + "value": "kernel_module_overlayfs_disabled" } ] }, { - "uuid": "153f8450-13af-4def-b754-771cef74b9b3", - "control-id": "cis_rhel10_6-3.3.10", + "uuid": "0d6c9b15-725e-47ff-ba39-e317fb7b6897", + "control-id": "cis_rhel10_1-1.1.7", "description": "REPLACE_ME", "props": [ { @@ -22734,13 +21799,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_media_export" + "value": "kernel_module_squashfs_disabled" } ] }, { - "uuid": "ef12cad6-e70f-450f-83c4-1e3e1fea177c", - "control-id": "cis_rhel10_6-3.3.11", + "uuid": "598103ff-5426-4e10-8d92-9cb5678bd976", + "control-id": "cis_rhel10_1-1.1.8", "description": "REPLACE_ME", "props": [ { @@ -22751,23 +21816,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_session_events_utmp" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_session_events_btmp" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_session_events_wtmp" + "value": "kernel_module_udf_disabled" } ] }, { - "uuid": "4e9e1f5d-b2ea-4ff1-94d3-43b547260ce7", - "control-id": "cis_rhel10_6-3.3.12", + "uuid": "fde92c0e-ecc6-4db5-b979-5ab6305a35e8", + "control-id": "cis_rhel10_1-1.1.9", "description": "REPLACE_ME", "props": [ { @@ -22778,18 +21833,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_login_events_faillock" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_login_events_lastlog" + "value": "kernel_module_firewire-core_disabled" } ] }, { - "uuid": "2798c8fc-598c-44a4-90d9-8032fcfb8863", - "control-id": "cis_rhel10_6-3.3.13", + "uuid": "d3843bf6-5c14-4db1-b680-3c4e701d1d55", + "control-id": "cis_rhel10_1-1.2.3.1", "description": "REPLACE_ME", "props": [ { @@ -22800,33 +21850,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_rename" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_renameat" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_renameat2" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_unlink" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_file_deletion_events_unlinkat" + "value": "partition_for_home" } ] }, { - "uuid": "f9bb922f-7cf8-42b5-87b3-82f3d11c7438", - "control-id": "cis_rhel10_6-3.3.14", + "uuid": "e8ef46a7-4a8c-4ed1-954f-64f585898b01", + "control-id": "cis_rhel10_1-1.2.4.1", "description": "REPLACE_ME", "props": [ { @@ -22837,18 +21867,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_mac_modification_etc_selinux" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_mac_modification_usr_share" + "value": "partition_for_var" } ] }, { - "uuid": "faa8624a-947a-4c6f-a88b-77834d68423b", - "control-id": "cis_rhel10_6-3.3.15", + "uuid": "e3b7d456-c90c-4218-8143-1fa85d502ce2", + "control-id": "cis_rhel10_1-1.2.5.1", "description": "REPLACE_ME", "props": [ { @@ -22859,13 +21884,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_execution_chcon" + "value": "partition_for_var_tmp" } ] }, { - "uuid": "f3d014ff-6562-46ff-aba2-38c103d98819", - "control-id": "cis_rhel10_6-3.3.16", + "uuid": "2ba1775a-ecfd-43f2-af03-f4e95966bf64", + "control-id": "cis_rhel10_1-1.2.6.1", "description": "REPLACE_ME", "props": [ { @@ -22876,13 +21901,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_execution_setfacl" + "value": "partition_for_var_log" } ] }, { - "uuid": "af444839-1edd-4031-bf2d-adeb80fff401", - "control-id": "cis_rhel10_6-3.3.17", + "uuid": "8d39314d-cda3-4682-bee0-380a1b3d15a8", + "control-id": "cis_rhel10_1-1.2.7.1", "description": "REPLACE_ME", "props": [ { @@ -22893,30 +21918,26 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_execution_chacl" + "value": "partition_for_var_log_audit" } ] }, { - "uuid": "4d465fe1-951a-4d1d-b920-712a0862cbc9", - "control-id": "cis_rhel10_6-3.3.18", + "uuid": "d5d48026-368e-433e-aa1f-85e106692e4e", + "control-id": "cis_rhel10_1-2.1.3", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_privileged_commands_usermod" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "3f414e1b-91fb-4541-9e27-75fe413fc48b", - "control-id": "cis_rhel10_6-3.3.19", + "uuid": "74f154c1-dfce-45bd-b431-c31eac827b4d", + "control-id": "cis_rhel10_1-3.1.5", "description": "REPLACE_ME", "props": [ { @@ -22927,33 +21948,43 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_delete" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_finit" - }, + "value": "selinux_state" + } + ] + }, + { + "uuid": "88341d5f-9639-490c-9265-6f88b950b442", + "control-id": "cis_rhel10_1-3.1.6", + "description": "REPLACE_ME", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_init" - }, + "value": "alternative", + "remarks": "REPLACE_ME" + } + ] + }, + { + "uuid": "1922c93f-d614-4d5b-8fb4-e46287715f0a", + "control-id": "cis_rhel10_1-5.3", + "description": "REPLACE_ME", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_kernel_module_loading_query" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_privileged_commands_kmod" + "value": "sysctl_fs_protected_symlinks" } ] }, { - "uuid": "551e197f-cfc1-496c-898a-39fb0e0daa0a", - "control-id": "cis_rhel10_6-3.3.20", + "uuid": "85ad7534-5812-4127-ace3-53afe65b95a4", + "control-id": "cis_rhel10_1-8.4", "description": "REPLACE_ME", "props": [ { @@ -22964,13 +21995,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "audit_rules_immutable" + "value": "dconf_gnome_disable_automount" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "dconf_gnome_disable_automount_open" } ] }, { - "uuid": "632fcc94-93ab-44b0-bae5-3277d66e34a5", - "control-id": "cis_rhel10_6-3.3.21", + "uuid": "6ec5a411-fdd1-4a24-ad9d-723de0155867", + "control-id": "cis_rhel10_1-8.6", "description": "REPLACE_ME", "props": [ { @@ -22982,8 +22018,8 @@ ] }, { - "uuid": "0d9204a2-5ed3-4da1-a00d-05125a8cb046", - "control-id": "cis_rhel10_6-3.4.1", + "uuid": "803a476c-57d8-40d9-a0a6-d660862e3c87", + "control-id": "cis_rhel10_2-1.1", "description": "REPLACE_ME", "props": [ { @@ -22994,13 +22030,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "directory_permissions_var_log_audit" + "value": "service_autofs_disabled" } ] }, { - "uuid": "e47258d2-61b9-4d4f-91c2-2c1415212b85", - "control-id": "cis_rhel10_6-3.4.2", + "uuid": "7a28c19f-df32-47f9-8a71-cc5018432923", + "control-id": "cis_rhel10_2-1.2", "description": "REPLACE_ME", "props": [ { @@ -23011,13 +22047,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_var_log_audit" + "value": "service_avahi-daemon_disabled" } ] }, { - "uuid": "f1f5d112-0264-4ebb-8317-1d89989dc38b", - "control-id": "cis_rhel10_6-3.4.3", + "uuid": "86ea5861-ebff-45f2-a8d8-5157f5c42d37", + "control-id": "cis_rhel10_2-1.3", "description": "REPLACE_ME", "props": [ { @@ -23028,13 +22064,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_var_log_audit_stig" + "value": "service_cockpit_disabled" } ] }, { - "uuid": "bf3c439b-0148-463c-950a-a417c8846368", - "control-id": "cis_rhel10_6-3.4.4", + "uuid": "0be5039d-ad36-4ce2-9573-1eb0609a9e36", + "control-id": "cis_rhel10_2-2.2", "description": "REPLACE_ME", "props": [ { @@ -23045,13 +22081,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_group_ownership_var_log_audit" + "value": "package_openldap-clients_removed" } ] }, { - "uuid": "d1bee4a7-6e7b-4773-bcd8-7ad24c618d1b", - "control-id": "cis_rhel10_6-3.4.5", + "uuid": "0f9d856e-2fad-49b6-a81f-2bcd261a6602", + "control-id": "cis_rhel10_3-1.3", "description": "REPLACE_ME", "props": [ { @@ -23062,13 +22098,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_audit_configuration" + "value": "service_bluetooth_disabled" } ] }, { - "uuid": "822f5452-93c0-41aa-ad81-f159876888aa", - "control-id": "cis_rhel10_6-3.4.6", + "uuid": "9b2e7c9d-ae3a-476f-89e4-602ec0880764", + "control-id": "cis_rhel10_5-2.4", "description": "REPLACE_ME", "props": [ { @@ -23079,13 +22115,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_audit_configuration" + "value": "sudo_require_authentication" } ] }, { - "uuid": "9bb9657a-dc4e-4d00-af6b-fe91424dfc20", - "control-id": "cis_rhel10_6-3.4.7", + "uuid": "f960be33-7b2c-40f5-a6ef-f3b63f4d80c7", + "control-id": "cis_rhel10_5-4.1.2", "description": "REPLACE_ME", "props": [ { @@ -23096,13 +22132,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_audit_configuration" + "value": "accounts_minimum_age_login_defs" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_password_set_min_life_existing" } ] }, { - "uuid": "9cdac4e7-43fa-40bb-8cfc-4acd80c03cf3", - "control-id": "cis_rhel10_6-3.4.8", + "uuid": "9e968bd2-53ce-4581-87f3-f31060869da4", + "control-id": "cis_rhel10_5-4.3.1", "description": "REPLACE_ME", "props": [ { @@ -23113,13 +22154,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_audit_binaries" + "value": "no_nologin_in_shells" } ] }, { - "uuid": "c2095224-df39-492b-9924-cd39f020253b", - "control-id": "cis_rhel10_6-3.4.9", + "uuid": "30fd9f3f-7581-462d-8a29-0ca0d04d9b3c", + "control-id": "cis_rhel10_6-3.1.1", "description": "REPLACE_ME", "props": [ { @@ -23130,13 +22171,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_audit_binaries" + "value": "package_audit_installed" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "package_audit-libs_installed" } ] }, { - "uuid": "4f4e6339-1c44-4f4f-9a64-2b90b324a6bf", - "control-id": "cis_rhel10_6-3.4.10", + "uuid": "44b6a3c8-3a0f-4c69-824e-83f1bf611a65", + "control-id": "cis_rhel10_6-3.1.2", "description": "REPLACE_ME", "props": [ { @@ -23147,27 +22193,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_audit_binaries" + "value": "grub2_audit_argument" } ] }, { - "uuid": "f42d91bf-1e1a-4f8e-96b3-174c83b01f94", - "control-id": "cis_rhel10_7-1.14", + "uuid": "579198be-e21e-4c49-9f08-e498b29aa76d", + "control-id": "cis_rhel10_6-3.1.3", "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" - } - ] - }, - { - "uuid": "47852d48-a417-46ba-8ad8-30d460a81d84", - "control-id": "reload_dconf_db", - "description": "This is a helper rule to reload Dconf database correctly.", "props": [ { "name": "implementation-status", @@ -23177,13 +22210,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_db_up_to_date" + "value": "grub2_audit_backlog_limit_argument" } ] }, { - "uuid": "c371a666-d9e1-44df-8123-ffbd63e9796f", - "control-id": "cis_rhel10_1-1.2.1.1", + "uuid": "4418b4d7-3da7-446c-93aa-86db4821aee8", + "control-id": "cis_rhel10_6-3.1.4", "description": "REPLACE_ME", "props": [ { @@ -23194,13 +22227,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_tmp" + "value": "service_auditd_enabled" } ] }, { - "uuid": "5752315a-c3e3-4886-85ca-56e44dc2c16a", - "control-id": "cis_rhel10_1-1.2.1.2", + "uuid": "778949e8-59c5-4c56-b70b-4200194cad67", + "control-id": "cis_rhel10_6-3.2.1", "description": "REPLACE_ME", "props": [ { @@ -23211,13 +22244,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_nodev" + "value": "auditd_data_retention_max_log_file" } ] }, { - "uuid": "4a2425ac-4f3d-494d-975e-fda3b0d59e6d", - "control-id": "cis_rhel10_1-1.2.1.3", + "uuid": "9d990bab-088e-4b78-9196-5595415c83cb", + "control-id": "cis_rhel10_6-3.2.2", "description": "REPLACE_ME", "props": [ { @@ -23228,13 +22261,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_nosuid" + "value": "auditd_data_retention_max_log_file_action" } ] }, { - "uuid": "8cc19ca3-a374-46ea-9ba9-2368a64b0b03", - "control-id": "cis_rhel10_1-1.2.1.4", + "uuid": "19b55155-5358-4d51-b68f-edcf17ad5044", + "control-id": "cis_rhel10_6-3.2.3", "description": "REPLACE_ME", "props": [ { @@ -23245,13 +22278,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_tmp_noexec" + "value": "auditd_data_disk_error_action" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "auditd_data_disk_full_action" } ] }, { - "uuid": "ed20106e-614a-4dc0-97cb-40fffae316a8", - "control-id": "cis_rhel10_1-1.2.2.1", + "uuid": "dbafc3a4-0923-4eb6-a05d-05480a20bce0", + "control-id": "cis_rhel10_6-3.2.4", "description": "REPLACE_ME", "props": [ { @@ -23262,13 +22300,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partition_for_dev_shm" + "value": "auditd_data_retention_action_mail_acct" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "auditd_data_retention_admin_space_left_action" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "auditd_data_retention_space_left_action" } ] }, { - "uuid": "bee789a2-5bbd-4c6b-8f5b-0561ddc85438", - "control-id": "cis_rhel10_1-1.2.2.2", + "uuid": "02e8a339-7b58-40d5-92cc-6822e91c889e", + "control-id": "cis_rhel10_6-3.3.1", "description": "REPLACE_ME", "props": [ { @@ -23279,13 +22327,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_nodev" + "value": "audit_rules_sysadmin_actions" } ] }, { - "uuid": "8af57239-d95a-499c-bd5c-565c93a14ed3", - "control-id": "cis_rhel10_1-1.2.2.3", + "uuid": "f06fdb74-cb6a-4044-857f-29e2b285e2ca", + "control-id": "cis_rhel10_6-3.3.2", "description": "REPLACE_ME", "props": [ { @@ -23296,13 +22344,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_nosuid" + "value": "audit_rules_suid_auid_privilege_function" } ] }, { - "uuid": "36232733-9d2b-4725-a449-82ed4b5c6a14", - "control-id": "cis_rhel10_1-1.2.2.4", + "uuid": "ca956014-6c6c-450f-b824-5917eb551424", + "control-id": "cis_rhel10_6-3.3.3", "description": "REPLACE_ME", "props": [ { @@ -23313,13 +22361,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_dev_shm_noexec" + "value": "audit_sudo_log_events" } ] }, { - "uuid": "532549b3-387e-4b64-87a1-5fb9356736f9", - "control-id": "cis_rhel10_1-1.2.3.2", + "uuid": "8fd5b953-f8ec-4109-b07b-72c715f8b4ae", + "control-id": "cis_rhel10_6-3.3.4", "description": "REPLACE_ME", "props": [ { @@ -23330,47 +22378,40 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_home_nodev" - } - ] - }, - { - "uuid": "ad60b9da-f909-45cf-8377-a0c58ec03fdd", - "control-id": "cis_rhel10_1-1.2.3.3", - "description": "REPLACE_ME", - "props": [ + "value": "audit_rules_time_adjtimex" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "audit_rules_time_settimeofday" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_home_nosuid" + "value": "audit_rules_time_clock_settime" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_time_watch_localtime" } ] }, { - "uuid": "a759b56a-cbaf-475f-9865-6215a4a84e3b", - "control-id": "cis_rhel10_1-1.2.4.2", - "description": "REPLACE_ME", + "uuid": "473f6506-e685-41e3-8bdf-f0e691bd8c5a", + "control-id": "cis_rhel10_6-3.3.5", + "description": "This requirement is covered by 6.3.3.6.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_nodev" } ] }, { - "uuid": "e36f9469-69d0-4172-929a-62d2b94dc42f", - "control-id": "cis_rhel10_1-1.2.4.3", + "uuid": "64dda874-06b2-470a-a327-33cfdd0a53e4", + "control-id": "cis_rhel10_6-3.3.6", "description": "REPLACE_ME", "props": [ { @@ -23381,31 +22422,26 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_nosuid" + "value": "audit_rules_networkconfig_modification" } ] }, { - "uuid": "c7924b28-e893-4ff9-8c19-693082083fef", - "control-id": "cis_rhel10_1-1.2.5.2", - "description": "REPLACE_ME", + "uuid": "31f822a9-1b85-4cb6-b61d-3a74d20f6d70", + "control-id": "cis_rhel10_6-3.3.7", + "description": "This requirement is partially covered by 6.3.3.6.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_tmp_nodev" } ] }, { - "uuid": "74a1850f-28f3-49a8-8714-38ba655f2cf7", - "control-id": "cis_rhel10_1-1.2.5.3", - "description": "REPLACE_ME", + "uuid": "bfefd31b-e9c7-484b-bd03-fab8c87a836c", + "control-id": "cis_rhel10_6-3.3.8", + "description": "This requirement is partially covered by 6.3.3.6.", "props": [ { "name": "implementation-status", @@ -23415,30 +22451,25 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_tmp_nosuid" + "value": "audit_rules_networkconfig_modification_network_scripts" } ] }, { - "uuid": "cbd10ea6-8608-4168-904c-5f895e7160ce", - "control-id": "cis_rhel10_1-1.2.5.4", - "description": "REPLACE_ME", + "uuid": "49bbcce7-228d-41fe-a7af-c28600df097c", + "control-id": "cis_rhel10_6-3.3.9", + "description": "This requirement is covered by 6.3.3.6.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_tmp_noexec" } ] }, { - "uuid": "8bb86390-6add-4066-bbac-5b95839f1f47", - "control-id": "cis_rhel10_1-1.2.6.2", + "uuid": "4a8cdefe-9da2-44d1-b421-cf3b194e3e28", + "control-id": "cis_rhel10_6-3.3.10", "description": "REPLACE_ME", "props": [ { @@ -23449,13 +22480,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_nodev" + "value": "audit_rules_privileged_commands" } ] }, { - "uuid": "e295fbb9-04a0-45a5-bd24-827f287dc1f2", - "control-id": "cis_rhel10_1-1.2.6.3", + "uuid": "9f78fb5a-34fa-459a-bfa1-0094e86af48c", + "control-id": "cis_rhel10_6-3.3.11", "description": "REPLACE_ME", "props": [ { @@ -23466,30 +22497,33 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_nosuid" - } - ] - }, - { - "uuid": "1e049030-f166-47e4-a32b-22be0b89df74", - "control-id": "cis_rhel10_1-1.2.6.4", - "description": "REPLACE_ME", - "props": [ + "value": "audit_rules_unsuccessful_file_modification_creat" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "audit_rules_unsuccessful_file_modification_ftruncate" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_noexec" + "value": "audit_rules_unsuccessful_file_modification_open" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_unsuccessful_file_modification_openat" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_unsuccessful_file_modification_truncate" } ] }, { - "uuid": "7612f171-d730-4834-bb40-00cbdc467924", - "control-id": "cis_rhel10_1-1.2.7.2", + "uuid": "0f1a82da-4763-47d1-8b71-da838caa1a94", + "control-id": "cis_rhel10_6-3.3.12", "description": "REPLACE_ME", "props": [ { @@ -23500,13 +22534,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_audit_nodev" + "value": "audit_rules_usergroup_modification_group" } ] }, { - "uuid": "111f726f-5a82-46b4-985d-8d2a306f8aa6", - "control-id": "cis_rhel10_1-1.2.7.3", + "uuid": "4554cfda-c29a-4be3-891a-9e2ec95e223b", + "control-id": "cis_rhel10_6-3.3.13", "description": "REPLACE_ME", "props": [ { @@ -23517,13 +22551,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_audit_nosuid" + "value": "audit_rules_usergroup_modification_passwd" } ] }, { - "uuid": "8826d9a2-4b48-4a0c-9ab9-0b98e3101c09", - "control-id": "cis_rhel10_1-1.2.7.4", + "uuid": "013ef2ef-205b-41c4-b6b6-8eb87b6c9158", + "control-id": "cis_rhel10_6-3.3.14", "description": "REPLACE_ME", "props": [ { @@ -23534,26 +22568,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "mount_option_var_log_audit_noexec" - } - ] - }, - { - "uuid": "cb40c235-45f8-4ddc-987c-bf747433ec91", - "control-id": "cis_rhel10_1-2.1.1", - "description": "REPLACE_ME", - "props": [ + "value": "audit_rules_usergroup_modification_gshadow" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "audit_rules_usergroup_modification_shadow" } ] }, { - "uuid": "6ca2994c-d9af-4b9c-bccd-0a6a639fdffa", - "control-id": "cis_rhel10_1-2.1.2", + "uuid": "c981ef23-9a41-4d89-aa11-1367128dc829", + "control-id": "cis_rhel10_6-3.3.15", "description": "REPLACE_ME", "props": [ { @@ -23564,13 +22590,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_gpgcheck_globally_activated" + "value": "audit_rules_usergroup_modification_opasswd" } ] }, { - "uuid": "d893db0a-11ee-4868-bad5-9410efc2d2d7", - "control-id": "cis_rhel10_1-2.1.4", + "uuid": "6cb4e235-5179-4dd2-a8a4-f0d40b959a8c", + "control-id": "cis_rhel10_6-3.3.16", "description": "REPLACE_ME", "props": [ { @@ -23582,8 +22608,8 @@ ] }, { - "uuid": "89f233ad-b466-4602-ac7b-70a1e30ccc43", - "control-id": "cis_rhel10_1-2.2.1", + "uuid": "e745e9b2-9ea5-473f-9f08-683dc82b52dd", + "control-id": "cis_rhel10_6-3.3.17", "description": "REPLACE_ME", "props": [ { @@ -23595,8 +22621,8 @@ ] }, { - "uuid": "8fae3803-7f9d-4007-8aed-f68d205f0125", - "control-id": "cis_rhel10_1-3.1.1", + "uuid": "81d5c160-4f0a-4095-968e-30d7afb0de75", + "control-id": "cis_rhel10_6-3.3.18", "description": "REPLACE_ME", "props": [ { @@ -23607,13 +22633,28 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_libselinux_installed" + "value": "audit_rules_dac_modification_chmod" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_dac_modification_fchmod" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_dac_modification_fchmodat" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_dac_modification_fchmodat2" } ] }, { - "uuid": "7af04bef-4152-46e5-adf3-31295801dd8c", - "control-id": "cis_rhel10_1-3.1.2", + "uuid": "5a855d14-821d-4d27-8e39-d87f44ced460", + "control-id": "cis_rhel10_6-3.3.19", "description": "REPLACE_ME", "props": [ { @@ -23624,13 +22665,28 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "grub2_enable_selinux" + "value": "audit_rules_dac_modification_chown" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_dac_modification_fchown" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_dac_modification_fchownat" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_dac_modification_lchown" } ] }, { - "uuid": "f9d7dc41-c58b-414f-b19b-c57a0a47359b", - "control-id": "cis_rhel10_1-3.1.3", + "uuid": "e459d0cb-1474-4a43-8ab4-dad6720cc732", + "control-id": "cis_rhel10_6-3.3.20", "description": "REPLACE_ME", "props": [ { @@ -23641,13 +22697,38 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "selinux_policytype" + "value": "audit_rules_dac_modification_fremovexattr" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_dac_modification_fsetxattr" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_dac_modification_lremovexattr" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_dac_modification_lsetxattr" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_dac_modification_removexattr" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "audit_rules_dac_modification_setxattr" } ] }, { - "uuid": "4079dddd-dbbe-4d45-8e34-d2b5dcfdd53a", - "control-id": "cis_rhel10_1-3.1.4", + "uuid": "491ccc90-22eb-4933-ad2b-4368eba79f90", + "control-id": "cis_rhel10_6-3.3.21", "description": "REPLACE_ME", "props": [ { @@ -23658,13 +22739,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "selinux_not_disabled" + "value": "audit_rules_media_export" } ] }, { - "uuid": "bbe6419c-97b0-4cbc-b993-390757309227", - "control-id": "cis_rhel10_1-3.1.7", + "uuid": "6ff5563b-c68c-4258-8d3d-9be0b59a23bd", + "control-id": "cis_rhel10_6-3.4.1", "description": "REPLACE_ME", "props": [ { @@ -23675,14 +22756,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_mcstrans_removed" + "value": "directory_permissions_var_log_audit" } ] }, { - "uuid": "e63a67d6-fced-4628-a72b-57b10ba9efa0", - "control-id": "cis_rhel10_1-4.1", - "description": "There is no automated remediation for this rule and this is intentional.\nMore details in the rule description.", + "uuid": "43ea24a7-f757-490d-9ad0-27349573b2d0", + "control-id": "cis_rhel10_6-3.4.2", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -23692,57 +22773,48 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "grub2_password" + "value": "file_permissions_var_log_audit" } ] }, { - "uuid": "d9a2c9f2-e31a-4698-a4c7-9401523b6a79", - "control-id": "cis_rhel10_1-4.2", + "uuid": "09fc9803-2e7a-4dfa-9ad9-19f7d44c294f", + "control-id": "cis_rhel10_6-3.4.3", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "This requirement demands a deeper review of the rules." - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_grub2_cfg" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_grub2_cfg" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_grub2_cfg" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_user_cfg" - }, + "value": "file_ownership_var_log_audit_stig" + } + ] + }, + { + "uuid": "c8b19352-de0c-4955-aa64-846404830ebb", + "control-id": "cis_rhel10_6-3.4.4", + "description": "REPLACE_ME", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_user_cfg" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_user_cfg" + "value": "file_group_ownership_var_log_audit" } ] }, { - "uuid": "dbd09918-02d5-4091-8f81-6faba5df9ea9", - "control-id": "cis_rhel10_1-5.1", - "description": "Address Space Layout Randomization (ASLR)", + "uuid": "a400103d-f22e-4aa9-a532-2810e84bffd6", + "control-id": "cis_rhel10_6-3.4.5", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -23752,13 +22824,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_kernel_randomize_va_space" + "value": "file_permissions_audit_configuration" } ] }, { - "uuid": "cf249caa-88ac-4ea3-a7c4-f1f9b26a5849", - "control-id": "cis_rhel10_1-5.2", + "uuid": "d1e00ae4-700e-4a35-b32b-93c9629ab741", + "control-id": "cis_rhel10_6-3.4.6", "description": "REPLACE_ME", "props": [ { @@ -23769,13 +22841,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_kernel_yama_ptrace_scope" + "value": "file_ownership_audit_configuration" } ] }, { - "uuid": "dd3bb034-ef9d-4ef6-9def-76c62e486804", - "control-id": "cis_rhel10_1-5.3", + "uuid": "30f3e9ac-0470-49a9-96d7-3e9e7732b33a", + "control-id": "cis_rhel10_6-3.4.7", "description": "REPLACE_ME", "props": [ { @@ -23786,13 +22858,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_backtraces" + "value": "file_groupownership_audit_configuration" } ] }, { - "uuid": "8b500ce7-df4c-42af-a498-e269be0fd3d7", - "control-id": "cis_rhel10_1-5.4", + "uuid": "0f27bfb0-73bc-4c68-9614-f03fba09bf77", + "control-id": "cis_rhel10_6-3.4.8", "description": "REPLACE_ME", "props": [ { @@ -23803,13 +22875,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "coredump_disable_storage" + "value": "file_permissions_audit_binaries" } ] }, { - "uuid": "7d6a2c52-ce28-46d0-9e28-f7878710e3fd", - "control-id": "cis_rhel10_1-6.1", + "uuid": "ecad33d4-9985-4cf3-9194-5210a9a29036", + "control-id": "cis_rhel10_6-3.4.9", "description": "REPLACE_ME", "props": [ { @@ -23820,13 +22892,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_crypto_policy" + "value": "file_ownership_audit_binaries" } ] }, { - "uuid": "2bdd015b-840f-4f21-a86f-15763ce43741", - "control-id": "cis_rhel10_1-6.2", + "uuid": "462f72be-485e-4510-afd3-9d94e8a22b24", + "control-id": "cis_rhel10_6-3.4.10", "description": "REPLACE_ME", "props": [ { @@ -23837,77 +22909,98 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "configure_ssh_crypto_policy" + "value": "file_groupownership_audit_binaries" } ] }, { - "uuid": "09943b89-2e2d-456b-a20e-47013e9258d8", - "control-id": "cis_rhel10_1-6.3", - "description": "This requirement is already satisfied by 1.6.1.", + "uuid": "f0368d6a-b76f-4156-ab8c-48bbba3345f6", + "control-id": "reload_dconf_db", + "description": "This is a helper rule to reload Dconf database correctly.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "dconf_db_up_to_date" } ] }, { - "uuid": "287f2124-f2f5-469c-86e7-89fe227c6e93", - "control-id": "cis_rhel10_1-6.4", + "uuid": "bf77f7ab-d0be-4b0f-bf29-97f6b3cddda7", + "control-id": "cis_rhel10_1-1.2.1.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary a new rule to ensure a module disabling weak MACs in\n/etc/crypto-policies/policies/modules/ so it can be used by update-crypto-policies command." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "partition_for_tmp" } ] }, { - "uuid": "2b01a806-7b2f-467a-8ee8-ea072df9869f", - "control-id": "cis_rhel10_1-6.5", + "uuid": "52f9fd8d-2dea-4a97-85e0-c88996714952", + "control-id": "cis_rhel10_1-1.2.1.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary a new rule to ensure a module disabling CBC in\n/etc/crypto-policies/policies/modules/ so it can be used by update-crypto-policies command." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "mount_option_tmp_nodev" } ] }, { - "uuid": "6be13061-753c-4400-bf81-fbd4be5064c2", - "control-id": "cis_rhel10_1-6.6", + "uuid": "e767597f-1e4f-4e05-af03-5bbb4d7b7a1d", + "control-id": "cis_rhel10_1-1.2.1.3", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "mount_option_tmp_nosuid" } ] }, { - "uuid": "3ba5e132-7b80-4fbf-9361-ab41cea65191", - "control-id": "cis_rhel10_1-6.7", + "uuid": "877852ed-610d-43bc-bcdd-9ef55734c215", + "control-id": "cis_rhel10_1-1.2.1.4", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "mount_option_tmp_noexec" } ] }, { - "uuid": "49417c79-5ddf-48cf-a579-489d7db6eab9", - "control-id": "cis_rhel10_1-7.1", + "uuid": "bb340b6e-ab6b-44aa-95ed-376079f41f89", + "control-id": "cis_rhel10_1-1.2.2.1", "description": "REPLACE_ME", "props": [ { @@ -23918,13 +23011,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "banner_etc_motd_cis" + "value": "partition_for_dev_shm" } ] }, { - "uuid": "5f341ffa-af9b-4354-b5b6-5c0f4d8390af", - "control-id": "cis_rhel10_1-7.2", + "uuid": "ae2d4d63-e374-4d21-b0cd-4752554124e5", + "control-id": "cis_rhel10_1-1.2.2.2", "description": "REPLACE_ME", "props": [ { @@ -23935,13 +23028,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "banner_etc_issue_cis" + "value": "mount_option_dev_shm_nodev" } ] }, { - "uuid": "dbd8f5b5-f46e-4d97-a0d8-c9eaceeae7c8", - "control-id": "cis_rhel10_1-7.3", + "uuid": "7c6201a5-b9d9-44a2-afc9-dc1898cca2d1", + "control-id": "cis_rhel10_1-1.2.2.3", "description": "REPLACE_ME", "props": [ { @@ -23952,13 +23045,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "banner_etc_issue_net_cis" + "value": "mount_option_dev_shm_nosuid" } ] }, { - "uuid": "e4bc719a-0792-4de4-8a5a-dd67bac2b44e", - "control-id": "cis_rhel10_1-7.4", + "uuid": "3dcc125b-f02e-4d8d-b58c-41b594fc4b49", + "control-id": "cis_rhel10_1-1.2.2.4", "description": "REPLACE_ME", "props": [ { @@ -23969,23 +23062,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_motd" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_motd" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_motd" + "value": "mount_option_dev_shm_noexec" } ] }, { - "uuid": "58c7d5d2-b4e0-4bce-9942-3f8dbd27d489", - "control-id": "cis_rhel10_1-7.5", + "uuid": "730cc661-3610-4a6c-a676-ce8a952099ed", + "control-id": "cis_rhel10_1-1.2.3.2", "description": "REPLACE_ME", "props": [ { @@ -23996,23 +23079,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_issue" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_issue" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_issue" + "value": "mount_option_home_nodev" } ] }, { - "uuid": "2a71ad2a-4cf1-44c6-abf7-1a96387d1996", - "control-id": "cis_rhel10_1-7.6", + "uuid": "0219c92c-ea5e-416f-840d-69320f85e49a", + "control-id": "cis_rhel10_1-1.2.3.3", "description": "REPLACE_ME", "props": [ { @@ -24023,23 +23096,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_etc_issue_net" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_etc_issue_net" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_etc_issue_net" + "value": "mount_option_home_nosuid" } ] }, { - "uuid": "973b7aa2-298b-422d-8777-1e636c295982", - "control-id": "cis_rhel10_1-8.2", + "uuid": "24751cf8-9353-4989-a1a6-e293846c25cb", + "control-id": "cis_rhel10_1-1.2.4.2", "description": "REPLACE_ME", "props": [ { @@ -24050,18 +23113,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_banner_enabled" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_login_banner_text" + "value": "mount_option_var_nodev" } ] }, { - "uuid": "933f5cc9-010e-4204-9f20-398528ed4127", - "control-id": "cis_rhel10_1-8.3", + "uuid": "c562ef78-f308-432c-9828-81c1b3d32e9e", + "control-id": "cis_rhel10_1-1.2.4.3", "description": "REPLACE_ME", "props": [ { @@ -24072,13 +23130,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_user_list" + "value": "mount_option_var_nosuid" } ] }, { - "uuid": "3a0df3f2-87a4-40fb-9ca0-e7fdbb00887e", - "control-id": "cis_rhel10_1-8.4", + "uuid": "e85d5523-d676-427f-b4ea-254427d4e504", + "control-id": "cis_rhel10_1-1.2.5.2", "description": "REPLACE_ME", "props": [ { @@ -24089,18 +23147,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_screensaver_idle_delay" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_screensaver_lock_delay" + "value": "mount_option_var_tmp_nodev" } ] }, { - "uuid": "12b9763d-24f3-4668-8ffa-987f6241bfe8", - "control-id": "cis_rhel10_1-8.5", + "uuid": "5f34d356-a611-420b-9c2e-d8e79c8a0665", + "control-id": "cis_rhel10_1-1.2.5.3", "description": "REPLACE_ME", "props": [ { @@ -24111,18 +23164,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_session_idle_user_locks" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_screensaver_user_locks" + "value": "mount_option_var_tmp_nosuid" } ] }, { - "uuid": "009bb863-7a46-45b0-835a-8f237b5b8d18", - "control-id": "cis_rhel10_1-8.8", + "uuid": "667d42b9-e672-4f77-9882-198201fb1c8c", + "control-id": "cis_rhel10_1-1.2.5.4", "description": "REPLACE_ME", "props": [ { @@ -24133,13 +23181,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_autorun" + "value": "mount_option_var_tmp_noexec" } ] }, { - "uuid": "fafef557-d425-44be-97c8-c6f56103a42f", - "control-id": "cis_rhel10_1-8.9", + "uuid": "718fdb23-f6b9-4f51-882b-c03a650dd981", + "control-id": "cis_rhel10_1-1.2.6.2", "description": "REPLACE_ME", "props": [ { @@ -24150,25 +23198,30 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "dconf_gnome_disable_autorun" + "value": "mount_option_var_log_nodev" } ] }, { - "uuid": "79690fa7-daac-423f-8f44-68479763f2d2", - "control-id": "cis_rhel10_1-8.10", - "description": "This was inherited from the RHEL 9 profile.\nHowever, it was reported that XDMCP is no\nlonger in RHEL 10.", + "uuid": "aa4e0f93-a04d-4dec-a6f7-33e2a25f256b", + "control-id": "cis_rhel10_1-1.2.6.3", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "mount_option_var_log_nosuid" } ] }, { - "uuid": "3c61ad4f-ee15-40ad-b77a-f69b3a1d860b", - "control-id": "cis_rhel10_2-1.3", + "uuid": "7e35b866-5de4-4b24-bb43-3d314820b656", + "control-id": "cis_rhel10_1-1.2.6.4", "description": "REPLACE_ME", "props": [ { @@ -24179,13 +23232,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_kea_removed" + "value": "mount_option_var_log_noexec" } ] }, { - "uuid": "7de09174-3755-4fbb-8ecc-4516b5345f2d", - "control-id": "cis_rhel10_2-1.4", + "uuid": "575db5c1-4e39-4ab2-ab5f-bdb0e5e806c0", + "control-id": "cis_rhel10_1-1.2.7.2", "description": "REPLACE_ME", "props": [ { @@ -24196,13 +23249,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_bind_removed" + "value": "mount_option_var_log_audit_nodev" } ] }, { - "uuid": "418aa448-eca9-44a0-8686-d08e57e4e852", - "control-id": "cis_rhel10_2-1.5", + "uuid": "206b29ec-4258-4b52-b515-53aefdf2b188", + "control-id": "cis_rhel10_1-1.2.7.3", "description": "REPLACE_ME", "props": [ { @@ -24213,13 +23266,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_dnsmasq_removed" + "value": "mount_option_var_log_audit_nosuid" } ] }, { - "uuid": "313cb5b3-e5d2-4272-9c09-6e7e0752c587", - "control-id": "cis_rhel10_2-1.6", + "uuid": "83b75309-a92c-42fc-8bf3-213dc4316aa9", + "control-id": "cis_rhel10_1-1.2.7.4", "description": "REPLACE_ME", "props": [ { @@ -24230,30 +23283,26 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_samba_removed" + "value": "mount_option_var_log_audit_noexec" } ] }, { - "uuid": "b4a309cb-25c3-4d22-b566-0ac775ddfb1a", - "control-id": "cis_rhel10_2-1.7", + "uuid": "1faf3c87-ae6a-4a14-ac53-b4a224ae96df", + "control-id": "cis_rhel10_1-2.1.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_vsftpd_removed" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "bb430462-a494-43d0-9c14-8cebd6d9be50", - "control-id": "cis_rhel10_2-1.8", + "uuid": "ff73d10d-421a-4404-b248-d7e2ab861032", + "control-id": "cis_rhel10_1-2.1.2", "description": "REPLACE_ME", "props": [ { @@ -24264,48 +23313,40 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_dovecot_removed" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_cyrus-imapd_removed" + "value": "ensure_gpgcheck_globally_activated" } ] }, { - "uuid": "8ec55d4e-2e67-40c8-922f-dbe1cb99bded", - "control-id": "cis_rhel10_2-1.9", - "description": "Many of the libvirt packages used by Enterprise Linux virtualization are dependent on the\nnfs-utils package.", + "uuid": "3abf912d-4b7e-46ce-9db7-a2f6bcb3a918", + "control-id": "cis_rhel10_1-2.1.4", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_nfs_disabled" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "681f774b-de4a-42ff-846c-08fed8dd2d01", - "control-id": "cis_rhel10_2-1.10", + "uuid": "e95940d4-e7eb-4af1-9272-71eec9c0257a", + "control-id": "cis_rhel10_1-2.2.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "b19ee900-cdc5-44c0-85bb-7f7219e04344", - "control-id": "cis_rhel10_2-1.12", - "description": "Many of the libvirt packages used by Enterprise Linux virtualization, and the nfs-utils\npackage used for The Network File System (NFS), are dependent on the rpcbind package.", + "uuid": "0c124610-249b-4482-8f14-389a4a3a0578", + "control-id": "cis_rhel10_1-3.1.1", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -24315,13 +23356,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_rpcbind_disabled" + "value": "package_libselinux_installed" } ] }, { - "uuid": "a3df0758-9e6e-4a8e-b3ca-f132a49cc2e2", - "control-id": "cis_rhel10_2-1.13", + "uuid": "46f85680-2518-4cbd-b8bf-759579caa44f", + "control-id": "cis_rhel10_1-3.1.2", "description": "REPLACE_ME", "props": [ { @@ -24332,13 +23373,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_rsync_removed" + "value": "grub2_enable_selinux" } ] }, { - "uuid": "444ca943-e7a1-42f4-a3e5-b735081429de", - "control-id": "cis_rhel10_2-1.14", + "uuid": "cf5aee23-d9d3-4512-afe8-ae667c7fb90e", + "control-id": "cis_rhel10_1-3.1.3", "description": "REPLACE_ME", "props": [ { @@ -24349,13 +23390,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_net-snmp_removed" + "value": "selinux_policytype" } ] }, { - "uuid": "d5483fab-055b-4f66-b75a-71cc49e2479e", - "control-id": "cis_rhel10_2-1.15", + "uuid": "963c5032-71ea-4eef-80f3-6297261d3517", + "control-id": "cis_rhel10_1-3.1.4", "description": "REPLACE_ME", "props": [ { @@ -24366,13 +23407,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_telnet-server_removed" + "value": "selinux_not_disabled" } ] }, { - "uuid": "3df77768-1b95-4311-9afd-449c9a801361", - "control-id": "cis_rhel10_2-1.16", + "uuid": "c6e2939b-e069-4d72-b35d-d2f6ecf8137b", + "control-id": "cis_rhel10_1-3.1.7", "description": "REPLACE_ME", "props": [ { @@ -24383,14 +23424,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_tftp-server_removed" + "value": "package_mcstrans_removed" } ] }, { - "uuid": "857a8c7e-b483-4de2-8577-41ed34f34425", - "control-id": "cis_rhel10_2-1.17", - "description": "REPLACE_ME", + "uuid": "2e388ee4-d539-4725-b337-4abe17d00e15", + "control-id": "cis_rhel10_1-4.1", + "description": "There is no automated remediation for this rule and this is intentional.\nMore details in the rule description.", "props": [ { "name": "implementation-status", @@ -24400,70 +23441,90 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_squid_removed" + "value": "grub2_password" } ] }, { - "uuid": "c84dd773-9f4e-47ad-a885-4dcc5656a96a", - "control-id": "cis_rhel10_2-1.18", + "uuid": "505c20dd-6a31-4aa4-8ce6-6d8e57fc813e", + "control-id": "cis_rhel10_1-4.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "alternative", + "remarks": "This requirement demands a deeper review of the rules." + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_groupowner_grub2_cfg" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_owner_grub2_cfg" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_grub2_cfg" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_groupowner_user_cfg" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_httpd_removed" + "value": "file_owner_user_cfg" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_nginx_removed" + "value": "file_permissions_user_cfg" } ] }, { - "uuid": "e0430d2e-96dc-442b-95a7-918286601e02", - "control-id": "cis_rhel10_2-1.21", - "description": "The rule has_nonlocal_mta currently checks for services listening only on port 25,\nbut the policy checks also for ports 465 and 587", + "uuid": "61bbea51-bc5f-4655-8317-5f28f50ef386", + "control-id": "cis_rhel10_1-5.1", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "postfix_network_listening_disabled" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "has_nonlocal_mta" + "value": "disable_users_coredumps" } ] }, { - "uuid": "e655d556-a89a-4390-95e3-e9e4ba26c3ca", - "control-id": "cis_rhel10_2-1.22", + "uuid": "d5b3730d-3288-43e9-afca-59ac394a219b", + "control-id": "cis_rhel10_1-5.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sysctl_fs_protected_hardlinks" } ] }, { - "uuid": "85607b05-c493-4c84-96be-4c73b6d351b6", - "control-id": "cis_rhel10_2-2.1", + "uuid": "d6cc19e1-2dab-4d3b-a175-e87ab47b3455", + "control-id": "cis_rhel10_1-5.4", "description": "REPLACE_ME", "props": [ { @@ -24474,71 +23535,69 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_ftp_removed" + "value": "sysctl_fs_suid_dumpable" } ] }, { - "uuid": "6b6febe3-6b85-4352-86f0-60c1332cf891", - "control-id": "cis_rhel10_2-2.3", + "uuid": "7a85b968-77a2-4ba2-aa60-88e9de994e12", + "control-id": "cis_rhel10_1-6.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "configure_crypto_policy" } ] }, { - "uuid": "9de165d0-e8f7-4cc2-bfcc-c646fd8786bf", - "control-id": "cis_rhel10_2-2.4", + "uuid": "f8a0d7b3-f1bb-42de-983c-306a3db2a987", + "control-id": "cis_rhel10_1-6.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_telnet_removed" + "value": "alternative", + "remarks": "It is necessary a new rule to ensure a module disabling sha1 in\n/etc/crypto-policies/policies/modules/ so it can be used by update-crypto-policies command." } ] }, { - "uuid": "9b099a6e-31dc-4231-9301-fb11700cdc4e", - "control-id": "cis_rhel10_2-2.5", + "uuid": "4508b3f5-0ae7-4c78-8812-9e3b8e7a88c5", + "control-id": "cis_rhel10_1-6.3", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_tftp_removed" + "value": "alternative", + "remarks": "It is necessary a new rule to ensure a module disabling weak MACs in\n/etc/crypto-policies/policies/modules/ so it can be used by update-crypto-policies command." } ] }, { - "uuid": "650d0018-8e58-4aea-8b29-0e269d929e0a", - "control-id": "cis_rhel10_2-3.1", + "uuid": "4923231d-0fc4-4b40-bfdd-959aa471ee45", + "control-id": "cis_rhel10_1-6.4", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "alternative", + "remarks": "It is necessary a new rule to ensure a module disabling CBC in\n/etc/crypto-policies/policies/modules/ so it can be used by update-crypto-policies command." } ] }, { - "uuid": "b995b766-6101-46db-aae6-331766dcfacf", - "control-id": "cis_rhel10_2-3.2", + "uuid": "45101d2d-a011-42dc-8646-de532e353d8e", + "control-id": "cis_rhel10_1-7.1", "description": "REPLACE_ME", "props": [ { @@ -24549,13 +23608,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "chronyd_specify_remote_server" + "value": "banner_etc_motd_cis" } ] }, { - "uuid": "bbab0b51-cba5-4e96-8969-782c416e1ddd", - "control-id": "cis_rhel10_2-3.3", + "uuid": "5bfa2e51-f9ec-4274-809b-85e76d1944eb", + "control-id": "cis_rhel10_1-7.2", "description": "REPLACE_ME", "props": [ { @@ -24566,13 +23625,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "chronyd_run_as_chrony_user" + "value": "banner_etc_issue_cis" } ] }, { - "uuid": "5427f56c-5e9f-4ea3-8132-589f087310ad", - "control-id": "cis_rhel10_2-4.1.1", + "uuid": "d6cdd9f5-5b1f-44bb-99e0-53c9d0cd305f", + "control-id": "cis_rhel10_1-7.3", "description": "REPLACE_ME", "props": [ { @@ -24583,18 +23642,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_cron_installed" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_crond_enabled" + "value": "banner_etc_issue_net_cis" } ] }, { - "uuid": "ec1c605c-7c1e-423e-89df-5a0c5a8e6e94", - "control-id": "cis_rhel10_2-4.1.2", + "uuid": "34fd2684-f80c-4668-99fc-5facb9d13b5d", + "control-id": "cis_rhel10_1-7.4", "description": "REPLACE_ME", "props": [ { @@ -24605,23 +23659,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_crontab" + "value": "file_groupowner_etc_motd" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_crontab" + "value": "file_owner_etc_motd" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_crontab" + "value": "file_permissions_etc_motd" } ] }, { - "uuid": "6e82915b-4f1a-41f8-8720-c0fa55c9337b", - "control-id": "cis_rhel10_2-4.1.3", + "uuid": "4f634aa8-5f83-49a5-9a98-7ee07ee61520", + "control-id": "cis_rhel10_1-7.5", "description": "REPLACE_ME", "props": [ { @@ -24632,23 +23686,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_hourly" + "value": "file_groupowner_etc_issue" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_hourly" + "value": "file_owner_etc_issue" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_hourly" + "value": "file_permissions_etc_issue" } ] }, { - "uuid": "9b4185db-72f0-4918-8634-76a0d3b51ea6", - "control-id": "cis_rhel10_2-4.1.4", + "uuid": "cba8e280-ec84-4ad6-a8a5-d4c48a42c6c9", + "control-id": "cis_rhel10_1-7.6", "description": "REPLACE_ME", "props": [ { @@ -24659,23 +23713,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_daily" + "value": "file_groupowner_etc_issue_net" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_daily" + "value": "file_owner_etc_issue_net" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_daily" + "value": "file_permissions_etc_issue_net" } ] }, { - "uuid": "499e65a8-d5fd-4492-9b36-db4c12a0ddc5", - "control-id": "cis_rhel10_2-4.1.5", + "uuid": "2035a6ca-ed4e-4e09-aade-acaf0087c251", + "control-id": "cis_rhel10_1-8.2", "description": "REPLACE_ME", "props": [ { @@ -24686,23 +23740,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_weekly" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_weekly" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_weekly" + "value": "dconf_gnome_disable_user_list" } ] }, { - "uuid": "d1ecb2fe-6a34-4415-8c07-8e87eba427ba", - "control-id": "cis_rhel10_2-4.1.6", + "uuid": "730a7e26-18a8-4894-b6aa-343355056c6e", + "control-id": "cis_rhel10_1-8.3", "description": "REPLACE_ME", "props": [ { @@ -24713,23 +23757,28 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_monthly" + "value": "dconf_gnome_screensaver_idle_delay" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_monthly" + "value": "dconf_gnome_screensaver_lock_delay" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_monthly" + "value": "dconf_gnome_session_idle_user_locks" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "dconf_gnome_screensaver_user_locks" } ] }, { - "uuid": "2cce5ab6-e903-4e80-b640-101c6cbff8d1", - "control-id": "cis_rhel10_2-4.1.7", + "uuid": "c985bdea-7c8c-4d69-adc8-1ed4fd16f674", + "control-id": "cis_rhel10_1-8.5", "description": "REPLACE_ME", "props": [ { @@ -24740,23 +23789,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_d" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_d" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_d" + "value": "dconf_gnome_disable_autorun" } ] }, { - "uuid": "c63ac66f-0a92-4bab-a85b-e864f18bc5c6", - "control-id": "cis_rhel10_2-4.1.8", + "uuid": "7384250d-d948-474f-a5df-241ded07bfb1", + "control-id": "cis_rhel10_2-1.4", "description": "REPLACE_ME", "props": [ { @@ -24767,78 +23806,47 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_cron_deny_not_exist" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_cron_allow_exists" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_cron_allow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_cron_allow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_cron_allow" + "value": "package_kea_removed" } ] }, { - "uuid": "ec8794ee-3b30-433d-9635-268bea75b028", - "control-id": "cis_rhel10_2-4.2.1", - "description": "It is necessary to create a rule to ensure the existence of at.allow.\nfile_cron_allow_exists can be used as reference for a new templated rule.", + "uuid": "b52074e7-0273-41c9-a35f-fe175e2ba656", + "control-id": "cis_rhel10_2-1.5", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_at_deny_not_exist" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_at_allow" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_at_allow" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_at_allow" + "value": "package_bind_removed" } ] }, { - "uuid": "7788910b-7e8a-4d7e-81f9-5e9d9873c087", - "control-id": "cis_rhel10_3-1.1", + "uuid": "bf3608a3-f4e6-48b1-9372-b84b076300ed", + "control-id": "cis_rhel10_2-1.6", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "package_dnsmasq_removed" } ] }, { - "uuid": "3860a478-5dd2-4b18-833f-bbcee94756ab", - "control-id": "cis_rhel10_3-3.1", + "uuid": "4add5800-0869-45fe-80bb-968bb0e865f5", + "control-id": "cis_rhel10_2-1.7", "description": "REPLACE_ME", "props": [ { @@ -24849,18 +23857,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_ip_forward" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_forwarding" + "value": "package_vsftpd_removed" } ] }, { - "uuid": "9152f917-bca0-407c-af63-8db63cd54969", - "control-id": "cis_rhel10_3-3.2", + "uuid": "92c690ba-984b-4946-8edf-b3b1efdbf5ee", + "control-id": "cis_rhel10_2-1.8", "description": "REPLACE_ME", "props": [ { @@ -24871,19 +23874,19 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_send_redirects" + "value": "package_dovecot_removed" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_send_redirects" + "value": "package_cyrus-imapd_removed" } ] }, { - "uuid": "fdad2cf3-a5e7-46df-9e5f-cfc7031f5456", - "control-id": "cis_rhel10_3-3.3", - "description": "REPLACE_ME", + "uuid": "f09f8ba3-7ac4-4331-bae7-025826e2394b", + "control-id": "cis_rhel10_2-1.9", + "description": "Many of the libvirt packages used by Enterprise Linux virtualization are dependent on the\nnfs-utils package.", "props": [ { "name": "implementation-status", @@ -24893,13 +23896,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_icmp_ignore_bogus_error_responses" + "value": "service_nfs_disabled" } ] }, { - "uuid": "6b12799c-018f-4113-a329-59dc14d77368", - "control-id": "cis_rhel10_3-3.4", + "uuid": "48581058-2c06-4280-9e05-eeeeec195281", + "control-id": "cis_rhel10_2-1.12", "description": "REPLACE_ME", "props": [ { @@ -24910,13 +23913,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_icmp_echo_ignore_broadcasts" + "value": "package_rsync_removed" } ] }, { - "uuid": "1aa948f6-490c-4b15-81e5-83641911cc2b", - "control-id": "cis_rhel10_3-3.5", + "uuid": "f9b13433-0fa8-4c2c-b66b-171d9adfbc8b", + "control-id": "cis_rhel10_2-1.13", "description": "REPLACE_ME", "props": [ { @@ -24927,28 +23930,30 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_accept_redirects" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_accept_redirects" - }, + "value": "package_samba_removed" + } + ] + }, + { + "uuid": "6d395c4f-1a22-4606-93a3-95bb57580f66", + "control-id": "cis_rhel10_2-1.14", + "description": "REPLACE_ME", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_redirects" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_redirects" + "value": "package_net-snmp_removed" } ] }, { - "uuid": "f3b75934-bedf-41e4-8bc5-e5fe17e9b5a9", - "control-id": "cis_rhel10_3-3.6", + "uuid": "959d5147-0cc3-45b5-a42d-13e9417bbd86", + "control-id": "cis_rhel10_2-1.15", "description": "REPLACE_ME", "props": [ { @@ -24959,18 +23964,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_secure_redirects" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_secure_redirects" + "value": "package_telnet-server_removed" } ] }, { - "uuid": "e22a808a-266a-40b6-90ec-37948c521528", - "control-id": "cis_rhel10_3-3.7", + "uuid": "64d8edef-ec07-439c-9eeb-1b4ded8e7da9", + "control-id": "cis_rhel10_2-1.16", "description": "REPLACE_ME", "props": [ { @@ -24981,18 +23981,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_rp_filter" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_rp_filter" + "value": "package_tftp-server_removed" } ] }, { - "uuid": "a22ee373-eca5-40e9-9b46-b1fdfb395bd2", - "control-id": "cis_rhel10_3-3.8", + "uuid": "7c5f8258-d6ce-41d0-bcd7-1abbd6238afd", + "control-id": "cis_rhel10_2-1.17", "description": "REPLACE_ME", "props": [ { @@ -25003,67 +23998,70 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_accept_source_route" - }, + "value": "package_squid_removed" + } + ] + }, + { + "uuid": "65f2a912-5d56-4ea9-93d1-2b3cff1a0896", + "control-id": "cis_rhel10_2-1.18", + "description": "REPLACE_ME", + "props": [ { - "name": "Rule_Id", + "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_accept_source_route" + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_source_route" + "value": "package_httpd_removed" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_source_route" + "value": "package_nginx_removed" } ] }, { - "uuid": "226f6a7b-30cd-4dd5-8a52-95a29870effd", - "control-id": "cis_rhel10_3-3.9", - "description": "REPLACE_ME", + "uuid": "31ded707-b17d-4c85-b4ed-252a261d4f57", + "control-id": "cis_rhel10_2-1.21", + "description": "The rule has_nonlocal_mta currently checks for services listening only on port 25,\nbut the policy checks also for ports 465 and 587", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "partial" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_all_log_martians" + "value": "postfix_network_listening_disabled" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_conf_default_log_martians" + "value": "has_nonlocal_mta" } ] }, { - "uuid": "a39696c3-5e6c-423d-9c47-b9a2c80f325a", - "control-id": "cis_rhel10_3-3.10", + "uuid": "aa140db7-6132-424c-8e62-e9b811301cea", + "control-id": "cis_rhel10_2-1.22", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv4_tcp_syncookies" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "86940414-6e88-4caf-83f9-5f86915ea0cc", - "control-id": "cis_rhel10_3-3.11", + "uuid": "97bb6e3e-2810-4087-bc52-30f402fed4b4", + "control-id": "cis_rhel10_2-2.1", "description": "REPLACE_ME", "props": [ { @@ -25074,18 +24072,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_all_accept_ra" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sysctl_net_ipv6_conf_default_accept_ra" + "value": "package_ftp_removed" } ] }, { - "uuid": "ff0e95d1-76b4-4485-b1ef-78bf7fcf78db", - "control-id": "cis_rhel10_4-1.1", + "uuid": "33a8db2f-7aaf-4980-9a7e-2d43c493037f", + "control-id": "cis_rhel10_2-2.3", "description": "REPLACE_ME", "props": [ { @@ -25096,13 +24089,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_nftables_installed" + "value": "package_telnet_removed" } ] }, { - "uuid": "7fbfcee9-197f-42ff-a7cb-b738c1478f73", - "control-id": "cis_rhel10_4-1.2", + "uuid": "ee28529d-a56a-4440-bbd9-16589109b86f", + "control-id": "cis_rhel10_2-2.4", "description": "REPLACE_ME", "props": [ { @@ -25113,36 +24106,25 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_firewalld_enabled" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_firewalld_installed" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "service_nftables_disabled" + "value": "package_tftp_removed" } ] }, { - "uuid": "1bfeadea-9b0a-4864-bfcf-576b11d2f1ca", - "control-id": "cis_rhel10_4-2.1", + "uuid": "db336a74-c53f-4bf6-afdf-ce08ad2b760c", + "control-id": "cis_rhel10_2-3.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "implemented" } ] }, { - "uuid": "ccc2ec7a-043d-4997-b726-394185b9c84f", - "control-id": "cis_rhel10_4-2.2", + "uuid": "d42ae402-4a76-416a-a734-de025346299a", + "control-id": "cis_rhel10_2-3.2", "description": "REPLACE_ME", "props": [ { @@ -25153,67 +24135,52 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "firewalld_loopback_traffic_trusted" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "firewalld_loopback_traffic_restricted" + "value": "chronyd_specify_remote_server" } ] }, { - "uuid": "3f938ee8-1681-405b-b4eb-88280de4e03b", - "control-id": "cis_rhel10_4-3.1", - "description": "RHEL systems use firewalld for firewall management. Although nftables is the default\nback-end for firewalld, it is not recommended to use nftables directly when firewalld\nis in use. When using firewalld the base chains are installed by default.", + "uuid": "57ce7489-3981-4c91-b5e6-a47e3aa192f2", + "control-id": "cis_rhel10_2-3.3", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - } - ] - }, - { - "uuid": "9ff0d763-aa09-400b-84aa-ee46046e4652", - "control-id": "cis_rhel10_4-3.2", - "description": "REPLACE_ME", - "props": [ + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "chronyd_run_as_chrony_user" } ] }, { - "uuid": "b30b5c15-bb33-4bad-ae6a-9f38d2f0dec7", - "control-id": "cis_rhel10_4-3.3", - "description": "RHEL systems use firewalld for firewall management. Although nftables is the default\nback-end for firewalld, it is not recommended to use nftables directly when firewalld\nis in use.", + "uuid": "68a33e43-d76d-4ebb-8aa9-8d06bcc6b213", + "control-id": "cis_rhel10_2-4.1.1", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - } - ] - }, - { - "uuid": "66a3879e-02d1-4c97-a40d-7c9fa3c321dc", - "control-id": "cis_rhel10_4-3.4", - "description": "RHEL systems use firewalld for firewall management. Although nftables is the default\nback-end for firewalld, it is not recommended to use nftables directly when firewalld\nis in use.", - "props": [ + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "package_cron_installed" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "service_crond_enabled" } ] }, { - "uuid": "8a922e3d-0fc9-4f69-9dfd-610f46d87763", - "control-id": "cis_rhel10_5-1.1", + "uuid": "8d8a114c-2d27-46cc-a737-0ce8c4dbbdd1", + "control-id": "cis_rhel10_2-4.1.2", "description": "REPLACE_ME", "props": [ { @@ -25224,23 +24191,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupowner_sshd_config" + "value": "file_groupowner_crontab" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_owner_sshd_config" + "value": "file_owner_crontab" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_config" + "value": "file_permissions_crontab" } ] }, { - "uuid": "9368f67b-1716-446f-b33e-6fd30904f2cc", - "control-id": "cis_rhel10_5-1.2", + "uuid": "c0bc0984-5af2-4c5e-aad4-124d922f1926", + "control-id": "cis_rhel10_2-4.1.3", "description": "REPLACE_ME", "props": [ { @@ -25251,23 +24218,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_private_key" + "value": "file_groupowner_cron_hourly" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_private_key" + "value": "file_owner_cron_hourly" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_sshd_private_key" + "value": "file_permissions_cron_hourly" } ] }, { - "uuid": "097ad0b2-f279-4a6d-a2fd-5fc240df6802", - "control-id": "cis_rhel10_5-1.3", + "uuid": "7598373f-4086-46c0-81ed-113f2a1fff95", + "control-id": "cis_rhel10_2-4.1.4", "description": "REPLACE_ME", "props": [ { @@ -25278,72 +24245,90 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_permissions_sshd_pub_key" + "value": "file_groupowner_cron_daily" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_ownership_sshd_pub_key" + "value": "file_owner_cron_daily" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "file_groupownership_sshd_pub_key" + "value": "file_permissions_cron_daily" } ] }, { - "uuid": "6c9db39e-4df7-43f2-bf2c-e62306703e96", - "control-id": "cis_rhel10_5-1.4", + "uuid": "9ab9c94b-23b8-4b6a-b151-0ba845dbdc9b", + "control-id": "cis_rhel10_2-4.1.5", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_groupowner_cron_weekly" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_owner_cron_weekly" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_cron_weekly" } ] }, { - "uuid": "6c31cf22-898a-4ada-9dd2-d1ca0197702b", - "control-id": "cis_rhel10_5-1.5", + "uuid": "2599789d-cf3f-460f-9a87-c230520af1d6", + "control-id": "cis_rhel10_2-4.1.6", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." + "value": "implemented" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_kex" + "value": "file_groupowner_cron_monthly" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_owner_cron_monthly" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_cron_monthly" } ] }, { - "uuid": "54a0c61d-7788-49fe-a7da-c230e099699e", - "control-id": "cis_rhel10_5-1.6", + "uuid": "7e6cb2c9-ad46-45ba-a115-d284f17cf24e", + "control-id": "cis_rhel10_2-4.1.7", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "alternative", - "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_use_strong_macs" + "remarks": "REPLACE_ME" } ] }, { - "uuid": "04f458fa-c3e2-4d51-9e74-fc1130cc6e11", - "control-id": "cis_rhel10_5-1.7", + "uuid": "6b5061a0-b9f3-47e2-90d5-445bb16fc6d4", + "control-id": "cis_rhel10_2-4.1.8", "description": "REPLACE_ME", "props": [ { @@ -25354,65 +24339,68 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_limit_user_access" - } - ] - }, - { - "uuid": "ce20250e-dc50-49da-8486-f7d560f9d51c", - "control-id": "cis_rhel10_5-1.8", - "description": "REPLACE_ME", - "props": [ + "value": "file_groupowner_cron_d" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "file_owner_cron_d" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_enable_warning_banner_net" + "value": "file_permissions_cron_d" } ] }, { - "uuid": "85dfa087-909a-48f9-8541-2d96c4a1bd70", - "control-id": "cis_rhel10_5-1.9", - "description": "The requirement gives an example of 45 seconds, but is flexible about the values. It is only\nnecessary to ensure there is a timeout configured in alignment to the site policy.", + "uuid": "ada2eb6d-6809-446c-9ff9-6a3b4db8d97c", + "control-id": "cis_rhel10_2-4.2.1", + "description": "It is necessary to create a rule to ensure the existence of at.allow.\nfile_cron_allow_exists can be used as reference for a new templated rule.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "partial" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_idle_timeout" + "value": "file_at_deny_not_exist" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_keepalive" + "value": "file_groupowner_at_allow" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_owner_at_allow" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_at_allow" } ] }, { - "uuid": "8311e8ae-a7d4-4417-b7ad-1c569b1be226", - "control-id": "cis_rhel10_5-1.10", + "uuid": "9e8d746b-18a2-487e-9f8d-4ac5d874eaa8", + "control-id": "cis_rhel10_3-1.1", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "alternative", - "remarks": "New templated rule is necessary for \"disableforwarding\" option." + "remarks": "REPLACE_ME" } ] }, { - "uuid": "7e62be04-47bb-4186-8a00-99eda5c5e98d", - "control-id": "cis_rhel10_5-1.11", + "uuid": "24437a32-c741-4544-b145-5fc0c0afc42a", + "control-id": "cis_rhel10_3-2.2", "description": "REPLACE_ME", "props": [ { @@ -25423,13 +24411,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_gssapi_auth" + "value": "kernel_module_can_disabled" } ] }, { - "uuid": "8162678d-82b2-4096-bd3e-83289ddaf75b", - "control-id": "cis_rhel10_5-1.12", + "uuid": "a537bcef-4dcf-4341-83c9-62a47086cbca", + "control-id": "cis_rhel10_3-2.4", "description": "REPLACE_ME", "props": [ { @@ -25440,13 +24428,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "disable_host_auth" + "value": "kernel_module_tipc_disabled" } ] }, { - "uuid": "d648ae88-7f41-4812-b2e4-e86f53f4d84b", - "control-id": "cis_rhel10_5-1.13", + "uuid": "943ed7d6-cca1-4fe5-9152-465bf9b92147", + "control-id": "cis_rhel10_4-1.1", "description": "REPLACE_ME", "props": [ { @@ -25457,31 +24445,27 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_rhosts" + "value": "package_firewalld_installed" } ] }, { - "uuid": "0fc7c2ec-ba8c-4b3c-978a-45f063b0196b", - "control-id": "cis_rhel10_5-1.14", + "uuid": "178309c8-907c-49c9-a5a3-60929cf1c1fd", + "control-id": "cis_rhel10_4-1.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_login_grace_time" + "value": "alternative", + "remarks": "REPLACE_ME" } ] }, { - "uuid": "4b304986-e8e2-4a67-987e-7f0537323224", - "control-id": "cis_rhel10_5-1.15", - "description": "The CIS benchmark is not opinionated about which loglevel is selected here. Here, this\nprofile uses VERBOSE by default, as it allows for the capture of login and logout activity\nas well as key fingerprints.", + "uuid": "bdc98036-806f-4216-9ac9-beca8e34bf9e", + "control-id": "cis_rhel10_5-1.1", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -25491,30 +24475,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_loglevel_verbose" - } - ] - }, - { - "uuid": "060b75ee-120e-4404-8748-8f43e7eb9de1", - "control-id": "cis_rhel10_5-1.16", - "description": "REPLACE_ME", - "props": [ + "value": "file_groupowner_sshd_config" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "file_owner_sshd_config" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_max_auth_tries" + "value": "file_permissions_sshd_config" } ] }, { - "uuid": "6fd8419b-f522-4486-8625-1d73b9207efa", - "control-id": "cis_rhel10_5-1.17", + "uuid": "509d432c-fa01-4fed-8336-9fa56e4fa4ff", + "control-id": "cis_rhel10_5-1.2", "description": "REPLACE_ME", "props": [ { @@ -25525,13 +24502,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_maxstartups" + "value": "file_groupownership_sshd_private_key" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_ownership_sshd_private_key" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_sshd_private_key" } ] }, { - "uuid": "99aba220-be22-4449-9c6d-78fa0c53733a", - "control-id": "cis_rhel10_5-1.18", + "uuid": "0e8ed8a8-8c70-469d-b0d0-e89add6e9481", + "control-id": "cis_rhel10_5-1.3", "description": "REPLACE_ME", "props": [ { @@ -25542,13 +24529,23 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_set_max_sessions" + "value": "file_groupownership_sshd_pub_key" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_ownership_sshd_pub_key" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "file_permissions_sshd_pub_key" } ] }, { - "uuid": "4bd7739e-8b42-4ee1-9d1d-7f14af1c32d0", - "control-id": "cis_rhel10_5-1.19", + "uuid": "6496a011-b17b-4db7-8cca-b57b6de89143", + "control-id": "cis_rhel10_5-1.4", "description": "REPLACE_ME", "props": [ { @@ -25559,13 +24556,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_empty_passwords" + "value": "sshd_limit_user_access" } ] }, { - "uuid": "79f43502-4cff-44be-a8db-ce46e27fe6a1", - "control-id": "cis_rhel10_5-1.20", + "uuid": "ca24e7b3-c787-4e31-a37c-4b400907f701", + "control-id": "cis_rhel10_5-1.5", "description": "REPLACE_ME", "props": [ { @@ -25576,31 +24573,26 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_disable_root_login" + "value": "sshd_enable_warning_banner_net" } ] }, { - "uuid": "cfa36838-1991-493e-a98a-7ac57717f4e9", - "control-id": "cis_rhel10_5-1.21", - "description": "REPLACE_ME", + "uuid": "87d1cf06-51fe-4316-8450-ee5a942e460a", + "control-id": "cis_rhel10_5-1.6", + "description": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_do_not_permit_user_env" } ] }, { - "uuid": "e7bd5b76-ffa4-4758-891f-b9bf142cfb24", - "control-id": "cis_rhel10_5-1.22", - "description": "REPLACE_ME", + "uuid": "ec69371c-d981-4b77-8640-913ecc221cba", + "control-id": "cis_rhel10_5-1.7", + "description": "The requirement gives an example of 45 seconds, but is flexible about the values. It is only\nnecessary to ensure there is a timeout configured in alignment to the site policy.", "props": [ { "name": "implementation-status", @@ -25610,13 +24602,18 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sshd_enable_pam" + "value": "sshd_set_idle_timeout" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_set_keepalive" } ] }, { - "uuid": "bfc117d2-1e9d-43f2-89a1-b667ca74c26a", - "control-id": "cis_rhel10_5-2.1", + "uuid": "5b5be1bc-b795-4163-9c44-7fdb1fe1ad20", + "control-id": "cis_rhel10_5-1.8", "description": "REPLACE_ME", "props": [ { @@ -25627,13 +24624,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_sudo_installed" + "value": "sshd_disable_forwarding" } ] }, { - "uuid": "fbab4dbd-b6c3-4aaf-b573-cc84816768a3", - "control-id": "cis_rhel10_5-2.2", + "uuid": "539dfeee-24c7-4dde-834a-d1eb7ed3c2bf", + "control-id": "cis_rhel10_5-1.9", "description": "REPLACE_ME", "props": [ { @@ -25644,13 +24641,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_add_use_pty" + "value": "sshd_disable_gssapi_auth" } ] }, { - "uuid": "7c7a3ea6-1b5f-4c1a-bf1b-970c5b3bd5e1", - "control-id": "cis_rhel10_5-2.3", + "uuid": "519f4013-4211-47c4-87ed-3cb936dcda0f", + "control-id": "cis_rhel10_5-1.10", "description": "REPLACE_ME", "props": [ { @@ -25661,13 +24658,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_custom_logfile" + "value": "disable_host_auth" } ] }, { - "uuid": "87bba689-05c1-451e-9262-9b9866cced6e", - "control-id": "cis_rhel10_5-2.5", + "uuid": "f6f3ec7b-e410-4b0d-a970-f3756c6c3b30", + "control-id": "cis_rhel10_5-1.11", "description": "REPLACE_ME", "props": [ { @@ -25678,31 +24675,32 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_require_reauthentication" + "value": "sshd_disable_rhosts" } ] }, { - "uuid": "10db16e3-7de1-4ffb-87e0-ad563c2e9afe", - "control-id": "cis_rhel10_5-2.6", + "uuid": "ffd140c8-52b0-49c6-9a71-f066c537e5b2", + "control-id": "cis_rhel10_5-1.12", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" + "value": "alternative", + "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "sudo_require_reauthentication" + "value": "sshd_use_strong_kex" } ] }, { - "uuid": "fcd94e04-b5cb-4ff6-93cb-0e4be96097bc", - "control-id": "cis_rhel10_5-2.7", - "description": "Members of \"wheel\" or GID 0 groups are checked by default if the group option is not set for\npam_wheel.so module. The recommendation states the group should be empty to reinforce the\nuse of \"sudo\" for privileged access. Therefore, members of these groups should be manually\nchecked or a different group should be informed.", + "uuid": "d582dc15-951e-4df7-9c1b-5351cc343c3c", + "control-id": "cis_rhel10_5-1.13", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -25712,75 +24710,49 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "use_pam_wheel_group_for_su" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "ensure_pam_wheel_group_empty" + "value": "sshd_set_login_grace_time" } ] }, { - "uuid": "6812f964-00a7-4aed-9b72-e2c9fe0c8de4", - "control-id": "cis_rhel10_5-3.1.1", - "description": "REPLACE_ME", + "uuid": "c8f7f234-bd75-4c5c-b0b0-8a2e537120b0", + "control-id": "cis_rhel10_5-1.14", + "description": "The CIS benchmark is not opinionated about which loglevel is selected here. Here, this\nprofile uses VERBOSE by default, as it allows for the capture of login and logout activity\nas well as key fingerprints.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary a new rule to ensure PAM package is updated." - } - ] - }, - { - "uuid": "9c4db586-d8f7-47e3-bf96-adfde9d15c53", - "control-id": "cis_rhel10_5-3.1.2", - "description": "REPLACE_ME", - "props": [ + "value": "implemented" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "It is necessary a new rule to ensure authselect package is updated." + "value": "sshd_set_loglevel_verbose" } ] }, { - "uuid": "b0986bf8-d578-4e4a-9632-32779f02ada7", - "control-id": "cis_rhel10_5-3.1.3", + "uuid": "fcc3398a-9c25-4bc5-b8d0-eff04aaa364b", + "control-id": "cis_rhel10_5-1.15", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "alternative", - "remarks": "It is necessary a new rule to ensure libpwquality package is updated." + "remarks": "The status was automated but we need to double check the approach used in this rule.\nTherefore I moved it to pending until deeper investigation." }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_pam_pwquality_installed" - } - ] - }, - { - "uuid": "bbc94653-4616-4770-b829-337360093495", - "control-id": "cis_rhel10_5-3.2.1", - "description": "This requirement is hard to be automated without any specific requirement. The policy even\nstates that provided commands are examples, other custom settings might be in place and the\nsettings might be different depending on site policies. The other rules will already make\nsure there is a correct autheselect profile regardless of the existing settings. It is\nnecessary to better discuss with CIS Community.", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "sshd_use_strong_macs" } ] }, { - "uuid": "85228591-a5fa-4fbc-a8a8-2e9071ad38a3", - "control-id": "cis_rhel10_5-3.2.2", - "description": "This requirement is also indirectly satisfied by the requirement 5.3.3.1.", + "uuid": "bc3686cf-0cbb-49a2-988c-4cb39bd39b19", + "control-id": "cis_rhel10_5-1.16", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -25790,54 +24762,47 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_password_auth" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "account_password_pam_faillock_system_auth" + "value": "sshd_set_max_auth_tries" } ] }, { - "uuid": "e23bc38c-c2ba-4a9b-a309-dc9c00bddefc", - "control-id": "cis_rhel10_5-3.2.3", - "description": "This requirement is also indirectly satisfied by the requirement 5.3.3.2.", + "uuid": "db91dba7-3529-4241-b393-252fab369c0b", + "control-id": "cis_rhel10_5-1.17", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sshd_set_maxstartups" } ] }, { - "uuid": "5be57602-6f36-4ecd-81b1-d0bd1f9d52b3", - "control-id": "cis_rhel10_5-3.2.4", - "description": "The module is properly enabled by the rules mentioned in related_rules.\nRequirements in 5.3.3.3 use these rules.", + "uuid": "b78f94dd-60d4-4f71-b00d-0f1c5f0b776f", + "control-id": "cis_rhel10_5-1.18", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "implemented" - } - ] - }, - { - "uuid": "f8d7cd58-6f5e-48ed-b8fe-ac02dccab9ec", - "control-id": "cis_rhel10_5-3.2.5", - "description": "This module is always present by default. It is necessary to investigate if a new rule to\ncheck its existence needs to be created. But so far the rule no_empty_passwords, used in\n5.3.3.4 can ensure this requirement is attended.", - "props": [ + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "sshd_set_max_sessions" } ] }, { - "uuid": "515248ca-0a81-4aa3-8e68-45b3b0ea66ef", - "control-id": "cis_rhel10_5-3.3.1.1", + "uuid": "71f41a7e-c1f2-4397-becb-10cebf39383c", + "control-id": "cis_rhel10_5-1.19", "description": "REPLACE_ME", "props": [ { @@ -25848,14 +24813,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_deny" + "value": "sshd_disable_empty_passwords" } ] }, { - "uuid": "b575c635-aeaf-4b46-b192-cd4565eb1dc8", - "control-id": "cis_rhel10_5-3.3.1.2", - "description": "The policy also accepts value 0, which means the locked accounts should be manually unlocked\nby an administrator. However, it also mentions that using value 0 can facilitate a DoS\nattack to legitimate users.", + "uuid": "14ce56da-4658-4a61-9f17-74f9c42cdef4", + "control-id": "cis_rhel10_5-1.20", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -25865,13 +24830,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_passwords_pam_faillock_unlock_time" + "value": "sshd_disable_root_login" } ] }, { - "uuid": "f77b106f-ea5c-4ea8-9cb2-0f67282163e6", - "control-id": "cis_rhel10_5-3.3.2.1", + "uuid": "6d605ad2-2108-4a24-8090-54fcbdb32032", + "control-id": "cis_rhel10_5-1.21", "description": "REPLACE_ME", "props": [ { @@ -25882,13 +24847,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_difok" + "value": "sshd_do_not_permit_user_env" } ] }, { - "uuid": "270ad27c-95d4-4e43-b97f-646b555b57e0", - "control-id": "cis_rhel10_5-3.3.2.2", + "uuid": "f6020fab-8dc6-4e6e-b707-019f5454de43", + "control-id": "cis_rhel10_5-1.22", "description": "REPLACE_ME", "props": [ { @@ -25899,14 +24864,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_minlen" + "value": "sshd_enable_pam" } ] }, { - "uuid": "0e5c2618-1df0-4c12-9c32-c5b27e414adf", - "control-id": "cis_rhel10_5-3.3.2.3", - "description": "This requirement is expected to be manual. However, in previous versions of the policy\nit was already automated the configuration of \"minclass\" option. This posture was kept for\nRHEL 9 in this new version. Rules related to other options are informed in related_rules.\nIn short, minclass=4 alone can achieve the same result achieved by the combination of the\nother 4 options mentioned in the policy.", + "uuid": "be8aaead-a8c7-4eab-adf8-c8b6f1621349", + "control-id": "cis_rhel10_5-2.1", + "description": "REPLACE_ME", "props": [ { "name": "implementation-status", @@ -25916,13 +24881,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_minclass" + "value": "package_sudo_installed" } ] }, { - "uuid": "eb23a647-f86b-434c-be7a-660fa8af2ce1", - "control-id": "cis_rhel10_5-3.3.2.4", + "uuid": "09307194-9434-48ae-b143-9716a0520a0d", + "control-id": "cis_rhel10_5-2.2", "description": "REPLACE_ME", "props": [ { @@ -25933,26 +24898,30 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_maxrepeat" + "value": "sudo_add_use_pty" } ] }, { - "uuid": "8114aed0-cbe1-47a4-b207-ba4ab103762b", - "control-id": "cis_rhel10_5-3.3.2.5", + "uuid": "c5d76fa8-e5f9-4f3d-8b42-bb1123ae27c2", + "control-id": "cis_rhel10_5-2.3", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "planned", - "remarks": "A new templated rule and variable are necessary for the maxsequence option." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "sudo_custom_logfile" } ] }, { - "uuid": "3d5fb2a5-d429-4eda-af4f-6b1543b7fd5f", - "control-id": "cis_rhel10_5-3.3.2.6", + "uuid": "3c7c94ec-7d34-4596-9029-82c24af9c926", + "control-id": "cis_rhel10_5-2.5", "description": "REPLACE_ME", "props": [ { @@ -25963,13 +24932,13 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_dictcheck" + "value": "sudo_require_authentication" } ] }, { - "uuid": "1bc84b79-8540-4656-b998-ac97a39de691", - "control-id": "cis_rhel10_5-3.3.2.7", + "uuid": "8a432fd9-a6da-40ac-a450-1e6e059db178", + "control-id": "cis_rhel10_5-2.6", "description": "REPLACE_ME", "props": [ { @@ -25980,14 +24949,14 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_enforce_root" + "value": "sudo_require_reauthentication" } ] }, { - "uuid": "0a2903bf-4187-4be8-80d6-d66d152cbe72", - "control-id": "cis_rhel10_5-3.3.3.1", - "description": "Although mentioned in the section 5.3.3.3, there is no explicit requirement to configure\nretry option of pam_pwhistory. If come in the future, the rule accounts_password_pam_retry\ncan be used.", + "uuid": "0f0f8afa-c47c-4f7d-843a-67b8a7c97738", + "control-id": "cis_rhel10_5-2.7", + "description": "Members of \"wheel\" or GID 0 groups are checked by default if the group option is not set for\npam_wheel.so module. The recommendation states the group should be empty to reinforce the\nuse of \"sudo\" for privileged access. Therefore, members of these groups should be manually\nchecked or a different group should be informed.", "props": [ { "name": "implementation-status", @@ -25997,32 +24966,19 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_pwhistory_remember_password_auth" + "value": "use_pam_wheel_group_for_su" }, { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "accounts_password_pam_pwhistory_remember_system_auth" - } - ] - }, - { - "uuid": "56cd51ed-139f-412e-ad5c-68a3c2c33840", - "control-id": "cis_rhel10_5-3.3.3.2", - "description": "REPLACE_ME", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "planned", - "remarks": "A new rule needs to be created to check and remediate the enforce_for_root option in\n/etc/security/pwhistory.conf. accounts_password_pam_enforce_root can be used as reference." + "value": "ensure_pam_wheel_group_empty" } ] }, { - "uuid": "5afecf91-9005-4a13-a71d-c90cbe648e54", - "control-id": "cis_rhel10_5-3.3.3.3", - "description": "In RHEL 9 pam_pwhistory is enabled via authselect feature, as required in 5.3.2.4. The\nfeature automatically set \"use_authok\" option. In any case, we don't have a rule to check\nthis option specifically.", + "uuid": "8cb560bd-267e-4219-a133-b2bb76fef696", + "control-id": "cis_rhel10_5-3.1.1", + "description": "This requirement is hard to be automated without any specific requirement. The policy even\nstates that provided commands are examples, other custom settings might be in place and the\nsettings might be different depending on site policies. The other rules will already make\nsure there is a correct autheselect profile regardless of the existing settings. It is\nnecessary to better discuss with CIS Community.", "props": [ { "name": "implementation-status", @@ -26032,9 +24988,9 @@ ] }, { - "uuid": "1d787bc9-19ab-4020-98e2-23bfc8f8ec23", - "control-id": "cis_rhel10_5-3.3.4.1", - "description": "The rule more specifically used in this requirement also satify the requirement 5.3.2.5.", + "uuid": "5e9c4aad-9348-44b0-9669-d8625ce2ee53", + "control-id": "cis_rhel10_5-3.1.2", + "description": "This requirement is also indirectly satisfied by the requirement 5.3.2.1.", "props": [ { "name": "implementation-status", @@ -26044,27 +25000,19 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "no_empty_passwords" - } - ] - }, - { - "uuid": "1512ea7e-b9ac-44ba-805c-669bc83995a8", - "control-id": "cis_rhel10_5-3.3.4.2", - "description": "REPLACE_ME", - "props": [ + "value": "account_password_pam_faillock_password_auth" + }, { - "name": "implementation-status", + "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "Usage of pam_unix.so module together with \"remember\" option is deprecated and is not\nrecommened by this policy. Instead, it should be used remember option of pam_pwhistory\nmodule, as required in 5.3.3.3.1. See here for more details about pam_unix.so:\nhttps://bugzilla.redhat.com/show_bug.cgi?id=1778929\nA new rule needs to be created to remove the remember option from pam_unix module." + "value": "account_password_pam_faillock_system_auth" } ] }, { - "uuid": "965e6bac-2dda-4fc7-b8b6-c796d2a454d5", - "control-id": "cis_rhel10_5-3.3.4.3", - "description": "Changes in logindefs mentioned in this requirement are more specifically covered by 5.4.1.4", + "uuid": "9f4cf7e9-3f8e-40d5-8494-84b553ddafc3", + "control-id": "cis_rhel10_5-3.1.3", + "description": "This requirement is also indirectly satisfied by the requirement 5.3.2.2.", "props": [ { "name": "implementation-status", @@ -26074,29 +25022,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_systemauth" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "set_password_hashing_algorithm_passwordauth" - } - ] - }, - { - "uuid": "bfcd97bf-c7fa-473f-b2d7-f15cc49df0d9", - "control-id": "cis_rhel10_5-3.3.4.4", - "description": "In RHEL 9 pam_unix is enabled by default in all authselect profiles already with the\nuse_authtok option set. In any case, we don't have a rule to check this option specifically,\nlike in 5.3.3.3.3.", - "props": [ - { - "name": "implementation-status", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "package_pam_pwquality_installed" } ] }, { - "uuid": "27ea1fc5-2d2e-4c8f-8a9d-b9a161c116d0", + "uuid": "961ee3d6-8f02-4dfb-9491-ec622ac23d1a", "control-id": "cis_rhel10_5-4.1.1", "description": "REPLACE_ME", "props": [ @@ -26118,7 +25049,7 @@ ] }, { - "uuid": "d06f970c-f4d1-404f-bf07-76cd5d18ccc9", + "uuid": "c3935f54-6434-4cde-ad72-1f066a445700", "control-id": "cis_rhel10_5-4.1.3", "description": "REPLACE_ME", "props": [ @@ -26140,7 +25071,7 @@ ] }, { - "uuid": "98ee1c1f-50b1-4603-ae1f-ac35dc63483f", + "uuid": "ca0399dc-6719-4754-b1be-e676d80a95e4", "control-id": "cis_rhel10_5-4.1.4", "description": "There's a \"new\" set of options in /etc/login.defs file to define the number of iterations\nperformed during the hashing process.", "props": [ @@ -26162,7 +25093,7 @@ ] }, { - "uuid": "0577c716-fd14-4a8d-ae7c-f2ab16f5067d", + "uuid": "83ef96b7-688d-4b0c-b0e4-5c0f5cdad3d1", "control-id": "cis_rhel10_5-4.1.5", "description": "REPLACE_ME", "props": [ @@ -26184,7 +25115,7 @@ ] }, { - "uuid": "eeb7b17d-faf4-4913-9ba3-82d22ff1b7a7", + "uuid": "2d56da59-d682-4fcb-b38e-7df6d6890ebe", "control-id": "cis_rhel10_5-4.1.6", "description": "REPLACE_ME", "props": [ @@ -26201,7 +25132,7 @@ ] }, { - "uuid": "edb086a8-6643-44bd-9271-61a4aed92db8", + "uuid": "4f5c34f9-aa49-4bae-8dd5-5f8b172c8693", "control-id": "cis_rhel10_5-4.2.1", "description": "REPLACE_ME", "props": [ @@ -26218,7 +25149,7 @@ ] }, { - "uuid": "740c6358-f926-4957-9299-8879b023936e", + "uuid": "e7ef38d7-02a4-4166-b58f-44ba6e7beb0f", "control-id": "cis_rhel10_5-4.2.2", "description": "The rule confirms the primary group for root, but doesn't check if any other user are also\nusing GID 0. New rule is necessary.\nThere is assessment but no automated remediation for this rule and this sounds reasonable.", "props": [ @@ -26235,20 +25166,24 @@ ] }, { - "uuid": "b9dc6648-02fd-48e6-a871-dfb87e2a3a89", + "uuid": "306307a0-6dab-43e9-b5b5-085b6b5b85ae", "control-id": "cis_rhel10_5-4.2.3", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "New rule is necessary." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "groups_no_zero_gid_except_root" } ] }, { - "uuid": "3bc8b0f3-cc54-427d-990a-d1736d896bb7", + "uuid": "0cbafd16-7a3f-41ad-a404-2f7658c668aa", "control-id": "cis_rhel10_5-4.2.4", "description": "REPLACE_ME", "props": [ @@ -26265,7 +25200,7 @@ ] }, { - "uuid": "44b8b9e9-5e1b-4b31-9f1a-20469e6dc652", + "uuid": "ab36a29e-b3fd-498c-8163-426a8859d74c", "control-id": "cis_rhel10_5-4.2.5", "description": "REPLACE_ME", "props": [ @@ -26287,20 +25222,24 @@ ] }, { - "uuid": "e761bc2d-a493-4709-adc9-7fe40fc0956a", + "uuid": "a7c1f215-ba87-48e7-b51a-d6c8d59befe1", "control-id": "cis_rhel10_5-4.2.6", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "There is no rule to ensure umask in /root/.bash_profile and /root/.bashrc. A new rule have\nto be created. It can be based on accounts_umask_interactive_users." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "accounts_umask_root" } ] }, { - "uuid": "e9fd15ab-859b-4eb8-9601-38287e9a84a6", + "uuid": "11a2ef07-1bcf-4618-bb66-a75894f7ebf9", "control-id": "cis_rhel10_5-4.2.7", "description": "REPLACE_ME", "props": [ @@ -26322,20 +25261,19 @@ ] }, { - "uuid": "14d1c5f5-d6de-4a6f-832e-96b188b4ec95", + "uuid": "a7504dc0-7eb4-42b2-8755-1f77bc8475d6", "control-id": "cis_rhel10_5-4.2.8", - "description": "REPLACE_ME", + "description": "New rule is necessary.", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "New rule is necessary." + "value": "implemented" } ] }, { - "uuid": "d5a2d027-49b0-490e-ab9c-1e29089aed84", + "uuid": "55437687-252d-46ea-a230-9993c12495f3", "control-id": "cis_rhel10_5-4.3.2", "description": "REPLACE_ME", "props": [ @@ -26352,7 +25290,7 @@ ] }, { - "uuid": "2660a72f-6bfa-4806-8994-6bffae124348", + "uuid": "9a93fcf8-bf96-4665-a04c-63b641740eea", "control-id": "cis_rhel10_5-4.3.3", "description": "REPLACE_ME", "props": [ @@ -26379,7 +25317,7 @@ ] }, { - "uuid": "2de010a9-08e1-4b3e-8e60-ee5669f9d115", + "uuid": "1a4b2544-2b36-4502-9dc7-3139c55821c5", "control-id": "cis_rhel10_6-1.1", "description": "REPLACE_ME", "props": [ @@ -26401,7 +25339,7 @@ ] }, { - "uuid": "b82031b5-dc60-4ee3-a603-8b6b4c2ece3b", + "uuid": "fdafce25-09ab-4d82-b5ca-0c3d2a49dddd", "control-id": "cis_rhel10_6-1.2", "description": "REPLACE_ME", "props": [ @@ -26418,7 +25356,7 @@ ] }, { - "uuid": "aa017580-d845-4bdf-9f3f-e94e3a44b3b4", + "uuid": "a2773f54-9eab-43c8-b659-5dcca99c7402", "control-id": "cis_rhel10_6-1.3", "description": "REPLACE_ME", "props": [ @@ -26435,7 +25373,7 @@ ] }, { - "uuid": "62fd375a-0655-4e53-b4ea-d29440baf940", + "uuid": "519226e8-191b-4c36-bcd7-3cdf05e88b1e", "control-id": "cis_rhel10_6-2.1.1", "description": "REPLACE_ME", "props": [ @@ -26452,7 +25390,7 @@ ] }, { - "uuid": "f195c6e2-a151-462c-81ed-16739be54081", + "uuid": "6e1614be-9a43-4a79-9ef6-e422e6faaf55", "control-id": "cis_rhel10_6-2.1.2", "description": "REPLACE_ME", "props": [ @@ -26465,7 +25403,7 @@ ] }, { - "uuid": "bf9d32eb-e741-456b-b602-804cadd19e5e", + "uuid": "a4ef6698-f906-400f-8f09-26d6303c56a9", "control-id": "cis_rhel10_6-2.1.3", "description": "REPLACE_ME", "props": [ @@ -26478,7 +25416,7 @@ ] }, { - "uuid": "54efe75f-d2d0-451e-9a4d-5366b075138f", + "uuid": "aaab5314-5ac8-4bd8-9349-1103b05f9edb", "control-id": "cis_rhel10_6-2.1.4", "description": "REPLACE_ME", "props": [ @@ -26491,51 +25429,55 @@ ] }, { - "uuid": "ad3e9ce0-9565-4eab-ad40-905b786b4260", - "control-id": "cis_rhel10_6-2.2.1.1", + "uuid": "0b1a7a3f-0f81-4337-be11-24567cfaccd9", + "control-id": "cis_rhel10_6-2.2.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "package_systemd-journal-remote_installed" + "value": "alternative", + "remarks": "This rule conflicts with 6.2.3.3. More investigation is needed to properly solve this." } ] }, { - "uuid": "8294e459-3f2f-44c5-8f2d-b71028e406a2", - "control-id": "cis_rhel10_6-2.2.1.2", + "uuid": "7787857d-e895-4efc-afdc-a37574dda826", + "control-id": "cis_rhel10_6-2.2.3", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "REPLACE_ME" + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "journald_compress" } ] }, { - "uuid": "87eceeab-0ba0-4aec-98a4-0248b639d77f", - "control-id": "cis_rhel10_6-2.2.1.3", + "uuid": "60139117-b5a8-479f-a603-8d0df71b72e1", + "control-id": "cis_rhel10_6-2.2.4", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "alternative", - "remarks": "New templated rule is necessary." + "value": "implemented" + }, + { + "name": "Rule_Id", + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", + "value": "journald_storage" } ] }, { - "uuid": "949c7ea6-a8ca-4271-9051-b215f8e21752", - "control-id": "cis_rhel10_6-2.2.1.4", + "uuid": "0e9b652e-eee7-44fb-8737-0470f6f5fecb", + "control-id": "cis_rhel10_6-2.2.1.1", "description": "REPLACE_ME", "props": [ { @@ -26546,43 +25488,39 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "socket_systemd-journal-remote_disabled" + "value": "package_systemd-journal-remote_installed" } ] }, { - "uuid": "e4217f2b-83fa-4623-9e0f-1aff520b3137", - "control-id": "cis_rhel10_6-2.2.2", + "uuid": "e8e3fd8f-4bb1-4cd0-bd1d-462920ade9bb", + "control-id": "cis_rhel10_6-2.2.1.2", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", "value": "alternative", - "remarks": "This rule conflicts with 6.2.3.3. More investigation is needed to properly solve this." + "remarks": "REPLACE_ME" } ] }, { - "uuid": "0ef1f463-cfad-4e96-b2de-1a43f6c70a36", - "control-id": "cis_rhel10_6-2.2.3", + "uuid": "bb31c779-e8c0-4b4a-a9f1-c4b647b68645", + "control-id": "cis_rhel10_6-2.2.1.3", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "implemented" - }, - { - "name": "Rule_Id", - "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_compress" + "value": "alternative", + "remarks": "New templated rule is necessary." } ] }, { - "uuid": "08dcc8b6-e838-4790-9f37-b0db5da7eb33", - "control-id": "cis_rhel10_6-2.2.4", + "uuid": "c8d9491d-b6ff-4366-81f6-5f19b8f57ca7", + "control-id": "cis_rhel10_6-2.2.1.4", "description": "REPLACE_ME", "props": [ { @@ -26593,12 +25531,12 @@ { "name": "Rule_Id", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "journald_storage" + "value": "socket_systemd-journal-remote_disabled" } ] }, { - "uuid": "ffc4ec07-3095-43cf-a50c-90827f778516", + "uuid": "18259440-cb80-4c11-91d0-5d5fbb8af88b", "control-id": "cis_rhel10_6-2.3.1", "description": "REPLACE_ME", "props": [ @@ -26610,7 +25548,7 @@ ] }, { - "uuid": "3781114a-28fd-4455-b4bd-5c5ae4e24161", + "uuid": "ff3cedd1-9ad4-4d3a-9a61-e7beeee27464", "control-id": "cis_rhel10_6-2.3.2", "description": "REPLACE_ME", "props": [ @@ -26622,7 +25560,7 @@ ] }, { - "uuid": "9fee27e5-9187-4f5f-bd0b-4e893cba4f01", + "uuid": "a5d56364-b63b-4d0a-98f7-974cb6de8dda", "control-id": "cis_rhel10_6-2.3.3", "description": "REPLACE_ME", "props": [ @@ -26634,7 +25572,7 @@ ] }, { - "uuid": "f394cb47-f15a-42f7-a6ae-dc6595ec2519", + "uuid": "8cf3ad7e-ed66-4149-8d87-664759088f2c", "control-id": "cis_rhel10_6-2.3.4", "description": "REPLACE_ME", "props": [ @@ -26646,7 +25584,7 @@ ] }, { - "uuid": "36594d62-815a-4c15-85f5-fe0297c52a85", + "uuid": "7eb4ddfb-d91a-4128-a973-0f47707f5136", "control-id": "cis_rhel10_6-2.3.5", "description": "REPLACE_ME", "props": [ @@ -26659,7 +25597,7 @@ ] }, { - "uuid": "f08a0106-a14b-40ad-8bb2-fb89e01d5f88", + "uuid": "b978e1a8-3653-4e0c-9379-94c11dea28aa", "control-id": "cis_rhel10_6-2.3.6", "description": "REPLACE_ME", "props": [ @@ -26672,7 +25610,7 @@ ] }, { - "uuid": "8d4eacf8-2b36-49b0-825c-7dbc78715e1b", + "uuid": "40267f75-3079-44b9-8458-f12acd560a86", "control-id": "cis_rhel10_6-2.3.7", "description": "REPLACE_ME", "props": [ @@ -26684,7 +25622,7 @@ ] }, { - "uuid": "fa59cb68-05c2-44e1-84bd-11f053523f88", + "uuid": "79e9aeb1-8eca-480b-87bf-285b4ba64faa", "control-id": "cis_rhel10_6-2.3.8", "description": "REPLACE_ME", "props": [ @@ -26697,7 +25635,7 @@ ] }, { - "uuid": "f3efc803-1ce9-4584-bcdf-40e1d74cf765", + "uuid": "c525be60-90d9-490b-b7ac-6159936cf6ff", "control-id": "cis_rhel10_6-2.4.1", "description": "It is not harmful to run these rules even if rsyslog is not installed or active.", "props": [ @@ -26724,7 +25662,7 @@ ] }, { - "uuid": "96e78e32-eb23-4114-a2c1-9291973a649e", + "uuid": "dd4c0520-ec99-404c-bba7-077f99b42602", "control-id": "cis_rhel10_7-1.1", "description": "REPLACE_ME", "props": [ @@ -26751,7 +25689,7 @@ ] }, { - "uuid": "40872b74-c3a7-4b6a-96e8-917f7022aa41", + "uuid": "3186b7f5-63e0-4793-9b6d-7baa1ab87865", "control-id": "cis_rhel10_7-1.2", "description": "REPLACE_ME", "props": [ @@ -26778,7 +25716,7 @@ ] }, { - "uuid": "c065d3fb-f490-4335-afc7-9103fa693fb5", + "uuid": "d5bde2bf-ae6d-4962-9fc8-01dbe65faa36", "control-id": "cis_rhel10_7-1.3", "description": "REPLACE_ME", "props": [ @@ -26805,7 +25743,7 @@ ] }, { - "uuid": "83c298e1-f0bf-4429-bdf7-31aa4bde73a9", + "uuid": "d118cf57-454d-4047-b8fb-863aa6d30fde", "control-id": "cis_rhel10_7-1.4", "description": "REPLACE_ME", "props": [ @@ -26832,7 +25770,7 @@ ] }, { - "uuid": "83dce4c5-8176-4956-b1ca-7c05a1815513", + "uuid": "8864ab2d-5266-4d2a-9bb1-1e7559d1f8f9", "control-id": "cis_rhel10_7-1.5", "description": "REPLACE_ME", "props": [ @@ -26859,7 +25797,7 @@ ] }, { - "uuid": "b86ea0c6-ca61-4727-95ba-86dacbf19384", + "uuid": "9a3f1fe6-078c-46b6-af7e-5eae6309c15e", "control-id": "cis_rhel10_7-1.6", "description": "REPLACE_ME", "props": [ @@ -26886,7 +25824,7 @@ ] }, { - "uuid": "e321d8f7-ecef-4abf-b70f-317d9403c1d3", + "uuid": "33a108a9-e1b1-4e87-bd19-8f356b872a71", "control-id": "cis_rhel10_7-1.7", "description": "REPLACE_ME", "props": [ @@ -26913,7 +25851,7 @@ ] }, { - "uuid": "083244da-b638-4f7c-aa41-1c015fb2cb1e", + "uuid": "f27473d9-0a6a-4052-97a6-982e7f57611b", "control-id": "cis_rhel10_7-1.8", "description": "REPLACE_ME", "props": [ @@ -26940,7 +25878,7 @@ ] }, { - "uuid": "bc94de5a-89e1-4d0b-8e85-8b6b6d0348de", + "uuid": "57ed8876-c705-41ee-8298-c2d430901a17", "control-id": "cis_rhel10_7-1.9", "description": "REPLACE_ME", "props": [ @@ -26967,14 +25905,14 @@ ] }, { - "uuid": "c009a8e0-beca-4a1f-b511-1e6e9aece8b6", + "uuid": "d8a9eb02-3722-44ff-9885-34ea8ee11c21", "control-id": "cis_rhel10_7-1.10", "description": "REPLACE_ME", "props": [ { "name": "implementation-status", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "partial" + "value": "implemented" }, { "name": "Rule_Id", @@ -26984,7 +25922,7 @@ ] }, { - "uuid": "a2cd9bdc-5001-41a7-9a92-a8f0ca0cd458", + "uuid": "ba8de51a-19a1-4077-b42d-7d75937c9880", "control-id": "cis_rhel10_7-1.11", "description": "REPLACE_ME", "props": [ @@ -27006,7 +25944,7 @@ ] }, { - "uuid": "4c1daccb-e9d1-437b-9493-8513130ad923", + "uuid": "7f50c6b3-faad-444c-b97e-9c1ceb4d7d10", "control-id": "cis_rhel10_7-1.12", "description": "REPLACE_ME", "props": [ @@ -27028,7 +25966,7 @@ ] }, { - "uuid": "5971e45c-3006-41b9-a2ff-821d08042d23", + "uuid": "bd3eff65-fc40-4b1a-8391-4c8679b65d0c", "control-id": "cis_rhel10_7-1.13", "description": "REPLACE_ME", "props": [ @@ -27041,7 +25979,7 @@ ] }, { - "uuid": "4ce7d642-3a1b-48fc-9b5d-87ad634116d3", + "uuid": "4c59136d-c374-445f-aca5-32ae4d6a0c24", "control-id": "cis_rhel10_7-2.1", "description": "REPLACE_ME", "props": [ @@ -27058,7 +25996,7 @@ ] }, { - "uuid": "c3ae7e89-63b4-42df-a6ca-badfd6f100c7", + "uuid": "300b758f-3aa8-4708-b6bf-c2d7c1d04dca", "control-id": "cis_rhel10_7-2.2", "description": "REPLACE_ME", "props": [ @@ -27075,7 +26013,7 @@ ] }, { - "uuid": "72f1439a-931f-4a86-bbf4-2ec178681455", + "uuid": "c164bc0b-7ecc-48d8-8e64-9f4f3bff8b45", "control-id": "cis_rhel10_7-2.3", "description": "REPLACE_ME", "props": [ @@ -27092,7 +26030,7 @@ ] }, { - "uuid": "d9113e75-50f5-4011-8582-47a94b78af92", + "uuid": "fbcc01bf-571e-4110-a866-52d68151e658", "control-id": "cis_rhel10_7-2.4", "description": "REPLACE_ME", "props": [ @@ -27109,7 +26047,7 @@ ] }, { - "uuid": "7061e975-2c26-4ff5-9688-e6e9a3bbd7f9", + "uuid": "00354d81-409d-4b7f-9862-bd80ff8213e1", "control-id": "cis_rhel10_7-2.5", "description": "REPLACE_ME", "props": [ @@ -27126,7 +26064,7 @@ ] }, { - "uuid": "c861a772-c9d1-4739-b190-c4f9fead61a1", + "uuid": "91d9b14e-5e32-44f1-8f10-7d16f2d26f66", "control-id": "cis_rhel10_7-2.6", "description": "REPLACE_ME", "props": [ @@ -27143,7 +26081,7 @@ ] }, { - "uuid": "129d36af-5678-419d-b684-e2e742201a87", + "uuid": "623c71b9-6546-4421-bf84-fa8fd91320e6", "control-id": "cis_rhel10_7-2.7", "description": "REPLACE_ME", "props": [ @@ -27160,7 +26098,7 @@ ] }, { - "uuid": "6ea1f195-4864-4d43-ab4b-afe1b59a4456", + "uuid": "4b0a73a2-a1cd-4406-b453-a2c4ffb8736b", "control-id": "cis_rhel10_7-2.8", "description": "REPLACE_ME", "props": [ @@ -27187,7 +26125,7 @@ ] }, { - "uuid": "ba000a3a-02c7-4e30-b34c-bba317a89249", + "uuid": "ba854e27-c8b2-4f7b-8ce4-58f6605c9ac7", "control-id": "cis_rhel10_7-2.9", "description": "Missing a rule to check that .bash_history is mode 0600 or more restrictive.", "props": [ diff --git a/component-definitions/rhel10/rhel10-pcidss_4-base/component-definition.json b/component-definitions/rhel10/rhel10-pcidss_4-base/component-definition.json index b09e019be..e49d02249 100644 --- a/component-definitions/rhel10/rhel10-pcidss_4-base/component-definition.json +++ b/component-definitions/rhel10/rhel10-pcidss_4-base/component-definition.json @@ -3,8 +3,8 @@ "uuid": "e263ec70-49b2-459f-bfae-283464b2cdcb", "metadata": { "title": "Component definition for rhel10", - "last-modified": "2025-09-12T15:05:49.084064+08:00", - "version": "1.0", + "last-modified": "2025-09-16T19:38:31.978060+00:00", + "version": "1.1", "oscal-version": "1.1.3" }, "components": [ @@ -185,7 +185,7 @@ { "name": "Parameter_Value_Alternatives_8", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt'}", + "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt', 'cis_rhel10': 'single|halt'}", "remarks": "rule_set_000" }, { @@ -239,7 +239,7 @@ { "name": "Parameter_Value_Alternatives_11", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt'}", + "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt', 'cis_rhel10': 'email|exec|single|halt'}", "remarks": "rule_set_000" }, { @@ -563,7 +563,7 @@ { "name": "Parameter_Value_Alternatives_29", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { @@ -8409,7 +8409,7 @@ { "name": "Parameter_Value_Alternatives_8", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt'}", + "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt', 'cis_rhel10': 'single|halt'}", "remarks": "rule_set_000" }, { @@ -8463,7 +8463,7 @@ { "name": "Parameter_Value_Alternatives_11", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt'}", + "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt', 'cis_rhel10': 'email|exec|single|halt'}", "remarks": "rule_set_000" }, { @@ -8787,7 +8787,7 @@ { "name": "Parameter_Value_Alternatives_29", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { diff --git a/component-definitions/rhel8/rhel8-cis_rhel8-l1_server/component-definition.json b/component-definitions/rhel8/rhel8-cis_rhel8-l1_server/component-definition.json index 7c72af4f0..03d62da39 100644 --- a/component-definitions/rhel8/rhel8-cis_rhel8-l1_server/component-definition.json +++ b/component-definitions/rhel8/rhel8-cis_rhel8-l1_server/component-definition.json @@ -3,8 +3,8 @@ "uuid": "169aacf4-6ab5-4525-bf07-428709770afc", "metadata": { "title": "Component definition for rhel8", - "last-modified": "2025-09-12T10:09:15.924826+08:00", - "version": "2.2", + "last-modified": "2025-09-16T19:22:15.816619+00:00", + "version": "2.3", "oscal-version": "1.1.3" }, "components": [ @@ -149,7 +149,7 @@ { "name": "Parameter_Value_Alternatives_6", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", + "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel10': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", "remarks": "rule_set_000" }, { @@ -167,7 +167,7 @@ { "name": "Parameter_Value_Alternatives_7", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", + "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel10': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", "remarks": "rule_set_000" }, { @@ -1013,7 +1013,7 @@ { "name": "Parameter_Value_Alternatives_54", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { @@ -9320,7 +9320,7 @@ { "name": "Parameter_Value_Alternatives_6", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", + "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel10': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", "remarks": "rule_set_000" }, { @@ -9338,7 +9338,7 @@ { "name": "Parameter_Value_Alternatives_7", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", + "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel10': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", "remarks": "rule_set_000" }, { @@ -10184,7 +10184,7 @@ { "name": "Parameter_Value_Alternatives_54", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { diff --git a/component-definitions/rhel8/rhel8-cis_rhel8-l1_workstation/component-definition.json b/component-definitions/rhel8/rhel8-cis_rhel8-l1_workstation/component-definition.json index af4d7d258..4527cdeca 100644 --- a/component-definitions/rhel8/rhel8-cis_rhel8-l1_workstation/component-definition.json +++ b/component-definitions/rhel8/rhel8-cis_rhel8-l1_workstation/component-definition.json @@ -3,8 +3,8 @@ "uuid": "63123942-bfce-434a-aee1-53cb9c6908ab", "metadata": { "title": "Component definition for rhel8", - "last-modified": "2025-09-12T10:10:13.202031+08:00", - "version": "2.2", + "last-modified": "2025-09-16T19:23:04.893781+00:00", + "version": "2.3", "oscal-version": "1.1.3" }, "components": [ @@ -149,7 +149,7 @@ { "name": "Parameter_Value_Alternatives_6", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", + "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel10': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", "remarks": "rule_set_000" }, { @@ -167,7 +167,7 @@ { "name": "Parameter_Value_Alternatives_7", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", + "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel10': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", "remarks": "rule_set_000" }, { @@ -1013,7 +1013,7 @@ { "name": "Parameter_Value_Alternatives_54", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { @@ -9130,7 +9130,7 @@ { "name": "Parameter_Value_Alternatives_6", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", + "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel10': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", "remarks": "rule_set_000" }, { @@ -9148,7 +9148,7 @@ { "name": "Parameter_Value_Alternatives_7", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", + "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel10': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", "remarks": "rule_set_000" }, { @@ -9994,7 +9994,7 @@ { "name": "Parameter_Value_Alternatives_54", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { diff --git a/component-definitions/rhel8/rhel8-cis_rhel8-l2_server/component-definition.json b/component-definitions/rhel8/rhel8-cis_rhel8-l2_server/component-definition.json index 25f029393..df64309da 100644 --- a/component-definitions/rhel8/rhel8-cis_rhel8-l2_server/component-definition.json +++ b/component-definitions/rhel8/rhel8-cis_rhel8-l2_server/component-definition.json @@ -3,8 +3,8 @@ "uuid": "818eaee8-564a-4579-9b6f-51625ae868eb", "metadata": { "title": "Component definition for rhel8", - "last-modified": "2025-09-12T10:08:14.679370+08:00", - "version": "2.0", + "last-modified": "2025-09-16T19:21:26.314536+00:00", + "version": "2.1", "oscal-version": "1.1.3" }, "components": [ @@ -149,7 +149,7 @@ { "name": "Parameter_Value_Alternatives_6", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", + "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel10': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", "remarks": "rule_set_000" }, { @@ -167,7 +167,7 @@ { "name": "Parameter_Value_Alternatives_7", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", + "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel10': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", "remarks": "rule_set_000" }, { @@ -707,7 +707,7 @@ { "name": "Parameter_Value_Alternatives_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt'}", + "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt', 'cis_rhel10': 'single|halt'}", "remarks": "rule_set_000" }, { @@ -725,7 +725,7 @@ { "name": "Parameter_Value_Alternatives_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_rhel10': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", "remarks": "rule_set_000" }, { @@ -743,7 +743,7 @@ { "name": "Parameter_Value_Alternatives_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_rhel10': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", "remarks": "rule_set_000" }, { @@ -797,7 +797,7 @@ { "name": "Parameter_Value_Alternatives_42", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt'}", + "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt', 'cis_rhel10': 'email|exec|single|halt'}", "remarks": "rule_set_000" }, { @@ -1175,7 +1175,7 @@ { "name": "Parameter_Value_Alternatives_63", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { @@ -11997,7 +11997,7 @@ { "name": "Parameter_Value_Alternatives_6", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", + "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel10': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", "remarks": "rule_set_000" }, { @@ -12015,7 +12015,7 @@ { "name": "Parameter_Value_Alternatives_7", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", + "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel10': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", "remarks": "rule_set_000" }, { @@ -12555,7 +12555,7 @@ { "name": "Parameter_Value_Alternatives_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt'}", + "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt', 'cis_rhel10': 'single|halt'}", "remarks": "rule_set_000" }, { @@ -12573,7 +12573,7 @@ { "name": "Parameter_Value_Alternatives_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_rhel10': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", "remarks": "rule_set_000" }, { @@ -12591,7 +12591,7 @@ { "name": "Parameter_Value_Alternatives_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_rhel10': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", "remarks": "rule_set_000" }, { @@ -12645,7 +12645,7 @@ { "name": "Parameter_Value_Alternatives_42", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt'}", + "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt', 'cis_rhel10': 'email|exec|single|halt'}", "remarks": "rule_set_000" }, { @@ -13023,7 +13023,7 @@ { "name": "Parameter_Value_Alternatives_63", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { diff --git a/component-definitions/rhel8/rhel8-cis_rhel8-l2_workstation/component-definition.json b/component-definitions/rhel8/rhel8-cis_rhel8-l2_workstation/component-definition.json index 1ad182afb..02eb466b8 100644 --- a/component-definitions/rhel8/rhel8-cis_rhel8-l2_workstation/component-definition.json +++ b/component-definitions/rhel8/rhel8-cis_rhel8-l2_workstation/component-definition.json @@ -3,8 +3,8 @@ "uuid": "e7ff176e-2120-4fd3-8dfe-e89432cc1fb6", "metadata": { "title": "Component definition for rhel8", - "last-modified": "2025-09-12T10:11:16.196990+08:00", - "version": "2.0", + "last-modified": "2025-09-16T19:23:59.365685+00:00", + "version": "2.1", "oscal-version": "1.1.3" }, "components": [ @@ -149,7 +149,7 @@ { "name": "Parameter_Value_Alternatives_6", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", + "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel10': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", "remarks": "rule_set_000" }, { @@ -167,7 +167,7 @@ { "name": "Parameter_Value_Alternatives_7", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", + "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel10': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", "remarks": "rule_set_000" }, { @@ -707,7 +707,7 @@ { "name": "Parameter_Value_Alternatives_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt'}", + "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt', 'cis_rhel10': 'single|halt'}", "remarks": "rule_set_000" }, { @@ -725,7 +725,7 @@ { "name": "Parameter_Value_Alternatives_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_rhel10': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", "remarks": "rule_set_000" }, { @@ -743,7 +743,7 @@ { "name": "Parameter_Value_Alternatives_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_rhel10': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", "remarks": "rule_set_000" }, { @@ -797,7 +797,7 @@ { "name": "Parameter_Value_Alternatives_42", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt'}", + "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt', 'cis_rhel10': 'email|exec|single|halt'}", "remarks": "rule_set_000" }, { @@ -1175,7 +1175,7 @@ { "name": "Parameter_Value_Alternatives_63", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { @@ -11835,7 +11835,7 @@ { "name": "Parameter_Value_Alternatives_6", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", + "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel10': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", "remarks": "rule_set_000" }, { @@ -11853,7 +11853,7 @@ { "name": "Parameter_Value_Alternatives_7", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", + "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel10': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", "remarks": "rule_set_000" }, { @@ -12393,7 +12393,7 @@ { "name": "Parameter_Value_Alternatives_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt'}", + "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt', 'cis_rhel10': 'single|halt'}", "remarks": "rule_set_000" }, { @@ -12411,7 +12411,7 @@ { "name": "Parameter_Value_Alternatives_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_rhel10': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", "remarks": "rule_set_000" }, { @@ -12429,7 +12429,7 @@ { "name": "Parameter_Value_Alternatives_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_rhel10': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", "remarks": "rule_set_000" }, { @@ -12483,7 +12483,7 @@ { "name": "Parameter_Value_Alternatives_42", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt'}", + "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt', 'cis_rhel10': 'email|exec|single|halt'}", "remarks": "rule_set_000" }, { @@ -12861,7 +12861,7 @@ { "name": "Parameter_Value_Alternatives_63", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { diff --git a/component-definitions/rhel8/rhel8-pcidss_4-base/component-definition.json b/component-definitions/rhel8/rhel8-pcidss_4-base/component-definition.json index 80602c29c..46666d709 100644 --- a/component-definitions/rhel8/rhel8-pcidss_4-base/component-definition.json +++ b/component-definitions/rhel8/rhel8-pcidss_4-base/component-definition.json @@ -3,8 +3,8 @@ "uuid": "0e8a3aab-7677-482a-8602-ea572d38aa22", "metadata": { "title": "Component definition for rhel8", - "last-modified": "2025-09-12T10:32:40.562792+08:00", - "version": "1.8", + "last-modified": "2025-09-16T19:24:47.445494+00:00", + "version": "1.9", "oscal-version": "1.1.3" }, "components": [ @@ -185,7 +185,7 @@ { "name": "Parameter_Value_Alternatives_8", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt'}", + "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt', 'cis_rhel10': 'single|halt'}", "remarks": "rule_set_000" }, { @@ -239,7 +239,7 @@ { "name": "Parameter_Value_Alternatives_11", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt'}", + "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt', 'cis_rhel10': 'email|exec|single|halt'}", "remarks": "rule_set_000" }, { @@ -563,7 +563,7 @@ { "name": "Parameter_Value_Alternatives_29", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { @@ -8545,7 +8545,7 @@ { "name": "Parameter_Value_Alternatives_8", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt'}", + "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt', 'cis_rhel10': 'single|halt'}", "remarks": "rule_set_000" }, { @@ -8599,7 +8599,7 @@ { "name": "Parameter_Value_Alternatives_11", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt'}", + "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt', 'cis_rhel10': 'email|exec|single|halt'}", "remarks": "rule_set_000" }, { @@ -8923,7 +8923,7 @@ { "name": "Parameter_Value_Alternatives_29", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { diff --git a/component-definitions/rhel8/rhel8-stig_rhel8-high/component-definition.json b/component-definitions/rhel8/rhel8-stig_rhel8-high/component-definition.json index f40a4d33e..a795999cf 100644 --- a/component-definitions/rhel8/rhel8-stig_rhel8-high/component-definition.json +++ b/component-definitions/rhel8/rhel8-stig_rhel8-high/component-definition.json @@ -3,8 +3,8 @@ "uuid": "a3d5b14d-253f-4987-ac8f-ec42ec80dea8", "metadata": { "title": "Component definition for rhel8", - "last-modified": "2025-09-12T10:33:41.122680+08:00", - "version": "1.8", + "last-modified": "2025-09-16T19:25:41.412476+00:00", + "version": "1.9", "oscal-version": "1.1.3" }, "components": [ @@ -311,7 +311,7 @@ { "name": "Parameter_Value_Alternatives_15", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_rhel10': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", "remarks": "rule_set_000" }, { @@ -329,7 +329,7 @@ { "name": "Parameter_Value_Alternatives_16", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_rhel10': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", "remarks": "rule_set_000" }, { @@ -383,7 +383,7 @@ { "name": "Parameter_Value_Alternatives_19", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt'}", + "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt', 'cis_rhel10': 'email|exec|single|halt'}", "remarks": "rule_set_000" }, { @@ -941,7 +941,7 @@ { "name": "Parameter_Value_Alternatives_50", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { @@ -7028,7 +7028,7 @@ { "name": "Parameter_Value_Alternatives_15", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_rhel10': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", "remarks": "rule_set_000" }, { @@ -7046,7 +7046,7 @@ { "name": "Parameter_Value_Alternatives_16", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_rhel10': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", "remarks": "rule_set_000" }, { @@ -7100,7 +7100,7 @@ { "name": "Parameter_Value_Alternatives_19", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt'}", + "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt', 'cis_rhel10': 'email|exec|single|halt'}", "remarks": "rule_set_000" }, { @@ -7658,7 +7658,7 @@ { "name": "Parameter_Value_Alternatives_50", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { diff --git a/component-definitions/rhel8/rhel8-stig_rhel8-low/component-definition.json b/component-definitions/rhel8/rhel8-stig_rhel8-low/component-definition.json index a78986079..747334a3c 100644 --- a/component-definitions/rhel8/rhel8-stig_rhel8-low/component-definition.json +++ b/component-definitions/rhel8/rhel8-stig_rhel8-low/component-definition.json @@ -3,8 +3,8 @@ "uuid": "7ab0197a-252f-40bf-88be-00111a016c20", "metadata": { "title": "Component definition for rhel8", - "last-modified": "2025-09-12T10:35:44.143203+08:00", - "version": "1.8", + "last-modified": "2025-09-16T19:27:28.151836+00:00", + "version": "1.9", "oscal-version": "1.1.3" }, "components": [ @@ -311,7 +311,7 @@ { "name": "Parameter_Value_Alternatives_15", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_rhel10': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", "remarks": "rule_set_000" }, { @@ -329,7 +329,7 @@ { "name": "Parameter_Value_Alternatives_16", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_rhel10': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", "remarks": "rule_set_000" }, { @@ -383,7 +383,7 @@ { "name": "Parameter_Value_Alternatives_19", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt'}", + "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt', 'cis_rhel10': 'email|exec|single|halt'}", "remarks": "rule_set_000" }, { @@ -941,7 +941,7 @@ { "name": "Parameter_Value_Alternatives_50", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { @@ -7072,7 +7072,7 @@ { "name": "Parameter_Value_Alternatives_15", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_rhel10': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", "remarks": "rule_set_000" }, { @@ -7090,7 +7090,7 @@ { "name": "Parameter_Value_Alternatives_16", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_rhel10': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", "remarks": "rule_set_000" }, { @@ -7144,7 +7144,7 @@ { "name": "Parameter_Value_Alternatives_19", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt'}", + "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt', 'cis_rhel10': 'email|exec|single|halt'}", "remarks": "rule_set_000" }, { @@ -7702,7 +7702,7 @@ { "name": "Parameter_Value_Alternatives_50", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { diff --git a/component-definitions/rhel8/rhel8-stig_rhel8-medium/component-definition.json b/component-definitions/rhel8/rhel8-stig_rhel8-medium/component-definition.json index b3f19b241..f6656130d 100644 --- a/component-definitions/rhel8/rhel8-stig_rhel8-medium/component-definition.json +++ b/component-definitions/rhel8/rhel8-stig_rhel8-medium/component-definition.json @@ -3,8 +3,8 @@ "uuid": "864145f4-4b1e-422b-8257-704e7408d0da", "metadata": { "title": "Component definition for rhel8", - "last-modified": "2025-09-12T10:34:41.853587+08:00", - "version": "1.8", + "last-modified": "2025-09-16T19:26:35.131763+00:00", + "version": "1.9", "oscal-version": "1.1.3" }, "components": [ @@ -311,7 +311,7 @@ { "name": "Parameter_Value_Alternatives_15", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_rhel10': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", "remarks": "rule_set_000" }, { @@ -329,7 +329,7 @@ { "name": "Parameter_Value_Alternatives_16", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_rhel10': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", "remarks": "rule_set_000" }, { @@ -383,7 +383,7 @@ { "name": "Parameter_Value_Alternatives_19", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt'}", + "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt', 'cis_rhel10': 'email|exec|single|halt'}", "remarks": "rule_set_000" }, { @@ -941,7 +941,7 @@ { "name": "Parameter_Value_Alternatives_50", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { @@ -12210,7 +12210,7 @@ { "name": "Parameter_Value_Alternatives_15", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_rhel10': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", "remarks": "rule_set_000" }, { @@ -12228,7 +12228,7 @@ { "name": "Parameter_Value_Alternatives_16", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_rhel10': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", "remarks": "rule_set_000" }, { @@ -12282,7 +12282,7 @@ { "name": "Parameter_Value_Alternatives_19", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt'}", + "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt', 'cis_rhel10': 'email|exec|single|halt'}", "remarks": "rule_set_000" }, { @@ -12840,7 +12840,7 @@ { "name": "Parameter_Value_Alternatives_50", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { diff --git a/component-definitions/rhel9/rhel9-cis_rhel9-l1_server/component-definition.json b/component-definitions/rhel9/rhel9-cis_rhel9-l1_server/component-definition.json index 6559c6a70..c6a374d09 100644 --- a/component-definitions/rhel9/rhel9-cis_rhel9-l1_server/component-definition.json +++ b/component-definitions/rhel9/rhel9-cis_rhel9-l1_server/component-definition.json @@ -3,8 +3,8 @@ "uuid": "1aaa0f47-03e7-4e63-9933-f7a7b01cc8d0", "metadata": { "title": "Component definition for rhel9", - "last-modified": "2025-09-12T13:25:58.644329+08:00", - "version": "1.1", + "last-modified": "2025-09-16T19:29:10.411054+00:00", + "version": "1.2", "oscal-version": "1.1.3" }, "components": [ @@ -131,7 +131,7 @@ { "name": "Parameter_Value_Alternatives_5", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", + "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel10': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", "remarks": "rule_set_000" }, { @@ -149,7 +149,7 @@ { "name": "Parameter_Value_Alternatives_6", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", + "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel10': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", "remarks": "rule_set_000" }, { @@ -995,7 +995,7 @@ { "name": "Parameter_Value_Alternatives_53", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { @@ -9250,7 +9250,7 @@ { "name": "Parameter_Value_Alternatives_5", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", + "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel10': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", "remarks": "rule_set_000" }, { @@ -9268,7 +9268,7 @@ { "name": "Parameter_Value_Alternatives_6", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", + "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel10': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", "remarks": "rule_set_000" }, { @@ -10114,7 +10114,7 @@ { "name": "Parameter_Value_Alternatives_53", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { @@ -21656,4 +21656,4 @@ } ] } -} \ No newline at end of file +} diff --git a/component-definitions/rhel9/rhel9-cis_rhel9-l1_workstation/component-definition.json b/component-definitions/rhel9/rhel9-cis_rhel9-l1_workstation/component-definition.json index 98ec4517a..945370bdf 100644 --- a/component-definitions/rhel9/rhel9-cis_rhel9-l1_workstation/component-definition.json +++ b/component-definitions/rhel9/rhel9-cis_rhel9-l1_workstation/component-definition.json @@ -3,8 +3,8 @@ "uuid": "ebd9c7c5-154b-4257-b6a8-c19c5e8aedbe", "metadata": { "title": "Component definition for rhel9", - "last-modified": "2025-09-12T13:26:51.697055+08:00", - "version": "1.1", + "last-modified": "2025-09-16T19:29:58.028505+00:00", + "version": "1.2", "oscal-version": "1.1.3" }, "components": [ @@ -131,7 +131,7 @@ { "name": "Parameter_Value_Alternatives_5", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", + "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel10': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", "remarks": "rule_set_000" }, { @@ -149,7 +149,7 @@ { "name": "Parameter_Value_Alternatives_6", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", + "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel10': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", "remarks": "rule_set_000" }, { @@ -995,7 +995,7 @@ { "name": "Parameter_Value_Alternatives_53", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { @@ -9008,7 +9008,7 @@ { "name": "Parameter_Value_Alternatives_5", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", + "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel10': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", "remarks": "rule_set_000" }, { @@ -9026,7 +9026,7 @@ { "name": "Parameter_Value_Alternatives_6", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", + "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel10': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", "remarks": "rule_set_000" }, { @@ -9872,7 +9872,7 @@ { "name": "Parameter_Value_Alternatives_53", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { @@ -21076,4 +21076,4 @@ } ] } -} \ No newline at end of file +} diff --git a/component-definitions/rhel9/rhel9-cis_rhel9-l2_server/component-definition.json b/component-definitions/rhel9/rhel9-cis_rhel9-l2_server/component-definition.json index 2100f49c4..0fe60550b 100644 --- a/component-definitions/rhel9/rhel9-cis_rhel9-l2_server/component-definition.json +++ b/component-definitions/rhel9/rhel9-cis_rhel9-l2_server/component-definition.json @@ -3,8 +3,8 @@ "uuid": "728f5c33-2d56-4762-9099-a7923fb80339", "metadata": { "title": "Component definition for rhel9", - "last-modified": "2025-09-12T13:25:04.142300+08:00", - "version": "1.1", + "last-modified": "2025-09-16T19:28:22.323756+00:00", + "version": "1.2", "oscal-version": "1.1.3" }, "components": [ @@ -131,7 +131,7 @@ { "name": "Parameter_Value_Alternatives_5", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", + "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel10': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", "remarks": "rule_set_000" }, { @@ -149,7 +149,7 @@ { "name": "Parameter_Value_Alternatives_6", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", + "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel10': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", "remarks": "rule_set_000" }, { @@ -707,7 +707,7 @@ { "name": "Parameter_Value_Alternatives_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt'}", + "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt', 'cis_rhel10': 'single|halt'}", "remarks": "rule_set_000" }, { @@ -725,7 +725,7 @@ { "name": "Parameter_Value_Alternatives_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_rhel10': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", "remarks": "rule_set_000" }, { @@ -743,7 +743,7 @@ { "name": "Parameter_Value_Alternatives_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_rhel10': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", "remarks": "rule_set_000" }, { @@ -797,7 +797,7 @@ { "name": "Parameter_Value_Alternatives_42", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt'}", + "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt', 'cis_rhel10': 'email|exec|single|halt'}", "remarks": "rule_set_000" }, { @@ -1175,7 +1175,7 @@ { "name": "Parameter_Value_Alternatives_63", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { @@ -11986,7 +11986,7 @@ { "name": "Parameter_Value_Alternatives_5", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", + "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel10': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", "remarks": "rule_set_000" }, { @@ -12004,7 +12004,7 @@ { "name": "Parameter_Value_Alternatives_6", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", + "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel10': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", "remarks": "rule_set_000" }, { @@ -12562,7 +12562,7 @@ { "name": "Parameter_Value_Alternatives_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt'}", + "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt', 'cis_rhel10': 'single|halt'}", "remarks": "rule_set_000" }, { @@ -12580,7 +12580,7 @@ { "name": "Parameter_Value_Alternatives_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_rhel10': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", "remarks": "rule_set_000" }, { @@ -12598,7 +12598,7 @@ { "name": "Parameter_Value_Alternatives_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_rhel10': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", "remarks": "rule_set_000" }, { @@ -12652,7 +12652,7 @@ { "name": "Parameter_Value_Alternatives_42", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt'}", + "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt', 'cis_rhel10': 'email|exec|single|halt'}", "remarks": "rule_set_000" }, { @@ -13030,7 +13030,7 @@ { "name": "Parameter_Value_Alternatives_63", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { @@ -28352,4 +28352,4 @@ } ] } -} \ No newline at end of file +} diff --git a/component-definitions/rhel9/rhel9-cis_rhel9-l2_workstation/component-definition.json b/component-definitions/rhel9/rhel9-cis_rhel9-l2_workstation/component-definition.json index 385d304ec..705fe303c 100644 --- a/component-definitions/rhel9/rhel9-cis_rhel9-l2_workstation/component-definition.json +++ b/component-definitions/rhel9/rhel9-cis_rhel9-l2_workstation/component-definition.json @@ -3,8 +3,8 @@ "uuid": "10f54385-c153-49b6-8d7a-21a4b54d508e", "metadata": { "title": "Component definition for rhel9", - "last-modified": "2025-09-12T13:27:50.200060+08:00", - "version": "1.1", + "last-modified": "2025-09-16T19:30:50.667195+00:00", + "version": "1.2", "oscal-version": "1.1.3" }, "components": [ @@ -131,7 +131,7 @@ { "name": "Parameter_Value_Alternatives_5", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", + "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel10': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", "remarks": "rule_set_000" }, { @@ -149,7 +149,7 @@ { "name": "Parameter_Value_Alternatives_6", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", + "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel10': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", "remarks": "rule_set_000" }, { @@ -707,7 +707,7 @@ { "name": "Parameter_Value_Alternatives_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt'}", + "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt', 'cis_rhel10': 'single|halt'}", "remarks": "rule_set_000" }, { @@ -725,7 +725,7 @@ { "name": "Parameter_Value_Alternatives_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_rhel10': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", "remarks": "rule_set_000" }, { @@ -743,7 +743,7 @@ { "name": "Parameter_Value_Alternatives_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_rhel10': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", "remarks": "rule_set_000" }, { @@ -797,7 +797,7 @@ { "name": "Parameter_Value_Alternatives_42", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt'}", + "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt', 'cis_rhel10': 'email|exec|single|halt'}", "remarks": "rule_set_000" }, { @@ -1175,7 +1175,7 @@ { "name": "Parameter_Value_Alternatives_63", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { @@ -11824,7 +11824,7 @@ { "name": "Parameter_Value_Alternatives_5", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", + "value": "{'default': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'pcidss': 'ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_rhel8': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel9': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_rhel10': '-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1', 'cis_sle12': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_sle15': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256', 'cis_ubuntu2204': 'curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'cis_ubuntu2404': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256', 'std_openeuler': 'curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256', 'cis_debian12': 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256'}", "remarks": "rule_set_000" }, { @@ -11842,7 +11842,7 @@ { "name": "Parameter_Value_Alternatives_6", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", + "value": "{'default': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_rhel8': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel9': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_rhel10': '-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com', 'cis_sle12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160', 'cis_sle15': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_tencentos4': 'hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com', 'cis_ubuntu2204': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'cis_ubuntu2404': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256', 'stig_rhel9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'stig_ol9': 'hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512', 'cis_debian12': 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256'}", "remarks": "rule_set_000" }, { @@ -12400,7 +12400,7 @@ { "name": "Parameter_Value_Alternatives_37", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt'}", + "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt', 'cis_rhel10': 'single|halt'}", "remarks": "rule_set_000" }, { @@ -12418,7 +12418,7 @@ { "name": "Parameter_Value_Alternatives_38", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_rhel10': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", "remarks": "rule_set_000" }, { @@ -12436,7 +12436,7 @@ { "name": "Parameter_Value_Alternatives_39", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_rhel10': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", "remarks": "rule_set_000" }, { @@ -12490,7 +12490,7 @@ { "name": "Parameter_Value_Alternatives_42", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt'}", + "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt', 'cis_rhel10': 'email|exec|single|halt'}", "remarks": "rule_set_000" }, { @@ -12868,7 +12868,7 @@ { "name": "Parameter_Value_Alternatives_63", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { @@ -27956,4 +27956,4 @@ } ] } -} \ No newline at end of file +} diff --git a/component-definitions/rhel9/rhel9-pcidss_4-base/component-definition.json b/component-definitions/rhel9/rhel9-pcidss_4-base/component-definition.json index 01767de83..12e46be26 100644 --- a/component-definitions/rhel9/rhel9-pcidss_4-base/component-definition.json +++ b/component-definitions/rhel9/rhel9-pcidss_4-base/component-definition.json @@ -3,8 +3,8 @@ "uuid": "82eef6a2-1ce5-4817-af27-287cf97df8aa", "metadata": { "title": "Component definition for rhel9", - "last-modified": "2025-09-12T13:35:01.883221+08:00", - "version": "1.1", + "last-modified": "2025-09-16T19:31:38.051103+00:00", + "version": "1.2", "oscal-version": "1.1.3" }, "components": [ @@ -185,7 +185,7 @@ { "name": "Parameter_Value_Alternatives_8", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt'}", + "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt', 'cis_rhel10': 'single|halt'}", "remarks": "rule_set_000" }, { @@ -239,7 +239,7 @@ { "name": "Parameter_Value_Alternatives_11", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt'}", + "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt', 'cis_rhel10': 'email|exec|single|halt'}", "remarks": "rule_set_000" }, { @@ -563,7 +563,7 @@ { "name": "Parameter_Value_Alternatives_29", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { @@ -8426,7 +8426,7 @@ { "name": "Parameter_Value_Alternatives_8", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt'}", + "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt', 'cis_rhel10': 'single|halt'}", "remarks": "rule_set_000" }, { @@ -8480,7 +8480,7 @@ { "name": "Parameter_Value_Alternatives_11", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt'}", + "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt', 'cis_rhel10': 'email|exec|single|halt'}", "remarks": "rule_set_000" }, { @@ -8804,7 +8804,7 @@ { "name": "Parameter_Value_Alternatives_29", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { @@ -19492,4 +19492,4 @@ } ] } -} \ No newline at end of file +} diff --git a/component-definitions/rhel9/rhel9-stig_rhel9-high/component-definition.json b/component-definitions/rhel9/rhel9-stig_rhel9-high/component-definition.json index b3a10d07c..232504f2c 100644 --- a/component-definitions/rhel9/rhel9-stig_rhel9-high/component-definition.json +++ b/component-definitions/rhel9/rhel9-stig_rhel9-high/component-definition.json @@ -3,8 +3,8 @@ "uuid": "3cf866f5-a877-4889-9f22-dbc4f7ff4cf9", "metadata": { "title": "Component definition for rhel9", - "last-modified": "2025-09-12T13:36:06.287124+08:00", - "version": "1.1", + "last-modified": "2025-09-16T19:32:35.274679+00:00", + "version": "1.2", "oscal-version": "1.1.3" }, "components": [ @@ -329,7 +329,7 @@ { "name": "Parameter_Value_Alternatives_16", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt'}", + "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt', 'cis_rhel10': 'single|halt'}", "remarks": "rule_set_000" }, { @@ -365,7 +365,7 @@ { "name": "Parameter_Value_Alternatives_18", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_rhel10': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", "remarks": "rule_set_000" }, { @@ -383,7 +383,7 @@ { "name": "Parameter_Value_Alternatives_19", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_rhel10': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", "remarks": "rule_set_000" }, { @@ -455,7 +455,7 @@ { "name": "Parameter_Value_Alternatives_23", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt'}", + "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt', 'cis_rhel10': 'email|exec|single|halt'}", "remarks": "rule_set_000" }, { @@ -977,7 +977,7 @@ { "name": "Parameter_Value_Alternatives_52", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { @@ -6923,7 +6923,7 @@ ], "control-implementations": [ { - "uuid": "2cf17da4-210d-4307-a8a0-3f6a6d63db95", + "uuid": "447f3f3c-e1ea-4793-9343-388356bb4221", "source": "trestle://profiles/rhel9-stig_rhel9-high/profile.json", "description": "REPLACE_ME", "props": [ @@ -7249,7 +7249,7 @@ { "param-id": "var_system_crypto_policy", "values": [ - "fips" + "fips_stig" ] }, { @@ -7267,7 +7267,7 @@ ], "implemented-requirements": [ { - "uuid": "b6d0d6a8-d6af-4889-ac66-bf9f9efdf8ce", + "uuid": "b852b54d-d29d-4cbd-8f81-a8f59c58dff4", "control-id": "rhel-09.211010", "description": "REPLACE_ME", "props": [ @@ -7284,7 +7284,7 @@ ] }, { - "uuid": "23f2bd20-b264-415c-be60-3e0e71326e64", + "uuid": "c90b08f7-95d0-4ee1-8ffc-b2967e04ba6a", "control-id": "rhel-09.211045", "description": "REPLACE_ME", "props": [ @@ -7301,7 +7301,7 @@ ] }, { - "uuid": "de23a22c-1033-46ef-be79-552511a1df97", + "uuid": "ef9da414-241b-47d7-be82-a3e7ab573f75", "control-id": "rhel-09.211050", "description": "REPLACE_ME", "props": [ @@ -7318,7 +7318,7 @@ ] }, { - "uuid": "44875c40-0027-4f3e-acae-56a24d734add", + "uuid": "f4dbd969-bbd4-4c5f-9f00-918720a7f3f4", "control-id": "rhel-09.212020", "description": "REPLACE_ME", "props": [ @@ -7335,7 +7335,7 @@ ] }, { - "uuid": "3c9c0c17-7406-45f9-97ca-787872b96a32", + "uuid": "6d4bbf2a-f818-4ae7-8eab-7f7104722380", "control-id": "rhel-09.214015", "description": "REPLACE_ME", "props": [ @@ -7352,7 +7352,7 @@ ] }, { - "uuid": "41d31721-471b-4eb4-8ba7-9d5e342be2f8", + "uuid": "6eba081e-c663-48cd-b90a-577a2b743e31", "control-id": "rhel-09.214020", "description": "REPLACE_ME", "props": [ @@ -7369,7 +7369,7 @@ ] }, { - "uuid": "7251b158-e4c0-4d43-afc2-3f291aa18304", + "uuid": "835683aa-53aa-4646-81ec-166a811e0a67", "control-id": "rhel-09.214025", "description": "REPLACE_ME", "props": [ @@ -7386,7 +7386,7 @@ ] }, { - "uuid": "6241dffd-45b4-4c1a-bc4b-e7f790648f53", + "uuid": "a35f0dc0-53ef-47bf-92ca-a87c69e8e0c7", "control-id": "rhel-09.215015", "description": "REPLACE_ME", "props": [ @@ -7403,7 +7403,7 @@ ] }, { - "uuid": "962914b0-e30d-4a2f-886c-c65d66a8a2a3", + "uuid": "3df84303-85bf-4cb5-bb00-4e7967819a30", "control-id": "rhel-09.215060", "description": "REPLACE_ME", "props": [ @@ -7420,7 +7420,7 @@ ] }, { - "uuid": "f7628995-d143-41ba-97bd-1f709710f42c", + "uuid": "a4636971-8a03-46ff-91a9-de75b459c507", "control-id": "rhel-09.231190", "description": "REPLACE_ME", "props": [ @@ -7437,7 +7437,7 @@ ] }, { - "uuid": "f9dc86c9-16ac-4251-8ae4-c858e9f05334", + "uuid": "aa875cb7-1b3d-432b-8781-e5a43f820bf4", "control-id": "rhel-09.252070", "description": "REPLACE_ME", "props": [ @@ -7454,7 +7454,7 @@ ] }, { - "uuid": "f47699a0-62f4-4c06-8cf2-9b728655fcf0", + "uuid": "70ac49fd-c6bc-4472-b6c6-67a1b77ca313", "control-id": "rhel-09.252075", "description": "REPLACE_ME", "props": [ @@ -7471,7 +7471,7 @@ ] }, { - "uuid": "694a2d78-fbd2-4ad1-933c-31639662adca", + "uuid": "55483552-8a9a-4a2c-8a07-2fdbb468613f", "control-id": "rhel-09.255040", "description": "REPLACE_ME", "props": [ @@ -7488,7 +7488,7 @@ ] }, { - "uuid": "169d2c41-5657-4efd-abb6-2ea024a7dd1c", + "uuid": "9a3df669-abe2-47e4-924c-c1a7ac242c05", "control-id": "rhel-09.255050", "description": "REPLACE_ME", "props": [ @@ -7505,7 +7505,7 @@ ] }, { - "uuid": "4f521b35-f814-4e66-93ec-50b62dff2bda", + "uuid": "60ceb08b-6f3c-4634-9bd1-1e545b7bca33", "control-id": "rhel-09.271040", "description": "REPLACE_ME", "props": [ @@ -7522,7 +7522,7 @@ ] }, { - "uuid": "f2bcec98-b578-4366-96fb-2a4a1e814b9c", + "uuid": "6c90c2ab-265b-4d0d-8f89-4306642069b1", "control-id": "rhel-09.411100", "description": "REPLACE_ME", "props": [ @@ -7539,7 +7539,7 @@ ] }, { - "uuid": "1d8dd1f3-a87f-462d-bb9a-4245102de8c0", + "uuid": "1f35cd66-c712-4a43-a12f-a5b19d0ec6e6", "control-id": "rhel-09.431010", "description": "REPLACE_ME", "props": [ @@ -7556,7 +7556,7 @@ ] }, { - "uuid": "95d5cd29-33ac-451c-ac4b-e1f164d38eb5", + "uuid": "ae3ebea4-9d51-4eff-ae8d-b9327fb4acc4", "control-id": "rhel-09.431016", "description": "REPLACE_ME", "props": [ @@ -7573,7 +7573,7 @@ ] }, { - "uuid": "246e36d5-9cc7-4a72-af1e-c265da4f81b2", + "uuid": "57fa16ae-4f35-47bd-8eed-3a2c85aabe96", "control-id": "rhel-09.611025", "description": "REPLACE_ME", "props": [ @@ -7590,7 +7590,7 @@ ] }, { - "uuid": "fd6302da-78e5-404e-91ee-71737dfcab99", + "uuid": "04ef57ea-b9f7-4111-91a1-d2f04c6e71ec", "control-id": "rhel-09.671010", "description": "REPLACE_ME", "props": [ @@ -7617,7 +7617,7 @@ ] }, { - "uuid": "73688b83-c678-4aa1-b89b-a1816677a79d", + "uuid": "24f147d4-adf8-4854-a867-28fac90bce1b", "control-id": "rhel-09.672015", "description": "REPLACE_ME", "props": [ @@ -7630,7 +7630,7 @@ ] }, { - "uuid": "281dc963-f8f3-4d1b-8edd-c7091782d6ef", + "uuid": "e351f127-f322-4aaa-bc09-cd7748122f6c", "control-id": "rhel-09.672030", "description": "REPLACE_ME", "props": [ @@ -7983,7 +7983,7 @@ { "name": "Parameter_Value_Alternatives_16", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt'}", + "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt', 'cis_rhel10': 'single|halt'}", "remarks": "rule_set_000" }, { @@ -8019,7 +8019,7 @@ { "name": "Parameter_Value_Alternatives_18", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_rhel10': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", "remarks": "rule_set_000" }, { @@ -8037,7 +8037,7 @@ { "name": "Parameter_Value_Alternatives_19", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_rhel10': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", "remarks": "rule_set_000" }, { @@ -8109,7 +8109,7 @@ { "name": "Parameter_Value_Alternatives_23", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt'}", + "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt', 'cis_rhel10': 'email|exec|single|halt'}", "remarks": "rule_set_000" }, { @@ -8631,7 +8631,7 @@ { "name": "Parameter_Value_Alternatives_52", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { @@ -20481,7 +20481,7 @@ ], "control-implementations": [ { - "uuid": "f367d1c0-389d-4a41-bcf3-1eee440f35dd", + "uuid": "b1fe98f2-ab9b-49bc-a6e0-7526e3a4aa67", "source": "trestle://profiles/rhel9-stig_rhel9-high/profile.json", "description": "REPLACE_ME", "props": [ @@ -20807,7 +20807,7 @@ { "param-id": "var_system_crypto_policy", "values": [ - "fips" + "fips_stig" ] }, { @@ -20825,7 +20825,7 @@ ], "implemented-requirements": [ { - "uuid": "d25bb9d8-cd6f-4571-af72-4bac54a2721a", + "uuid": "84a31922-708b-42e8-a072-7c1f53a75cd2", "control-id": "rhel-09.211010", "description": "REPLACE_ME", "props": [ @@ -20842,7 +20842,7 @@ ] }, { - "uuid": "aa7532a1-ea58-4ff3-8e58-d5f57e99e5c7", + "uuid": "6fabfeb5-7898-40ec-9771-cf4bd820e7bc", "control-id": "rhel-09.211045", "description": "REPLACE_ME", "props": [ @@ -20859,7 +20859,7 @@ ] }, { - "uuid": "cfe9e57e-7a18-43b7-945c-3d98ae9a3f6a", + "uuid": "7983fe9e-40e1-41b4-a4f8-63361a284d31", "control-id": "rhel-09.211050", "description": "REPLACE_ME", "props": [ @@ -20876,7 +20876,7 @@ ] }, { - "uuid": "146d912d-7174-4815-8b8e-cac103ac4c93", + "uuid": "cb47e05f-6336-432c-b683-0da2ecd97558", "control-id": "rhel-09.212020", "description": "REPLACE_ME", "props": [ @@ -20893,7 +20893,7 @@ ] }, { - "uuid": "0234ff00-1fba-4092-b62f-6573b3144def", + "uuid": "64d2e2e1-6c23-4eb7-9026-b52826f2500d", "control-id": "rhel-09.214015", "description": "REPLACE_ME", "props": [ @@ -20910,7 +20910,7 @@ ] }, { - "uuid": "36a26c51-f8b3-4b8c-8d6b-a462099084f5", + "uuid": "212ec47b-4396-4d90-bc50-dee977a46b27", "control-id": "rhel-09.214020", "description": "REPLACE_ME", "props": [ @@ -20927,7 +20927,7 @@ ] }, { - "uuid": "25ac741b-cc88-44ba-b6d6-a24b30aaff69", + "uuid": "cc1a5e58-fda1-4d62-9e22-64847350b61a", "control-id": "rhel-09.214025", "description": "REPLACE_ME", "props": [ @@ -20944,7 +20944,7 @@ ] }, { - "uuid": "fdb3228d-fe28-434f-b0e8-7771fd7f327f", + "uuid": "e0031007-d0b1-41b7-bd06-fac64d22bb66", "control-id": "rhel-09.215015", "description": "REPLACE_ME", "props": [ @@ -20961,7 +20961,7 @@ ] }, { - "uuid": "91837fc6-c5dc-4280-8d39-d2d638783fa2", + "uuid": "437a7005-7b1d-41bb-bef4-29fdd2b8696d", "control-id": "rhel-09.215060", "description": "REPLACE_ME", "props": [ @@ -20978,7 +20978,7 @@ ] }, { - "uuid": "aee282fc-d529-4bad-a4d0-4d70bfd45188", + "uuid": "e04fe9b3-07da-4a94-aa4a-7b14348032bb", "control-id": "rhel-09.231190", "description": "REPLACE_ME", "props": [ @@ -20995,7 +20995,7 @@ ] }, { - "uuid": "70655ed0-8ca6-46b2-b838-a7e27d060995", + "uuid": "d4326235-b892-4723-ab15-bfb3ada29b26", "control-id": "rhel-09.252070", "description": "REPLACE_ME", "props": [ @@ -21012,7 +21012,7 @@ ] }, { - "uuid": "e52de0bc-2d8c-4bcd-8b50-96be501739fd", + "uuid": "069776d4-1ddb-42b1-a81e-dac90275d4c4", "control-id": "rhel-09.252075", "description": "REPLACE_ME", "props": [ @@ -21029,7 +21029,7 @@ ] }, { - "uuid": "2bca0ee3-f077-402d-b300-ce19c513a833", + "uuid": "5f6fdadf-7e30-419c-b274-4c7fdb4c10c4", "control-id": "rhel-09.255040", "description": "REPLACE_ME", "props": [ @@ -21046,7 +21046,7 @@ ] }, { - "uuid": "61dc8cc6-2e79-424d-8ba1-b78801e917da", + "uuid": "f97e2438-d2be-4653-9bfb-0ec85e8d1a58", "control-id": "rhel-09.255050", "description": "REPLACE_ME", "props": [ @@ -21063,7 +21063,7 @@ ] }, { - "uuid": "7dd0d1f6-1a4e-43c4-908d-5c0e4b369791", + "uuid": "772dc236-aec4-4dee-8cca-c4cd7d9dbbd5", "control-id": "rhel-09.271040", "description": "REPLACE_ME", "props": [ @@ -21080,7 +21080,7 @@ ] }, { - "uuid": "38d84fe8-18d9-48d7-9665-2969a987038b", + "uuid": "43824555-2346-4d63-8043-bfbde31002ce", "control-id": "rhel-09.411100", "description": "REPLACE_ME", "props": [ @@ -21097,7 +21097,7 @@ ] }, { - "uuid": "9a8077e2-838e-439f-953c-0d34f1e79cff", + "uuid": "4daea47a-380f-4f51-9d21-0b73929200fa", "control-id": "rhel-09.431010", "description": "REPLACE_ME", "props": [ @@ -21114,7 +21114,7 @@ ] }, { - "uuid": "9a70503d-8dd2-4ac3-834e-43750f7c08c0", + "uuid": "526ee0b0-36b8-48ae-848c-482fd5d3187f", "control-id": "rhel-09.431016", "description": "REPLACE_ME", "props": [ @@ -21131,7 +21131,7 @@ ] }, { - "uuid": "fc17890f-8e7a-443f-8f5a-a1edeb3c0b63", + "uuid": "c6ba1273-9490-4e04-a020-934251ba084a", "control-id": "rhel-09.611025", "description": "REPLACE_ME", "props": [ @@ -21148,7 +21148,7 @@ ] }, { - "uuid": "4d57c8d2-59a8-4168-9759-2e8a8529e5d0", + "uuid": "c168af1b-683d-4b28-9b70-56955c8939de", "control-id": "rhel-09.671010", "description": "REPLACE_ME", "props": [ @@ -21175,7 +21175,7 @@ ] }, { - "uuid": "b6bf4528-3657-46f2-9085-dd549fd15a55", + "uuid": "217db898-d075-4aca-aa9d-b0560daeec49", "control-id": "rhel-09.672015", "description": "REPLACE_ME", "props": [ @@ -21188,7 +21188,7 @@ ] }, { - "uuid": "68b881e8-90c0-4012-bbea-b88521085f41", + "uuid": "2d53ce49-f721-453d-9d17-99f6b79ce5b2", "control-id": "rhel-09.672030", "description": "REPLACE_ME", "props": [ @@ -21210,4 +21210,4 @@ } ] } -} \ No newline at end of file +} diff --git a/component-definitions/rhel9/rhel9-stig_rhel9-low/component-definition.json b/component-definitions/rhel9/rhel9-stig_rhel9-low/component-definition.json index 4d1f86b6d..c1990ef72 100644 --- a/component-definitions/rhel9/rhel9-stig_rhel9-low/component-definition.json +++ b/component-definitions/rhel9/rhel9-stig_rhel9-low/component-definition.json @@ -3,8 +3,8 @@ "uuid": "1b1feb53-c4af-4351-9a25-d99774a01d82", "metadata": { "title": "Component definition for rhel9", - "last-modified": "2025-09-12T13:38:15.035120+08:00", - "version": "1.1", + "last-modified": "2025-09-16T19:34:27.893429+00:00", + "version": "1.2", "oscal-version": "1.1.3" }, "components": [ @@ -329,7 +329,7 @@ { "name": "Parameter_Value_Alternatives_16", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt'}", + "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt', 'cis_rhel10': 'single|halt'}", "remarks": "rule_set_000" }, { @@ -365,7 +365,7 @@ { "name": "Parameter_Value_Alternatives_18", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_rhel10': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", "remarks": "rule_set_000" }, { @@ -383,7 +383,7 @@ { "name": "Parameter_Value_Alternatives_19", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_rhel10': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", "remarks": "rule_set_000" }, { @@ -455,7 +455,7 @@ { "name": "Parameter_Value_Alternatives_23", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt'}", + "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt', 'cis_rhel10': 'email|exec|single|halt'}", "remarks": "rule_set_000" }, { @@ -977,7 +977,7 @@ { "name": "Parameter_Value_Alternatives_52", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { @@ -6923,7 +6923,7 @@ ], "control-implementations": [ { - "uuid": "f389615c-3b93-4a3e-ac60-da3d22ba921f", + "uuid": "039fc6aa-ebb8-4470-ba96-600d82429e39", "source": "trestle://profiles/rhel9-stig_rhel9-low/profile.json", "description": "REPLACE_ME", "props": [ @@ -7249,7 +7249,7 @@ { "param-id": "var_system_crypto_policy", "values": [ - "fips" + "fips_stig" ] }, { @@ -7267,7 +7267,7 @@ ], "implemented-requirements": [ { - "uuid": "44864e4a-d029-47e6-9456-fb47653bcc53", + "uuid": "24be244a-b860-4d3d-bbf4-823ed9c23de7", "control-id": "rhel-09.211035", "description": "REPLACE_ME", "props": [ @@ -7280,7 +7280,7 @@ ] }, { - "uuid": "96b00e43-0357-4a06-80e5-24e5c229e8cb", + "uuid": "b2fa93f8-6143-46ba-ab22-a34695587878", "control-id": "rhel-09.212050", "description": "REPLACE_ME", "props": [ @@ -7297,7 +7297,7 @@ ] }, { - "uuid": "58936cf3-7454-49aa-807e-0fcfbf4a1807", + "uuid": "04a04370-f9c2-4a78-bab5-d157c88131ba", "control-id": "rhel-09.212055", "description": "REPLACE_ME", "props": [ @@ -7314,7 +7314,7 @@ ] }, { - "uuid": "730e3604-1078-49c9-b874-fcae7b13c94a", + "uuid": "813272f2-d27b-4b35-975b-316674a3c8c2", "control-id": "rhel-09.214035", "description": "REPLACE_ME", "props": [ @@ -7331,7 +7331,7 @@ ] }, { - "uuid": "a66c4072-72ba-4fdd-b994-2a6c3c28cccd", + "uuid": "dbf080dd-9c96-41f0-8dba-df9232457a39", "control-id": "rhel-09.231020", "description": "REPLACE_ME", "props": [ @@ -7348,7 +7348,7 @@ ] }, { - "uuid": "5925f2b9-0cd6-4933-a8d8-21abd2025c8f", + "uuid": "ad17b8e3-dc33-4b5c-811c-a5c92d900ccf", "control-id": "rhel-09.231025", "description": "REPLACE_ME", "props": [ @@ -7365,7 +7365,7 @@ ] }, { - "uuid": "5aeae5bf-012f-404e-90d6-32cd1917f765", + "uuid": "471ddcc1-50a1-46ba-b1c6-d93c7d2fa1ae", "control-id": "rhel-09.231030", "description": "REPLACE_ME", "props": [ @@ -7382,7 +7382,7 @@ ] }, { - "uuid": "ec5d5aac-c2d6-4438-a402-9e031b795fd0", + "uuid": "ba4152cb-5850-477c-be06-5ad00ce13854", "control-id": "rhel-09.231195", "description": "REPLACE_ME", "props": [ @@ -7399,7 +7399,7 @@ ] }, { - "uuid": "9350eb1b-cd68-4ecc-a322-adbf122ade06", + "uuid": "5c29e2b2-95fe-4f2f-9ada-fd54d814bb0c", "control-id": "rhel-09.252025", "description": "REPLACE_ME", "props": [ @@ -7416,7 +7416,7 @@ ] }, { - "uuid": "74759a8b-d7f4-4ebb-ab34-b026a63e7a66", + "uuid": "1ca56ade-30e6-4695-b837-6240ef544c87", "control-id": "rhel-09.252030", "description": "REPLACE_ME", "props": [ @@ -7433,7 +7433,7 @@ ] }, { - "uuid": "1c3ce9c8-70cc-4547-9b3b-298f029f8c55", + "uuid": "5ea17e3b-3d1b-4a44-95b7-e84b1d3f9b4a", "control-id": "rhel-09.291025", "description": "REPLACE_ME", "props": [ @@ -7450,7 +7450,7 @@ ] }, { - "uuid": "d351e259-4146-4e5e-b956-bc8eee35382e", + "uuid": "054bfbb3-9718-4a7e-98c0-5cbfdebc05d4", "control-id": "rhel-09.412040", "description": "REPLACE_ME", "props": [ @@ -7467,7 +7467,7 @@ ] }, { - "uuid": "f7b63bfc-cbd3-4c51-aadf-4b78a7f82437", + "uuid": "6cad0cfb-e911-43e8-b8c1-cad91aa5a61d", "control-id": "rhel-09.412075", "description": "REPLACE_ME", "props": [ @@ -7484,7 +7484,7 @@ ] }, { - "uuid": "089aeee0-d3bb-45eb-8477-b9e541c0dbec", + "uuid": "d4fba941-1aab-424c-b1d9-e40aa827b798", "control-id": "rhel-09.651030", "description": "REPLACE_ME", "props": [ @@ -7501,7 +7501,7 @@ ] }, { - "uuid": "bdba7d73-7e04-4556-893d-c6c3f4f1f133", + "uuid": "bc9e3b52-f7ba-4d61-aa01-e01d876de0d3", "control-id": "rhel-09.651035", "description": "REPLACE_ME", "props": [ @@ -7518,7 +7518,7 @@ ] }, { - "uuid": "f080a9b2-fe87-486b-8a2d-ee7db9c435db", + "uuid": "43f4cf93-38b2-408d-9e5d-562de88ebc3e", "control-id": "rhel-09.653120", "description": "REPLACE_ME", "props": [ @@ -7871,7 +7871,7 @@ { "name": "Parameter_Value_Alternatives_16", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt'}", + "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt', 'cis_rhel10': 'single|halt'}", "remarks": "rule_set_000" }, { @@ -7907,7 +7907,7 @@ { "name": "Parameter_Value_Alternatives_18", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_rhel10': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", "remarks": "rule_set_000" }, { @@ -7925,7 +7925,7 @@ { "name": "Parameter_Value_Alternatives_19", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_rhel10': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", "remarks": "rule_set_000" }, { @@ -7997,7 +7997,7 @@ { "name": "Parameter_Value_Alternatives_23", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt'}", + "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt', 'cis_rhel10': 'email|exec|single|halt'}", "remarks": "rule_set_000" }, { @@ -8519,7 +8519,7 @@ { "name": "Parameter_Value_Alternatives_52", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { @@ -20369,7 +20369,7 @@ ], "control-implementations": [ { - "uuid": "1b51659f-0d70-4faf-a5fa-21bfc7638bac", + "uuid": "3202abb5-d4dd-400c-957e-0cbc6bbc228f", "source": "trestle://profiles/rhel9-stig_rhel9-low/profile.json", "description": "REPLACE_ME", "props": [ @@ -20695,7 +20695,7 @@ { "param-id": "var_system_crypto_policy", "values": [ - "fips" + "fips_stig" ] }, { @@ -20713,7 +20713,7 @@ ], "implemented-requirements": [ { - "uuid": "9bb3daf4-f337-437b-a31a-1e7c0c7ebae6", + "uuid": "17e84a97-8935-4ad3-b4ed-f52d1f5f3d48", "control-id": "rhel-09.211035", "description": "REPLACE_ME", "props": [ @@ -20726,7 +20726,7 @@ ] }, { - "uuid": "b1d902fe-ac88-4ecd-b99d-e6c7719a5ead", + "uuid": "19862f8e-8700-4b51-8374-b0987c63f730", "control-id": "rhel-09.212050", "description": "REPLACE_ME", "props": [ @@ -20743,7 +20743,7 @@ ] }, { - "uuid": "abcdbb0e-e992-4301-aa44-8abe96576e0a", + "uuid": "3bb43940-ad3c-469d-a96d-fffebaa509f4", "control-id": "rhel-09.212055", "description": "REPLACE_ME", "props": [ @@ -20760,7 +20760,7 @@ ] }, { - "uuid": "5a22b1e0-5df3-47ae-8eed-e2f729d50ced", + "uuid": "ab766351-ba97-476f-b760-43ca36d53590", "control-id": "rhel-09.214035", "description": "REPLACE_ME", "props": [ @@ -20777,7 +20777,7 @@ ] }, { - "uuid": "a37ab187-4c43-4b08-bc7c-df94e8abccd7", + "uuid": "f013a74f-e560-400a-8d89-8b08cdf50a8c", "control-id": "rhel-09.231020", "description": "REPLACE_ME", "props": [ @@ -20794,7 +20794,7 @@ ] }, { - "uuid": "b50ddf19-53a9-4cad-830a-53947233f33a", + "uuid": "a686ccdd-184b-4a0f-be0e-0e6ca5088d49", "control-id": "rhel-09.231025", "description": "REPLACE_ME", "props": [ @@ -20811,7 +20811,7 @@ ] }, { - "uuid": "91b3da08-9718-41ec-be51-87185337ba23", + "uuid": "6aaabdf0-dd9e-43ff-9977-f0daf5e1e198", "control-id": "rhel-09.231030", "description": "REPLACE_ME", "props": [ @@ -20828,7 +20828,7 @@ ] }, { - "uuid": "f86a4ded-2d2f-4207-921c-4fd2e7bbbaf4", + "uuid": "83db1a7d-4888-48ea-b339-b6e5ecf7ef87", "control-id": "rhel-09.231195", "description": "REPLACE_ME", "props": [ @@ -20845,7 +20845,7 @@ ] }, { - "uuid": "0af99ce0-ce0a-44ce-9518-7c5d72156eab", + "uuid": "586d4e0a-d7a1-472f-8d60-15346fe6f0fc", "control-id": "rhel-09.252025", "description": "REPLACE_ME", "props": [ @@ -20862,7 +20862,7 @@ ] }, { - "uuid": "a37049fc-30af-4ea1-a793-6e1d46c44e88", + "uuid": "0bdcb0c7-7f0c-4269-a934-3f011c01a095", "control-id": "rhel-09.252030", "description": "REPLACE_ME", "props": [ @@ -20879,7 +20879,7 @@ ] }, { - "uuid": "039206ed-bf52-4e5c-a7e3-0acb86528952", + "uuid": "431250c7-5c47-463c-a057-58a7b8a4add1", "control-id": "rhel-09.291025", "description": "REPLACE_ME", "props": [ @@ -20896,7 +20896,7 @@ ] }, { - "uuid": "18ac7f6c-35f5-44b0-82fe-512ca35dac46", + "uuid": "0499181c-fbfe-4704-b972-2ac7bd12691a", "control-id": "rhel-09.412040", "description": "REPLACE_ME", "props": [ @@ -20913,7 +20913,7 @@ ] }, { - "uuid": "1544fcda-5999-4e08-a309-062057a96122", + "uuid": "841ff20a-90ef-4397-a3e5-9dab294d9c30", "control-id": "rhel-09.412075", "description": "REPLACE_ME", "props": [ @@ -20930,7 +20930,7 @@ ] }, { - "uuid": "672b6fb6-5b25-4ef7-95fc-6407234599dd", + "uuid": "ae10ba0c-b5e5-4e88-b622-f0a2ba1135ba", "control-id": "rhel-09.651030", "description": "REPLACE_ME", "props": [ @@ -20947,7 +20947,7 @@ ] }, { - "uuid": "33132e73-6b4e-475b-a12f-4937e22ed9ee", + "uuid": "a6c84aaa-68e1-42f6-a396-5526a406e9c1", "control-id": "rhel-09.651035", "description": "REPLACE_ME", "props": [ @@ -20964,7 +20964,7 @@ ] }, { - "uuid": "80ca9943-7447-488c-8d75-543dc9e86cd8", + "uuid": "129c9cda-dd71-4369-b243-758dc9b7095d", "control-id": "rhel-09.653120", "description": "REPLACE_ME", "props": [ @@ -20986,4 +20986,4 @@ } ] } -} \ No newline at end of file +} diff --git a/component-definitions/rhel9/rhel9-stig_rhel9-medium/component-definition.json b/component-definitions/rhel9/rhel9-stig_rhel9-medium/component-definition.json index 532103585..0dc023b1c 100644 --- a/component-definitions/rhel9/rhel9-stig_rhel9-medium/component-definition.json +++ b/component-definitions/rhel9/rhel9-stig_rhel9-medium/component-definition.json @@ -3,8 +3,8 @@ "uuid": "7c36017d-6d99-4cd9-9e5c-74d62489ecfb", "metadata": { "title": "Component definition for rhel9", - "last-modified": "2025-09-12T13:37:10.367771+08:00", - "version": "1.1", + "last-modified": "2025-09-16T19:33:32.050817+00:00", + "version": "1.2", "oscal-version": "1.1.3" }, "components": [ @@ -329,7 +329,7 @@ { "name": "Parameter_Value_Alternatives_16", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt'}", + "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt', 'cis_rhel10': 'single|halt'}", "remarks": "rule_set_000" }, { @@ -365,7 +365,7 @@ { "name": "Parameter_Value_Alternatives_18", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_rhel10': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", "remarks": "rule_set_000" }, { @@ -383,7 +383,7 @@ { "name": "Parameter_Value_Alternatives_19", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_rhel10': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", "remarks": "rule_set_000" }, { @@ -455,7 +455,7 @@ { "name": "Parameter_Value_Alternatives_23", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt'}", + "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt', 'cis_rhel10': 'email|exec|single|halt'}", "remarks": "rule_set_000" }, { @@ -977,7 +977,7 @@ { "name": "Parameter_Value_Alternatives_52", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { @@ -6923,7 +6923,7 @@ ], "control-implementations": [ { - "uuid": "c9da6f9a-1a77-451c-a868-36cf064c3174", + "uuid": "625bf85d-4e9d-400d-b1ae-7fdd533291ea", "source": "trestle://profiles/rhel9-stig_rhel9-medium/profile.json", "description": "REPLACE_ME", "props": [ @@ -7249,7 +7249,7 @@ { "param-id": "var_system_crypto_policy", "values": [ - "fips" + "fips_stig" ] }, { @@ -7267,7 +7267,7 @@ ], "implemented-requirements": [ { - "uuid": "7ece9ad5-3ea2-485f-89d9-83c7938d95e4", + "uuid": "3336749a-6ffc-4b82-8ffe-d2156ae4e4cb", "control-id": "needed_rules", "description": "REPLACE_ME", "props": [ @@ -7285,7 +7285,7 @@ ] }, { - "uuid": "f589db66-29ff-4e66-a887-5695794f37fa", + "uuid": "de431bb9-73fb-4807-90c7-d19c33032f47", "control-id": "rhel-09.171011", "description": "REPLACE_ME", "props": [ @@ -7303,7 +7303,7 @@ ] }, { - "uuid": "7dea9a4c-cee8-4a68-8f81-d234ca4dfc73", + "uuid": "ca84aaee-6643-442f-a5fe-0f8a939748a8", "control-id": "rhel-09.211015", "description": "REPLACE_ME", "props": [ @@ -7320,7 +7320,7 @@ ] }, { - "uuid": "15f6e118-77f0-4b3f-920d-c52e09f486d2", + "uuid": "818648f0-6953-4d2f-8815-aff7ed4d05e2", "control-id": "rhel-09.211020", "description": "REPLACE_ME", "props": [ @@ -7337,7 +7337,7 @@ ] }, { - "uuid": "bd9e3dcb-9182-41d5-936e-1cdd01f615b1", + "uuid": "a34c2cdc-6498-412a-8f03-118e3fec3e07", "control-id": "rhel-09.211030", "description": "REPLACE_ME", "props": [ @@ -7354,7 +7354,7 @@ ] }, { - "uuid": "d33c81c4-cc3f-4d72-934e-84f4aa49047e", + "uuid": "9cb4b18a-8d34-4962-90da-31ff76fd4513", "control-id": "rhel-09.211040", "description": "REPLACE_ME", "props": [ @@ -7371,7 +7371,7 @@ ] }, { - "uuid": "05ad7f30-e037-40ab-8677-8a2d1687db03", + "uuid": "ec1e126d-71ad-45c2-ab7a-93be2991173f", "control-id": "rhel-09.211055", "description": "REPLACE_ME", "props": [ @@ -7388,7 +7388,7 @@ ] }, { - "uuid": "6637adeb-a40c-4aa6-92e3-e5f94f23015c", + "uuid": "7b1369a8-cf10-4708-81a5-b81a0c155fda", "control-id": "rhel-09.212010", "description": "REPLACE_ME", "props": [ @@ -7405,7 +7405,7 @@ ] }, { - "uuid": "3740f4ba-dcd6-4615-82c7-f577c6e8970a", + "uuid": "26d90854-fed6-4c7f-a019-75431de470d0", "control-id": "rhel-09.212015", "description": "REPLACE_ME", "props": [ @@ -7422,7 +7422,7 @@ ] }, { - "uuid": "4c7ef8c5-de41-4000-bec3-f594c1fca6f3", + "uuid": "7e8cd648-02ab-48cd-b845-b8c24e3d5026", "control-id": "rhel-09.212025", "description": "REPLACE_ME", "props": [ @@ -7439,7 +7439,7 @@ ] }, { - "uuid": "330a336b-5753-4e5d-baf3-81b9d75433da", + "uuid": "6d8400eb-ba38-40af-88b6-1963e4e530bb", "control-id": "rhel-09.212030", "description": "REPLACE_ME", "props": [ @@ -7456,7 +7456,7 @@ ] }, { - "uuid": "6c18933a-a5cd-42b7-b586-0314919fb74d", + "uuid": "aacaf315-9674-4961-a7b7-3c22f06ae95e", "control-id": "rhel-09.212035", "description": "REPLACE_ME", "props": [ @@ -7473,7 +7473,7 @@ ] }, { - "uuid": "26be7801-4836-4509-ae44-d3162a96c9bd", + "uuid": "ad63fede-cdf6-4e3d-81d5-2d0dc3dbec38", "control-id": "rhel-09.212040", "description": "REPLACE_ME", "props": [ @@ -7490,7 +7490,7 @@ ] }, { - "uuid": "543726fd-43ad-4483-84a0-e538dfdd839f", + "uuid": "3424a4b3-e54f-436c-9511-c1b7addb4bc8", "control-id": "rhel-09.212045", "description": "REPLACE_ME", "props": [ @@ -7507,7 +7507,7 @@ ] }, { - "uuid": "d06fdda7-913e-49db-ab1e-07d4087287f8", + "uuid": "eb0d7dc4-3a13-4669-8b89-f95f625ba63a", "control-id": "rhel-09.213010", "description": "REPLACE_ME", "props": [ @@ -7524,7 +7524,7 @@ ] }, { - "uuid": "ffe4f345-663a-450e-99e5-727c8096b70f", + "uuid": "d63e64f4-8a4b-4aa3-a7e1-2898e20ecb04", "control-id": "rhel-09.213015", "description": "REPLACE_ME", "props": [ @@ -7541,7 +7541,7 @@ ] }, { - "uuid": "ca4cfea6-869c-4c17-b9ee-6c7a2ba8b8cf", + "uuid": "dec3f4d7-1e21-4b83-ae66-e810d8dbb1ae", "control-id": "rhel-09.213020", "description": "REPLACE_ME", "props": [ @@ -7558,7 +7558,7 @@ ] }, { - "uuid": "a1d5c3b6-4778-48ee-afbd-18268a0bd392", + "uuid": "ee4c680e-ec10-45c8-8682-c090a29fa231", "control-id": "rhel-09.213025", "description": "REPLACE_ME", "props": [ @@ -7575,7 +7575,7 @@ ] }, { - "uuid": "fbd1f223-0f57-4f5d-ac61-fbd75b577f5b", + "uuid": "28ca331e-9530-445f-95ae-6703470aaec3", "control-id": "rhel-09.213030", "description": "REPLACE_ME", "props": [ @@ -7592,7 +7592,7 @@ ] }, { - "uuid": "31ae5a9b-8733-45ad-a973-f6245b23be99", + "uuid": "e7e5b3b7-4aa0-4ec4-aadd-1a8cdac8482f", "control-id": "rhel-09.213035", "description": "REPLACE_ME", "props": [ @@ -7609,7 +7609,7 @@ ] }, { - "uuid": "5b0be247-7fbe-4059-8c17-9deeb9c710b6", + "uuid": "575c0a4d-03b8-4b4a-b68c-bdcdba56f857", "control-id": "rhel-09.213040", "description": "REPLACE_ME", "props": [ @@ -7626,7 +7626,7 @@ ] }, { - "uuid": "7511aa8d-bf03-4d95-8317-97a3a6329387", + "uuid": "b66bca4a-269e-49eb-adab-6c48a1282a1c", "control-id": "rhel-09.213045", "description": "REPLACE_ME", "props": [ @@ -7643,7 +7643,7 @@ ] }, { - "uuid": "6187cf97-7357-48c9-a342-33cf4d8a48de", + "uuid": "d8389c81-27f7-47f4-b54c-a304aaf0b50a", "control-id": "rhel-09.213050", "description": "REPLACE_ME", "props": [ @@ -7660,7 +7660,7 @@ ] }, { - "uuid": "a72d0bbc-cd56-440f-a294-104d1076bdaa", + "uuid": "444c2ca5-9d2c-4f77-a75d-c89a500194b7", "control-id": "rhel-09.213055", "description": "REPLACE_ME", "props": [ @@ -7677,7 +7677,7 @@ ] }, { - "uuid": "9d9f59e1-2a12-4459-9857-e9e5dbfcfbb3", + "uuid": "6aac343f-8c92-42ae-b28e-69a85e6c7902", "control-id": "rhel-09.213060", "description": "REPLACE_ME", "props": [ @@ -7694,7 +7694,7 @@ ] }, { - "uuid": "2cea4178-c73f-4fca-b728-384f12c49e58", + "uuid": "ee2ac3dc-9d98-4d23-b259-a415220445a8", "control-id": "rhel-09.213065", "description": "REPLACE_ME", "props": [ @@ -7711,7 +7711,7 @@ ] }, { - "uuid": "6b918cca-2255-4493-9fb3-fd41622f7359", + "uuid": "9c9f3c83-9c06-483d-96c6-a4228c706903", "control-id": "rhel-09.213070", "description": "REPLACE_ME", "props": [ @@ -7728,7 +7728,7 @@ ] }, { - "uuid": "94facb88-3fc7-4958-a2f4-ba970de0c0db", + "uuid": "0dc03006-ea2b-4684-bae7-39a3b2175020", "control-id": "rhel-09.213075", "description": "REPLACE_ME", "props": [ @@ -7745,7 +7745,7 @@ ] }, { - "uuid": "25b12491-92d4-41e2-9117-2ae79dc77497", + "uuid": "7730f12c-6e21-4aed-ac32-31cb94878973", "control-id": "rhel-09.213080", "description": "REPLACE_ME", "props": [ @@ -7762,7 +7762,7 @@ ] }, { - "uuid": "023edb97-6a8d-4667-a808-29654aae906c", + "uuid": "95148600-3bf1-4787-aef8-3430e40d870a", "control-id": "rhel-09.213085", "description": "REPLACE_ME", "props": [ @@ -7779,7 +7779,7 @@ ] }, { - "uuid": "3cc4a75f-5ab8-48c7-a478-9c20da1082e0", + "uuid": "26548832-4c2a-40e1-8e90-ebc7f84a066e", "control-id": "rhel-09.213090", "description": "REPLACE_ME", "props": [ @@ -7796,7 +7796,7 @@ ] }, { - "uuid": "70c4cdbe-aed2-4b10-8c15-d40f0242e75d", + "uuid": "8ba82a00-aa55-45ef-9364-3c6dbdb5ef68", "control-id": "rhel-09.213095", "description": "REPLACE_ME", "props": [ @@ -7813,7 +7813,7 @@ ] }, { - "uuid": "b73d2814-fca0-4a48-8a10-e82517e5a03a", + "uuid": "c0cecca1-e9d1-45e6-80c7-73223bdfcf86", "control-id": "rhel-09.213100", "description": "REPLACE_ME", "props": [ @@ -7830,7 +7830,7 @@ ] }, { - "uuid": "1a0c6f59-07b4-496f-9994-23656b2c6288", + "uuid": "cb41b812-239d-4186-a141-3c0d27f49b47", "control-id": "rhel-09.213105", "description": "REPLACE_ME", "props": [ @@ -7847,7 +7847,7 @@ ] }, { - "uuid": "47d8c3ab-627b-4981-ad67-dd580f70ea26", + "uuid": "6bc24879-b965-4d5c-a0e5-038bdcb95c62", "control-id": "rhel-09.213110", "description": "REPLACE_ME", "props": [ @@ -7864,7 +7864,7 @@ ] }, { - "uuid": "7f0e7ad1-1884-4e5b-9095-885facf228dc", + "uuid": "36af5043-4834-4621-9e84-e2b47efc932e", "control-id": "rhel-09.213115", "description": "REPLACE_ME", "props": [ @@ -7881,7 +7881,7 @@ ] }, { - "uuid": "7a939e9f-60a7-4ef3-8edb-ecfbd21a4056", + "uuid": "afe0a029-5202-461d-977d-ed08c5b7de6b", "control-id": "rhel-09.214010", "description": "REPLACE_ME", "props": [ @@ -7898,7 +7898,7 @@ ] }, { - "uuid": "fc25ea96-c6e2-4e4a-b663-097b13c4f5f2", + "uuid": "adad301f-be6b-436b-bd23-14ffbd5a4fcb", "control-id": "rhel-09.214030", "description": "REPLACE_ME", "props": [ @@ -7911,7 +7911,7 @@ ] }, { - "uuid": "2ad631ea-0925-47ca-a149-8d3e0fec4a20", + "uuid": "c331fe10-c614-4d3e-bdbb-a312f1b8d8a2", "control-id": "rhel-09.215010", "description": "REPLACE_ME", "props": [ @@ -7928,7 +7928,7 @@ ] }, { - "uuid": "41f04727-184c-4a97-8e6a-612f78be8a0e", + "uuid": "497ad753-f988-41c6-8470-38d3ced170a3", "control-id": "rhel-09.215020", "description": "REPLACE_ME", "props": [ @@ -7945,7 +7945,7 @@ ] }, { - "uuid": "390a36c7-a435-4d16-9184-6f69e3026f89", + "uuid": "ab70d277-4ffa-4402-861f-43cfcadab772", "control-id": "rhel-09.215025", "description": "REPLACE_ME", "props": [ @@ -7962,7 +7962,7 @@ ] }, { - "uuid": "5d4932f7-a051-4841-8db3-6f10efd04376", + "uuid": "ff288a5c-1089-4a67-8afc-4236894a6f65", "control-id": "rhel-09.215030", "description": "REPLACE_ME", "props": [ @@ -7975,7 +7975,7 @@ ] }, { - "uuid": "5c9a8fce-49d5-484d-9eea-f0c9162dd224", + "uuid": "b8cf5c07-eefa-4c3c-a92d-5c17dc329fe0", "control-id": "rhel-09.215035", "description": "REPLACE_ME", "props": [ @@ -7988,7 +7988,7 @@ ] }, { - "uuid": "3755149e-8339-4b65-9e20-fe2ba8f7b332", + "uuid": "9f7249f3-7922-46ad-a08c-b6d1184e58aa", "control-id": "rhel-09.215040", "description": "REPLACE_ME", "props": [ @@ -8005,7 +8005,7 @@ ] }, { - "uuid": "6a2e69d0-9a2f-4c37-a124-b26c58b17ff5", + "uuid": "55b869a3-ba19-478b-b248-076678aa6a4c", "control-id": "rhel-09.215045", "description": "REPLACE_ME", "props": [ @@ -8022,7 +8022,7 @@ ] }, { - "uuid": "7641804d-d17d-4d7c-b506-232b618af122", + "uuid": "c000fd2f-74ec-4f02-bc35-d902ed41a48d", "control-id": "rhel-09.215050", "description": "REPLACE_ME", "props": [ @@ -8039,7 +8039,7 @@ ] }, { - "uuid": "89790c82-f942-4d99-9e26-1ed818afc226", + "uuid": "aaa8495a-47d2-4a5b-b342-dc202a9da924", "control-id": "rhel-09.215055", "description": "REPLACE_ME", "props": [ @@ -8056,7 +8056,7 @@ ] }, { - "uuid": "4a40c28e-e7e0-402e-bdf2-3ce58d1774fb", + "uuid": "d8a21e87-0f6f-4d64-a752-73bf40ec17e5", "control-id": "rhel-09.215065", "description": "REPLACE_ME", "props": [ @@ -8069,7 +8069,7 @@ ] }, { - "uuid": "ed526d2c-ece5-4541-a822-f2df0e3fa084", + "uuid": "198304fe-00b1-4d31-a257-a34aeaa7b037", "control-id": "rhel-09.215070", "description": "REPLACE_ME", "props": [ @@ -8086,7 +8086,7 @@ ] }, { - "uuid": "1ab26d6e-b1f6-4954-8700-d1a2c5c65ec9", + "uuid": "a052229a-e0a2-4ff2-ae1f-df23832da978", "control-id": "rhel-09.215075", "description": "REPLACE_ME", "props": [ @@ -8103,7 +8103,7 @@ ] }, { - "uuid": "46c2ea14-ecac-45b6-b0e5-ac798ec70779", + "uuid": "d49b2c6b-3912-4eac-b099-b59f69421f05", "control-id": "rhel-09.215080", "description": "REPLACE_ME", "props": [ @@ -8120,7 +8120,7 @@ ] }, { - "uuid": "a7d71cf3-e715-428b-b13f-e4febd4c903d", + "uuid": "3e1e9abf-87a0-4cb4-badf-88b5cd066ec7", "control-id": "rhel-09.215085", "description": "REPLACE_ME", "props": [ @@ -8137,7 +8137,7 @@ ] }, { - "uuid": "ddb3129a-0e86-46cc-85b6-db8a30045303", + "uuid": "bad56a82-5f86-47d0-b18a-07252f27f16d", "control-id": "rhel-09.215090", "description": "REPLACE_ME", "props": [ @@ -8154,7 +8154,7 @@ ] }, { - "uuid": "863157d2-bd80-4dd7-aad2-2938834cd57d", + "uuid": "0ede3fcc-307f-42a7-a1b0-395fc6d5e57b", "control-id": "rhel-09.215095", "description": "REPLACE_ME", "props": [ @@ -8171,7 +8171,7 @@ ] }, { - "uuid": "9af2d39a-57a3-4987-8294-28bfe8e1e6aa", + "uuid": "c5ced960-ba78-4776-b91f-b88b8f114a91", "control-id": "rhel-09.215100", "description": "REPLACE_ME", "props": [ @@ -8188,7 +8188,7 @@ ] }, { - "uuid": "fbc7223e-0506-45dc-b480-a6a5ae873aa1", + "uuid": "6fe354d5-a2ed-447f-9a50-0e0c7d067e0a", "control-id": "rhel-09.215101", "description": "REPLACE_ME", "props": [ @@ -8205,7 +8205,7 @@ ] }, { - "uuid": "80e420c5-5f0b-4cd0-a6af-2d7881127630", + "uuid": "f80729cd-1954-43b8-a239-d13d5fec57c0", "control-id": "rhel-09.215105", "description": "REPLACE_ME", "props": [ @@ -8232,7 +8232,7 @@ ] }, { - "uuid": "7e24cc4d-f5f1-4c55-8c78-5256b15ff9c5", + "uuid": "3a5082d1-5b60-4ed2-a4dc-759da2ee40d2", "control-id": "rhel-09.231010", "description": "REPLACE_ME", "props": [ @@ -8249,7 +8249,7 @@ ] }, { - "uuid": "229d7a6c-5190-4bb5-976a-3267c0cabfda", + "uuid": "62833db7-5e83-473d-af74-ba25c7a5696c", "control-id": "rhel-09.231015", "description": "REPLACE_ME", "props": [ @@ -8266,7 +8266,7 @@ ] }, { - "uuid": "fc695232-bda4-4b4d-885e-19f43de7ff57", + "uuid": "a4ba5f7c-6d58-44a0-b493-78b019350134", "control-id": "rhel-09.231035", "description": "REPLACE_ME", "props": [ @@ -8283,7 +8283,7 @@ ] }, { - "uuid": "104a2c9e-b581-4179-92b7-a69079320846", + "uuid": "4c44f034-1e62-499d-8501-2585f6bf2e27", "control-id": "rhel-09.231040", "description": "REPLACE_ME", "props": [ @@ -8300,7 +8300,7 @@ ] }, { - "uuid": "5cf2fcac-d792-4527-bb5c-55500aa9a01f", + "uuid": "66dfbd6d-72e2-4a7e-9eb0-a33b1cd45883", "control-id": "rhel-09.231045", "description": "REPLACE_ME", "props": [ @@ -8317,7 +8317,7 @@ ] }, { - "uuid": "81f2f415-cf99-401e-9690-c2aaa7ea550a", + "uuid": "820c7d4b-e033-48cf-b80d-526074a2ec45", "control-id": "rhel-09.231050", "description": "REPLACE_ME", "props": [ @@ -8334,7 +8334,7 @@ ] }, { - "uuid": "ce976776-1f25-4ab5-8e16-c64df33a8610", + "uuid": "b97f8b6c-8c61-4439-8a2e-64996ebc5b60", "control-id": "rhel-09.231055", "description": "REPLACE_ME", "props": [ @@ -8351,7 +8351,7 @@ ] }, { - "uuid": "e9675d86-ef4a-4c13-8fb3-d051792eeeab", + "uuid": "45b2ca7d-27a1-4f9b-876a-000cbfbf19f7", "control-id": "rhel-09.231065", "description": "REPLACE_ME", "props": [ @@ -8368,7 +8368,7 @@ ] }, { - "uuid": "977c4553-159a-4bb7-9e69-3cecc7a5a856", + "uuid": "2ec5d10c-f65a-4a38-b4c5-5975fe6320d6", "control-id": "rhel-09.231070", "description": "REPLACE_ME", "props": [ @@ -8385,7 +8385,7 @@ ] }, { - "uuid": "4704c088-af36-42a0-9dc8-a4a7771bc5ce", + "uuid": "ba68d7aa-3fa2-427c-96c6-5db25176b193", "control-id": "rhel-09.231075", "description": "REPLACE_ME", "props": [ @@ -8402,7 +8402,7 @@ ] }, { - "uuid": "ef193d1b-e91f-4fbb-a50e-9d3e80616084", + "uuid": "4a5a4197-a1ea-4ced-8c3c-1a5b221d4b32", "control-id": "rhel-09.231080", "description": "REPLACE_ME", "props": [ @@ -8419,7 +8419,7 @@ ] }, { - "uuid": "d52d9375-a6cb-4d4d-bcd9-423f562a2a36", + "uuid": "e7efef55-aad2-4cd2-a04d-7840be634c57", "control-id": "rhel-09.231085", "description": "REPLACE_ME", "props": [ @@ -8436,7 +8436,7 @@ ] }, { - "uuid": "287a90af-f0dd-4180-8c75-6b5cd35263f1", + "uuid": "9e9542e8-30c2-4cdd-9038-947d89dfde79", "control-id": "rhel-09.231090", "description": "REPLACE_ME", "props": [ @@ -8453,7 +8453,7 @@ ] }, { - "uuid": "6c0582b8-b16d-4be6-9947-2272b6c62b24", + "uuid": "2f35ebd1-8cf1-40a5-b099-5c93aed102f2", "control-id": "rhel-09.231095", "description": "REPLACE_ME", "props": [ @@ -8470,7 +8470,7 @@ ] }, { - "uuid": "d534e713-fdc5-48d9-9661-50370d375c41", + "uuid": "e56604c7-9694-441a-9364-b9f1e2018a74", "control-id": "rhel-09.231100", "description": "REPLACE_ME", "props": [ @@ -8487,7 +8487,7 @@ ] }, { - "uuid": "6bc00c2b-fd51-4664-9503-125c5629ff78", + "uuid": "349966f9-bb0c-4806-ab41-274b56e5df0c", "control-id": "rhel-09.231105", "description": "REPLACE_ME", "props": [ @@ -8504,7 +8504,7 @@ ] }, { - "uuid": "0a768e3e-612f-41e6-b8ab-073b20b0e26f", + "uuid": "bc36a79a-e0e4-4fc5-9c07-97e5e8ed5023", "control-id": "rhel-09.231110", "description": "REPLACE_ME", "props": [ @@ -8521,7 +8521,7 @@ ] }, { - "uuid": "304581cb-d108-4ba1-ba41-ca319fd9f1f3", + "uuid": "03d28ce4-9782-4f51-b5a3-fe82231396c7", "control-id": "rhel-09.231115", "description": "REPLACE_ME", "props": [ @@ -8538,7 +8538,7 @@ ] }, { - "uuid": "4388fff5-60a3-4e18-af00-95e4a64b96e5", + "uuid": "7006da5a-6ae2-482f-94e5-294008c4aedc", "control-id": "rhel-09.231120", "description": "REPLACE_ME", "props": [ @@ -8555,7 +8555,7 @@ ] }, { - "uuid": "cec0d9a9-032c-4ebc-96d1-39a7021d0438", + "uuid": "f76e5f3f-3044-4ac3-8f21-defcc759a592", "control-id": "rhel-09.231125", "description": "REPLACE_ME", "props": [ @@ -8572,7 +8572,7 @@ ] }, { - "uuid": "648b5d34-aae8-4e34-b071-39f3cf90e7f5", + "uuid": "84f9229c-d72c-497e-91eb-a2e0a1e5315b", "control-id": "rhel-09.231130", "description": "REPLACE_ME", "props": [ @@ -8589,7 +8589,7 @@ ] }, { - "uuid": "4dc3af45-90f8-4d7e-95f8-ef67b66050e9", + "uuid": "9d9935b9-2f8a-4795-a78f-48890cf34e89", "control-id": "rhel-09.231135", "description": "REPLACE_ME", "props": [ @@ -8606,7 +8606,7 @@ ] }, { - "uuid": "eec5b2bf-d6ab-4a0b-b1b6-a78a71bf8191", + "uuid": "28346738-6733-48c3-89d7-bc19338aae06", "control-id": "rhel-09.231140", "description": "REPLACE_ME", "props": [ @@ -8623,7 +8623,7 @@ ] }, { - "uuid": "ba46873f-0932-4bf1-8f0e-ad3f54198ce2", + "uuid": "7b01b0de-7398-4a78-9631-cd87aadf0b4c", "control-id": "rhel-09.231145", "description": "REPLACE_ME", "props": [ @@ -8640,7 +8640,7 @@ ] }, { - "uuid": "cb2f9467-1fdf-4b0d-b57a-e05c1c1a1dff", + "uuid": "c457acb7-e7d2-4b5f-82f0-7a5be9851246", "control-id": "rhel-09.231150", "description": "REPLACE_ME", "props": [ @@ -8657,7 +8657,7 @@ ] }, { - "uuid": "e13a7845-26f3-400c-9138-47d605aec301", + "uuid": "61780bf5-f694-44f7-a71e-1311adbebd1e", "control-id": "rhel-09.231155", "description": "REPLACE_ME", "props": [ @@ -8674,7 +8674,7 @@ ] }, { - "uuid": "75e8c172-5cd1-41a3-b0a2-f7055fbc2880", + "uuid": "381ef829-c17d-4844-8199-929be530a45d", "control-id": "rhel-09.231160", "description": "REPLACE_ME", "props": [ @@ -8691,7 +8691,7 @@ ] }, { - "uuid": "b5c58ee7-e14b-42ad-91a8-9cc1870cbe6c", + "uuid": "6e2f31a3-30db-4454-be61-e81bb7e319ce", "control-id": "rhel-09.231165", "description": "REPLACE_ME", "props": [ @@ -8708,7 +8708,7 @@ ] }, { - "uuid": "bc80e9a5-607c-42b1-aaa6-68734728c507", + "uuid": "d4ede2f3-a072-4a99-bea0-10ae0aba7e8f", "control-id": "rhel-09.231170", "description": "REPLACE_ME", "props": [ @@ -8725,7 +8725,7 @@ ] }, { - "uuid": "773cf573-eaf8-49d7-8a5d-c00d7f31e48a", + "uuid": "5c52b858-4400-4d2b-80ac-a95d298a4cc0", "control-id": "rhel-09.231175", "description": "REPLACE_ME", "props": [ @@ -8742,7 +8742,7 @@ ] }, { - "uuid": "13cdc65b-432c-415d-89b1-43c7ddd60df5", + "uuid": "536c813f-dea9-438e-bc29-2d0f18005b88", "control-id": "rhel-09.231180", "description": "REPLACE_ME", "props": [ @@ -8759,7 +8759,7 @@ ] }, { - "uuid": "cdcbf42a-7c62-44a0-b012-e97fdc270109", + "uuid": "c6d88221-6749-40ec-972b-fb8df5d53b1f", "control-id": "rhel-09.231185", "description": "REPLACE_ME", "props": [ @@ -8776,7 +8776,7 @@ ] }, { - "uuid": "4f4f0344-ff25-47eb-bf8a-762988194cbc", + "uuid": "b355f5be-3864-4b64-ac0e-f40a23fb293c", "control-id": "rhel-09.231200", "description": "REPLACE_ME", "props": [ @@ -8793,7 +8793,7 @@ ] }, { - "uuid": "560d2a63-0f0f-465e-8b41-50b8c6c974f2", + "uuid": "485a231f-01e9-4d59-b058-78a66508426c", "control-id": "rhel-09.232010", "description": "REPLACE_ME", "props": [ @@ -8810,7 +8810,7 @@ ] }, { - "uuid": "ceb05d0b-5322-4d05-ab13-2cd63aa47c41", + "uuid": "84f998f1-70e7-4dc5-a04d-74147ea3c8d6", "control-id": "rhel-09.232015", "description": "REPLACE_ME", "props": [ @@ -8827,7 +8827,7 @@ ] }, { - "uuid": "aa2dea95-4d79-46f1-8b5a-db393b671a40", + "uuid": "cce3ded9-8eb6-4c7e-b56a-48b3670d9f13", "control-id": "rhel-09.232020", "description": "REPLACE_ME", "props": [ @@ -8844,7 +8844,7 @@ ] }, { - "uuid": "aef5e0b6-5fed-4ef8-90a0-3a07ef8adaee", + "uuid": "c2ffff96-2c14-4347-9d47-b4708b3c0dee", "control-id": "rhel-09.232025", "description": "REPLACE_ME", "props": [ @@ -8861,7 +8861,7 @@ ] }, { - "uuid": "eff41b56-f5d3-41fb-a801-d41d4effa14a", + "uuid": "b5583133-8a1e-418e-90bc-58d4f3102b54", "control-id": "rhel-09.232030", "description": "REPLACE_ME", "props": [ @@ -8878,7 +8878,7 @@ ] }, { - "uuid": "249a6909-1076-4aad-8559-28f844ad1a43", + "uuid": "e74b738c-e13c-41fc-a319-ad34338991c5", "control-id": "rhel-09.232035", "description": "REPLACE_ME", "props": [ @@ -8895,7 +8895,7 @@ ] }, { - "uuid": "732615ef-15a5-4fc6-a9e1-9e036f5d3180", + "uuid": "530a9072-21e7-4c33-9bc8-23ba7d057dfd", "control-id": "rhel-09.232040", "description": "REPLACE_ME", "props": [ @@ -8937,7 +8937,7 @@ ] }, { - "uuid": "0f58c349-65ae-4139-ac16-ebdc3342da0a", + "uuid": "ceea7a4e-3bf6-45c5-bf9c-60a8cb0e1c5d", "control-id": "rhel-09.232045", "description": "REPLACE_ME", "props": [ @@ -8959,7 +8959,7 @@ ] }, { - "uuid": "9204e50c-07da-41d7-81dd-77ba52e1c04e", + "uuid": "7ed03b2f-8334-44fa-a7bc-2e3368180e92", "control-id": "rhel-09.232050", "description": "REPLACE_ME", "props": [ @@ -8976,7 +8976,7 @@ ] }, { - "uuid": "b085994a-1518-4f0f-a62f-98e84ad171e3", + "uuid": "9ae27597-1f79-45fc-b62a-a113267a5885", "control-id": "rhel-09.232055", "description": "REPLACE_ME", "props": [ @@ -8993,7 +8993,7 @@ ] }, { - "uuid": "317304ed-68f3-4c86-b955-5cc1abc03f7a", + "uuid": "66cbd445-d1e6-47b2-b58b-807c763adf31", "control-id": "rhel-09.232060", "description": "REPLACE_ME", "props": [ @@ -9010,7 +9010,7 @@ ] }, { - "uuid": "d1acbe1f-79eb-4f61-ba72-2b66da65246d", + "uuid": "2b3932c7-7069-47e4-b7f6-ddbf2003107f", "control-id": "rhel-09.232065", "description": "REPLACE_ME", "props": [ @@ -9027,7 +9027,7 @@ ] }, { - "uuid": "8994f6d2-708b-4396-be7a-d7df6cfc3324", + "uuid": "f02621e6-1d98-4353-8197-1c56e875d08c", "control-id": "rhel-09.232070", "description": "REPLACE_ME", "props": [ @@ -9044,7 +9044,7 @@ ] }, { - "uuid": "698c6a9e-80cf-41bb-b3c8-493a27e79f2b", + "uuid": "8557be76-273d-442a-8edd-6d7e50d809e7", "control-id": "rhel-09.232075", "description": "REPLACE_ME", "props": [ @@ -9061,7 +9061,7 @@ ] }, { - "uuid": "4bb76290-db15-48b2-8608-681293a8413f", + "uuid": "3c826df9-ab2c-48ca-9f29-e07d21869cf2", "control-id": "rhel-09.232080", "description": "REPLACE_ME", "props": [ @@ -9078,7 +9078,7 @@ ] }, { - "uuid": "0a560afe-30f9-47db-b03a-5fb9cff28b33", + "uuid": "13b7144b-2224-4095-a9d3-08b7ab391523", "control-id": "rhel-09.232085", "description": "REPLACE_ME", "props": [ @@ -9095,7 +9095,7 @@ ] }, { - "uuid": "77efd187-fb53-47a9-a03a-0c9840e561a3", + "uuid": "c9a199a5-de44-4b9d-83fd-44764e402031", "control-id": "rhel-09.232090", "description": "REPLACE_ME", "props": [ @@ -9112,7 +9112,7 @@ ] }, { - "uuid": "dac77e6e-d20c-42f6-94f1-0d38e84a2c57", + "uuid": "6269f9f8-c19a-47dd-8fb2-b39fba2a16de", "control-id": "rhel-09.232095", "description": "REPLACE_ME", "props": [ @@ -9129,7 +9129,7 @@ ] }, { - "uuid": "286a9c38-85d6-4053-a95a-cbe8002ba280", + "uuid": "3a7433be-1809-43ea-9f91-3eab59ff2898", "control-id": "rhel-09.232100", "description": "REPLACE_ME", "props": [ @@ -9147,7 +9147,7 @@ ] }, { - "uuid": "bc7423aa-eda4-4fe7-bc65-5baf71df24c8", + "uuid": "740cf1b6-75a7-404a-8b7d-a0ce52dddcb4", "control-id": "rhel-09.232103", "description": "REPLACE_ME", "props": [ @@ -9164,7 +9164,7 @@ ] }, { - "uuid": "da3936f3-4c63-43b2-a10f-5bcca5fb09b5", + "uuid": "043422f6-94a3-40df-9156-a85100aa4102", "control-id": "rhel-09.232104", "description": "REPLACE_ME", "props": [ @@ -9182,7 +9182,7 @@ ] }, { - "uuid": "b0115cfd-0a3c-40ee-a7e0-6672d74fb143", + "uuid": "2a3b532d-4d0f-4a64-8fc3-f7407707dd6e", "control-id": "rhel-09.232105", "description": "REPLACE_ME", "props": [ @@ -9199,7 +9199,7 @@ ] }, { - "uuid": "e9c1f91d-126c-4c8a-85c0-c0c8ec7c1756", + "uuid": "e4acd7e4-18ac-43bf-a79f-da2cd3877647", "control-id": "rhel-09.232110", "description": "REPLACE_ME", "props": [ @@ -9216,7 +9216,7 @@ ] }, { - "uuid": "61799530-c325-4877-bbfa-6898124f9587", + "uuid": "5f3040e1-09a1-4ce6-b689-15d8cc8e5cb5", "control-id": "rhel-09.232115", "description": "REPLACE_ME", "props": [ @@ -9233,7 +9233,7 @@ ] }, { - "uuid": "1a6c7665-4dfb-4271-af6c-1b119e7f52e6", + "uuid": "07f17301-2c04-4624-a532-84e55ab05cc6", "control-id": "rhel-09.232120", "description": "REPLACE_ME", "props": [ @@ -9250,7 +9250,7 @@ ] }, { - "uuid": "93bec90d-9c6d-437c-8169-cfb1c30f09d7", + "uuid": "f269be8e-7123-4c20-9c80-83fce6a2cf23", "control-id": "rhel-09.232125", "description": "REPLACE_ME", "props": [ @@ -9267,7 +9267,7 @@ ] }, { - "uuid": "e71174e7-e14a-4dde-9d83-2db4bba0d301", + "uuid": "45a25531-bbfa-4b9d-9122-ed882c97de3e", "control-id": "rhel-09.232130", "description": "REPLACE_ME", "props": [ @@ -9284,7 +9284,7 @@ ] }, { - "uuid": "b0fd518d-3ad3-4cc7-86a8-d2afb846e01f", + "uuid": "3f663d01-20f4-4e63-9001-ddc9fcdcce36", "control-id": "rhel-09.232135", "description": "REPLACE_ME", "props": [ @@ -9301,7 +9301,7 @@ ] }, { - "uuid": "ec82a958-9390-4038-bc9f-036d7cce2ee3", + "uuid": "0424dffe-48d6-4af3-a2b9-734cea20a8e9", "control-id": "rhel-09.232140", "description": "REPLACE_ME", "props": [ @@ -9318,7 +9318,7 @@ ] }, { - "uuid": "d97f3964-f382-4e2a-a0aa-ca3ba3066078", + "uuid": "0b31bba3-7415-42ec-9f8f-2f426426e820", "control-id": "rhel-09.232145", "description": "REPLACE_ME", "props": [ @@ -9335,7 +9335,7 @@ ] }, { - "uuid": "412c033a-3e5a-4412-b4fa-8443bb42cbdc", + "uuid": "d2106601-cec0-4999-b2f9-b2af5a64f978", "control-id": "rhel-09.232150", "description": "REPLACE_ME", "props": [ @@ -9352,7 +9352,7 @@ ] }, { - "uuid": "0417cf4e-3552-4120-bf31-8459a2044cb0", + "uuid": "e748852c-394b-44bf-a58f-22baa03397d1", "control-id": "rhel-09.232155", "description": "REPLACE_ME", "props": [ @@ -9369,7 +9369,7 @@ ] }, { - "uuid": "fc1f780f-e1bb-4d91-be47-84e3e09322a4", + "uuid": "34f8d4e8-faf4-42be-8a88-69961f39b2d2", "control-id": "rhel-09.232160", "description": "REPLACE_ME", "props": [ @@ -9386,7 +9386,7 @@ ] }, { - "uuid": "31ed3d34-f730-470e-86c6-052bf22eede9", + "uuid": "f31af1b7-729b-4eb0-b31b-b55d5a959cee", "control-id": "rhel-09.232165", "description": "REPLACE_ME", "props": [ @@ -9403,7 +9403,7 @@ ] }, { - "uuid": "49320b20-454f-4c19-85fe-588b970e81f3", + "uuid": "a4eb6459-a89e-4ef6-9a2f-6dfdfd9ce7e8", "control-id": "rhel-09.232170", "description": "REPLACE_ME", "props": [ @@ -9420,7 +9420,7 @@ ] }, { - "uuid": "d70cd166-38ba-4e42-afeb-6ecf46cc2af1", + "uuid": "72d977b4-97e1-4da7-a025-b36ff34ffad6", "control-id": "rhel-09.232175", "description": "REPLACE_ME", "props": [ @@ -9437,7 +9437,7 @@ ] }, { - "uuid": "445fd084-0cc4-4380-9b26-a0acec1362bb", + "uuid": "d50fbaad-eca9-446c-ade9-64cc4b7840ba", "control-id": "rhel-09.232180", "description": "REPLACE_ME", "props": [ @@ -9454,7 +9454,7 @@ ] }, { - "uuid": "5a729582-e1bd-415c-86db-ef67e00ebc5f", + "uuid": "804b483a-2cee-4f43-ae52-166068245b00", "control-id": "rhel-09.232185", "description": "REPLACE_ME", "props": [ @@ -9471,7 +9471,7 @@ ] }, { - "uuid": "589e133e-da4e-4d74-bcd5-b33478bd1770", + "uuid": "4d6d3f91-d16a-41ff-a9e6-df048d604a4b", "control-id": "rhel-09.232190", "description": "REPLACE_ME", "props": [ @@ -9488,7 +9488,7 @@ ] }, { - "uuid": "abd2ff11-8d89-4aa5-b28b-b8458ffde7fb", + "uuid": "b906f571-1dca-41e0-a0c8-dbc4bd2e9533", "control-id": "rhel-09.232195", "description": "REPLACE_ME", "props": [ @@ -9505,7 +9505,7 @@ ] }, { - "uuid": "9b0ec927-8cc4-4a37-b8af-c8981c8e09d2", + "uuid": "e7777f2e-9902-4aa9-8b3d-77e9e49af554", "control-id": "rhel-09.232200", "description": "REPLACE_ME", "props": [ @@ -9522,7 +9522,7 @@ ] }, { - "uuid": "19b51de8-b064-4928-bcc3-349249dc936a", + "uuid": "1c2e8d84-95ff-4904-aa4d-36c56accda7d", "control-id": "rhel-09.232205", "description": "REPLACE_ME", "props": [ @@ -9539,7 +9539,7 @@ ] }, { - "uuid": "c4902d57-db96-4318-bdad-e0ce2d5e1e31", + "uuid": "b2f6a602-b645-4930-b087-22eaa9a7f7a0", "control-id": "rhel-09.232210", "description": "REPLACE_ME", "props": [ @@ -9556,7 +9556,7 @@ ] }, { - "uuid": "c35f15b5-18c1-427c-b572-b7041a32afa3", + "uuid": "27c54cf9-d649-417f-8704-aeb0c693a0a6", "control-id": "rhel-09.232215", "description": "REPLACE_ME", "props": [ @@ -9573,7 +9573,7 @@ ] }, { - "uuid": "bbbca8f3-e880-45d0-85d7-45bbd260db91", + "uuid": "f27745ab-6e5f-4eeb-809c-d9509854bd5e", "control-id": "rhel-09.232220", "description": "REPLACE_ME", "props": [ @@ -9590,7 +9590,7 @@ ] }, { - "uuid": "23290438-3faa-4680-9742-b1c31767fce7", + "uuid": "a076a7ea-9c9a-4516-9534-b35ac691d343", "control-id": "rhel-09.232225", "description": "REPLACE_ME", "props": [ @@ -9607,7 +9607,7 @@ ] }, { - "uuid": "9e377318-087b-44df-afbf-950012a4b54a", + "uuid": "d0424343-b6da-4b5c-beb8-07d85ea2212c", "control-id": "rhel-09.232230", "description": "REPLACE_ME", "props": [ @@ -9654,7 +9654,7 @@ ] }, { - "uuid": "7a71e513-cc9d-4891-afd3-dbfe06f043dc", + "uuid": "9c6e8db9-696c-4db9-bc85-4ac27d9f6056", "control-id": "rhel-09.232235", "description": "REPLACE_ME", "props": [ @@ -9701,7 +9701,7 @@ ] }, { - "uuid": "10677499-68c1-4fba-8b02-7f338d045e89", + "uuid": "a726e571-9b58-4184-b76a-0900a6ce0a03", "control-id": "rhel-09.232240", "description": "REPLACE_ME", "props": [ @@ -9718,7 +9718,7 @@ ] }, { - "uuid": "4eed9927-dfec-4bf9-8eea-2cc415b91393", + "uuid": "a06136a5-d336-431b-ae22-79969461cbb3", "control-id": "rhel-09.232245", "description": "REPLACE_ME", "props": [ @@ -9735,7 +9735,7 @@ ] }, { - "uuid": "e5907c30-2ad5-4ee5-b1be-1a297ba9fe77", + "uuid": "61611bbe-bcc2-4780-8b15-44c334a74e6f", "control-id": "rhel-09.232250", "description": "REPLACE_ME", "props": [ @@ -9752,7 +9752,7 @@ ] }, { - "uuid": "f55b4275-54db-41b3-98ba-84db4a6748cd", + "uuid": "ea91326e-60e6-4297-a4e9-b5393c9b3403", "control-id": "rhel-09.232255", "description": "REPLACE_ME", "props": [ @@ -9769,7 +9769,7 @@ ] }, { - "uuid": "dcb0f1cf-1fbd-4158-b196-2e2423f0eefa", + "uuid": "2c612e90-f3d6-4c36-864a-742377595d9e", "control-id": "rhel-09.232260", "description": "REPLACE_ME", "props": [ @@ -9786,7 +9786,7 @@ ] }, { - "uuid": "b34bcde9-a010-4c32-b6ad-6b8cf8feec4c", + "uuid": "dcb73aae-0809-4ee7-887b-ae4215750fb9", "control-id": "rhel-09.232270", "description": "REPLACE_ME", "props": [ @@ -9803,7 +9803,7 @@ ] }, { - "uuid": "2ffd5901-95f9-441d-ab71-7f616a95bae0", + "uuid": "c4f1c5f5-99d4-425e-b4d8-04a30747c00f", "control-id": "rhel-09.251010", "description": "REPLACE_ME", "props": [ @@ -9820,7 +9820,7 @@ ] }, { - "uuid": "bc5cb02c-ddb7-431e-bdbc-a98b51e2797c", + "uuid": "c97d4817-b486-40e9-843f-01915e151fdb", "control-id": "rhel-09.251015", "description": "REPLACE_ME", "props": [ @@ -9837,7 +9837,7 @@ ] }, { - "uuid": "1f3eb3b6-7318-4fc0-97b0-1c1d4c1238f9", + "uuid": "e25c43e3-db51-42f6-9c56-58d0641635ea", "control-id": "rhel-09.251020", "description": "REPLACE_ME", "props": [ @@ -9854,7 +9854,7 @@ ] }, { - "uuid": "f917d9fc-38a7-4bc2-8466-33f351aaa382", + "uuid": "53cc0230-0fbf-48e0-966b-6ead91e5e43c", "control-id": "rhel-09.251030", "description": "REPLACE_ME", "props": [ @@ -9871,7 +9871,7 @@ ] }, { - "uuid": "1eaab03b-8de5-4580-8c32-491a2ff45aa2", + "uuid": "3e4efeca-6382-46d9-839d-bab58c7bb094", "control-id": "rhel-09.251035", "description": "REPLACE_ME", "props": [ @@ -9888,7 +9888,7 @@ ] }, { - "uuid": "8911f122-b295-4e71-81c9-48fb733a93a0", + "uuid": "5ff30560-c987-4257-bb57-ec6736a587a2", "control-id": "rhel-09.251040", "description": "REPLACE_ME", "props": [ @@ -9905,7 +9905,7 @@ ] }, { - "uuid": "81378a97-74f5-4d2b-8215-fec29cf65f08", + "uuid": "c48bf9e6-945a-4e96-9e6d-e8b8e1d88657", "control-id": "rhel-09.251045", "description": "REPLACE_ME", "props": [ @@ -9922,7 +9922,7 @@ ] }, { - "uuid": "ca849e2f-7d8b-49de-aa72-b9c0dd84ff88", + "uuid": "f6d45a49-fe81-41c9-b8bf-3744b23c1c75", "control-id": "rhel-09.252010", "description": "REPLACE_ME", "props": [ @@ -9939,7 +9939,7 @@ ] }, { - "uuid": "8a3620cc-7383-433c-9089-19af3409cfb7", + "uuid": "6d26519a-165d-4ed5-b75d-c2c45aa6da76", "control-id": "rhel-09.252015", "description": "REPLACE_ME", "props": [ @@ -9956,7 +9956,7 @@ ] }, { - "uuid": "fc10ad20-e13d-46f9-8716-a2037c8900d4", + "uuid": "27411cd2-9af3-4b1e-b95d-91da53da3e92", "control-id": "rhel-09.252020", "description": "REPLACE_ME", "props": [ @@ -9983,7 +9983,7 @@ ] }, { - "uuid": "19a0c94f-3252-43de-924b-bccb88af918f", + "uuid": "6c93e4a7-6a94-4de8-849c-862dd00fac9c", "control-id": "rhel-09.252035", "description": "REPLACE_ME", "props": [ @@ -10000,7 +10000,7 @@ ] }, { - "uuid": "c408c71e-0d27-4b29-85da-abae67da8824", + "uuid": "dc38cc71-b5c6-4d77-b799-6a5cb645b83f", "control-id": "rhel-09.252040", "description": "REPLACE_ME", "props": [ @@ -10017,7 +10017,7 @@ ] }, { - "uuid": "f2c95a3d-847b-490e-86f1-005999fa8e33", + "uuid": "1bb5ce75-fe49-4bfa-8a07-60c35fc431d6", "control-id": "rhel-09.252045", "description": "REPLACE_ME", "props": [ @@ -10034,7 +10034,7 @@ ] }, { - "uuid": "7207afff-a5d7-475e-9565-cb9712f2eeb1", + "uuid": "388f5e7f-305c-4dfe-ac39-21926fffaa7d", "control-id": "rhel-09.252050", "description": "REPLACE_ME", "props": [ @@ -10051,7 +10051,7 @@ ] }, { - "uuid": "1c7fc43c-8326-4c9d-bb2c-2d46a8e0ec62", + "uuid": "def6f630-b94f-4dfc-9929-9428c0770140", "control-id": "rhel-09.252060", "description": "REPLACE_ME", "props": [ @@ -10068,7 +10068,7 @@ ] }, { - "uuid": "24625982-1559-469d-b1cf-f906a840b5c2", + "uuid": "2bb354c5-0f3c-4bd3-aa2d-187c369858fd", "control-id": "rhel-09.252065", "description": "REPLACE_ME", "props": [ @@ -10085,7 +10085,7 @@ ] }, { - "uuid": "2b808ff5-4693-4ec0-9dbd-ce3cc577c290", + "uuid": "4f067b0d-8cd9-4740-b510-d160b18ff567", "control-id": "rhel-09.253010", "description": "REPLACE_ME", "props": [ @@ -10102,7 +10102,7 @@ ] }, { - "uuid": "2b67dfd6-e3b0-4320-bb9f-285fc0f364d8", + "uuid": "06965f8f-da48-4e2d-8069-dfd0015f4966", "control-id": "rhel-09.253015", "description": "REPLACE_ME", "props": [ @@ -10119,7 +10119,7 @@ ] }, { - "uuid": "7a4903ee-5acd-4642-a82f-e4bf188e6732", + "uuid": "91fe3c85-d5d8-4314-a2cd-0416a1367672", "control-id": "rhel-09.253020", "description": "REPLACE_ME", "props": [ @@ -10136,7 +10136,7 @@ ] }, { - "uuid": "75ff4849-6a26-43f3-a303-002c4808f58f", + "uuid": "554d8df7-4853-4c93-a85f-334b9b81b678", "control-id": "rhel-09.253025", "description": "REPLACE_ME", "props": [ @@ -10153,7 +10153,7 @@ ] }, { - "uuid": "d2ca6e61-aa11-4848-befc-1d2e03bce320", + "uuid": "b6b86409-37fa-4fb8-ba46-565b0401abf5", "control-id": "rhel-09.253030", "description": "REPLACE_ME", "props": [ @@ -10170,7 +10170,7 @@ ] }, { - "uuid": "ac8ad540-fed0-4166-ae9e-a09130666430", + "uuid": "49d9beb8-3e0d-4885-a96f-810dd2e52ab5", "control-id": "rhel-09.253035", "description": "REPLACE_ME", "props": [ @@ -10187,7 +10187,7 @@ ] }, { - "uuid": "121c54a0-684b-4148-bc74-a7df557c91f6", + "uuid": "5fd5fd75-a80c-4abd-b645-bc1638c65e9d", "control-id": "rhel-09.253040", "description": "REPLACE_ME", "props": [ @@ -10204,7 +10204,7 @@ ] }, { - "uuid": "6ae53be0-ab41-4b97-be78-b0da6d9d3b02", + "uuid": "4b433a0b-551f-402f-9deb-8851eb6b421a", "control-id": "rhel-09.253045", "description": "REPLACE_ME", "props": [ @@ -10221,7 +10221,7 @@ ] }, { - "uuid": "42c60d80-b0aa-4f25-b798-b92216fe6052", + "uuid": "7954c4d9-f71a-4f91-9615-ff6441e659cd", "control-id": "rhel-09.253050", "description": "REPLACE_ME", "props": [ @@ -10238,7 +10238,7 @@ ] }, { - "uuid": "5268d6f6-2f0b-43a6-825a-80aa52a79d97", + "uuid": "7a7c294c-4ff6-43cb-a196-19d22a6554f6", "control-id": "rhel-09.253055", "description": "REPLACE_ME", "props": [ @@ -10255,7 +10255,7 @@ ] }, { - "uuid": "41d365a0-c9b3-49d5-8e91-14b83e1b7b5c", + "uuid": "5de0c5be-2786-4746-912c-cc994426d55d", "control-id": "rhel-09.253060", "description": "REPLACE_ME", "props": [ @@ -10272,7 +10272,7 @@ ] }, { - "uuid": "e0b427b3-e66b-4c40-b8d3-0ad51fff2bd9", + "uuid": "28f70193-96c4-4891-9b03-01afc1ebce13", "control-id": "rhel-09.253065", "description": "REPLACE_ME", "props": [ @@ -10289,7 +10289,7 @@ ] }, { - "uuid": "47f16867-d9ff-400f-9e54-a361db120d1a", + "uuid": "83a6d89b-3f1d-4074-905d-8a4814ed4b62", "control-id": "rhel-09.253070", "description": "REPLACE_ME", "props": [ @@ -10306,7 +10306,7 @@ ] }, { - "uuid": "16b7f7e5-fd1c-4179-bf0f-c9411889b8ea", + "uuid": "7912d147-683c-48a4-9662-480833d35654", "control-id": "rhel-09.253075", "description": "REPLACE_ME", "props": [ @@ -10323,7 +10323,7 @@ ] }, { - "uuid": "306f9dbd-1131-4dc5-8626-6311f760b7a1", + "uuid": "a2aff44d-b9a3-4d0d-ab32-c6b80d3b78f2", "control-id": "rhel-09.254010", "description": "REPLACE_ME", "props": [ @@ -10340,7 +10340,7 @@ ] }, { - "uuid": "c8d55ac7-eb85-4fdf-9e0f-af1213d17638", + "uuid": "4de9f73f-99d2-4fa4-92ef-cb75e569da86", "control-id": "rhel-09.254015", "description": "REPLACE_ME", "props": [ @@ -10357,7 +10357,7 @@ ] }, { - "uuid": "bc7e1943-9ba3-49e9-9acd-ebd535c8e747", + "uuid": "57a84f11-5968-4889-96a0-1fb6fefc23bc", "control-id": "rhel-09.254020", "description": "REPLACE_ME", "props": [ @@ -10374,7 +10374,7 @@ ] }, { - "uuid": "3eccdb3f-a92f-40e9-be5e-824b6dbcb854", + "uuid": "ff1eb0e9-166f-4e23-a6c6-edfbc476d10f", "control-id": "rhel-09.254025", "description": "REPLACE_ME", "props": [ @@ -10391,7 +10391,7 @@ ] }, { - "uuid": "e06290a7-a056-462d-9677-b9522f694ad3", + "uuid": "5a78c65a-f012-481a-875a-ca65c1ff903a", "control-id": "rhel-09.254030", "description": "REPLACE_ME", "props": [ @@ -10408,7 +10408,7 @@ ] }, { - "uuid": "d10245f0-0a40-41f5-bef2-8b60750c17a7", + "uuid": "b96d5b5c-1d76-4cd6-b342-bbb1138c3041", "control-id": "rhel-09.254035", "description": "REPLACE_ME", "props": [ @@ -10425,7 +10425,7 @@ ] }, { - "uuid": "42cc156c-9f93-475e-9805-b7827afa9641", + "uuid": "d71a6bc9-ab4b-4b15-81c4-39b3043239d9", "control-id": "rhel-09.254040", "description": "REPLACE_ME", "props": [ @@ -10442,7 +10442,7 @@ ] }, { - "uuid": "e1a837ed-1013-4f63-95c0-7c4ccfcc3e2f", + "uuid": "15c81bf9-1655-4999-aadd-456ca12cc859", "control-id": "rhel-09.255010", "description": "REPLACE_ME", "props": [ @@ -10459,7 +10459,7 @@ ] }, { - "uuid": "2b4f661c-5531-40fa-bf9d-a1717d0d79c9", + "uuid": "305c967f-1d5c-4d39-adcf-a9e6f138a2bd", "control-id": "rhel-09.255015", "description": "REPLACE_ME", "props": [ @@ -10476,7 +10476,7 @@ ] }, { - "uuid": "f12e91fc-14ab-4f5d-ba06-72a12060280a", + "uuid": "d1edf395-a821-43da-8c19-b577ea83eb0f", "control-id": "rhel-09.255020", "description": "REPLACE_ME", "props": [ @@ -10493,7 +10493,7 @@ ] }, { - "uuid": "0bca3256-2591-4314-97e0-0f40f5b0bf9c", + "uuid": "25f07184-12dc-4c7d-9e76-1b68dddd62f1", "control-id": "rhel-09.255025", "description": "REPLACE_ME", "props": [ @@ -10510,7 +10510,7 @@ ] }, { - "uuid": "fb1262c2-f3c1-4c52-b4ea-3a128bc91cd5", + "uuid": "e833bf62-260c-4615-abcf-de96d0c5e9af", "control-id": "rhel-09.255030", "description": "REPLACE_ME", "props": [ @@ -10527,7 +10527,7 @@ ] }, { - "uuid": "6cf98a4a-3437-4aa6-a9b1-33f438f143bc", + "uuid": "1b97fbe5-16b8-42ec-8ff9-05486680300c", "control-id": "rhel-09.255035", "description": "REPLACE_ME", "props": [ @@ -10544,7 +10544,7 @@ ] }, { - "uuid": "1d769e9a-5454-4948-8031-00d32c0add28", + "uuid": "79552d49-ad45-4941-b27e-3eb33749db2a", "control-id": "rhel-09.255045", "description": "REPLACE_ME", "props": [ @@ -10561,7 +10561,7 @@ ] }, { - "uuid": "327c37e8-7067-493e-96eb-ddfb3d1cb4dd", + "uuid": "8924aea5-bc49-4540-b1d5-dfb61b6d1f19", "control-id": "rhel-09.255055", "description": "REPLACE_ME", "props": [ @@ -10583,7 +10583,7 @@ ] }, { - "uuid": "c9daea56-fc0e-4cec-ad94-c3e343b14307", + "uuid": "9170e6c1-37db-4173-b09f-235d74814bc2", "control-id": "rhel-09.255060", "description": "REPLACE_ME", "props": [ @@ -10600,7 +10600,7 @@ ] }, { - "uuid": "f6f058d3-6c2d-4a25-bfa8-c905761b4292", + "uuid": "ecab69de-2248-49d1-9406-ff95dccfff38", "control-id": "rhel-09.255064", "description": "REPLACE_ME", "props": [ @@ -10618,7 +10618,7 @@ ] }, { - "uuid": "cbfe6902-3e16-4821-aa8b-91d1e30f2205", + "uuid": "53d3e74e-bd55-4891-af8f-14dd37656c2b", "control-id": "rhel-09.255065", "description": "REPLACE_ME", "props": [ @@ -10635,7 +10635,7 @@ ] }, { - "uuid": "7eddd336-2d8b-4b72-bf3f-88d11fdf3aa3", + "uuid": "ebe2d772-047b-427e-bbdc-5a7c31a73387", "control-id": "rhel-09.255070", "description": "REPLACE_ME", "props": [ @@ -10653,7 +10653,7 @@ ] }, { - "uuid": "42d7dc3d-1638-4cf7-9831-b30f2f61fbb6", + "uuid": "fc642a94-be2e-48b7-ab3e-fee316224b5d", "control-id": "rhel-09.255075", "description": "REPLACE_ME", "props": [ @@ -10670,7 +10670,7 @@ ] }, { - "uuid": "c5b730de-f774-459e-96dc-81e228485f6c", + "uuid": "7193879a-d0aa-4af7-ad2f-46a3b5653934", "control-id": "rhel-09.255080", "description": "REPLACE_ME", "props": [ @@ -10687,7 +10687,7 @@ ] }, { - "uuid": "4d9b8596-81f7-4d87-a4f6-a121637e4be2", + "uuid": "6e17e184-f419-47cf-837d-410b863b9d67", "control-id": "rhel-09.255085", "description": "REPLACE_ME", "props": [ @@ -10704,7 +10704,7 @@ ] }, { - "uuid": "267833d5-355b-462d-9cbd-ad111ac67c3c", + "uuid": "8313fb6d-f0a0-42e3-95d7-3d1063a4ffaa", "control-id": "rhel-09.255090", "description": "REPLACE_ME", "props": [ @@ -10721,7 +10721,7 @@ ] }, { - "uuid": "883636ea-e8fd-4eca-ba0a-4f505624b3fc", + "uuid": "16c5d393-f0c9-410e-ae39-6b7f90095610", "control-id": "rhel-09.255095", "description": "REPLACE_ME", "props": [ @@ -10738,7 +10738,7 @@ ] }, { - "uuid": "57199b7d-f1b2-4b19-b855-97d2ad8a292e", + "uuid": "443f4f60-a6f0-4af6-9415-e60efa035e8d", "control-id": "rhel-09.255100", "description": "REPLACE_ME", "props": [ @@ -10755,7 +10755,7 @@ ] }, { - "uuid": "e723f3ca-a3d7-45dc-a8b7-c087c09e068d", + "uuid": "719a552e-9e73-405a-9d15-5fe8e3a26138", "control-id": "rhel-09.255105", "description": "REPLACE_ME", "props": [ @@ -10782,7 +10782,7 @@ ] }, { - "uuid": "3c0eaf9d-9a1b-4a7d-9cf4-75635a44bcf0", + "uuid": "ae88ea24-221d-45cf-bea0-613672797438", "control-id": "rhel-09.255110", "description": "REPLACE_ME", "props": [ @@ -10809,7 +10809,7 @@ ] }, { - "uuid": "3bc458af-287e-4c6e-bfa5-805f493c5b9a", + "uuid": "9e8920c1-5c94-4cc2-8bcc-652f7d6118e4", "control-id": "rhel-09.255115", "description": "REPLACE_ME", "props": [ @@ -10836,7 +10836,7 @@ ] }, { - "uuid": "0b5221a9-92f1-42fb-a5cc-d31658ffbebe", + "uuid": "d8b662a8-2576-42d0-9182-0fb01ea70978", "control-id": "rhel-09.255120", "description": "REPLACE_ME", "props": [ @@ -10853,7 +10853,7 @@ ] }, { - "uuid": "36b15ddb-8eef-4804-80ef-2e265dd096c8", + "uuid": "f8e7df6e-3949-40f5-9c7d-aecdbeae886a", "control-id": "rhel-09.255125", "description": "REPLACE_ME", "props": [ @@ -10870,7 +10870,7 @@ ] }, { - "uuid": "831258c7-b0b2-4415-b515-7f99d6108be4", + "uuid": "052f2b9e-a2c0-4c9d-bd69-6f2c8c1f5af2", "control-id": "rhel-09.255130", "description": "REPLACE_ME", "props": [ @@ -10887,7 +10887,7 @@ ] }, { - "uuid": "5e69c590-eed7-48ec-8e1b-21c4e71daa24", + "uuid": "9fa0d4b6-a615-4de4-9a7b-16df413d2dd3", "control-id": "rhel-09.255135", "description": "REPLACE_ME", "props": [ @@ -10904,7 +10904,7 @@ ] }, { - "uuid": "087339fb-4e14-4de0-a29f-d228cf84d80a", + "uuid": "71e2ac5d-0317-49e4-9df0-1c84e63db71c", "control-id": "rhel-09.255140", "description": "REPLACE_ME", "props": [ @@ -10921,7 +10921,7 @@ ] }, { - "uuid": "fa0b0752-3671-4955-a07e-4086e900cedd", + "uuid": "a1722eed-cd1f-4748-874c-3e7234afd031", "control-id": "rhel-09.255145", "description": "REPLACE_ME", "props": [ @@ -10938,7 +10938,7 @@ ] }, { - "uuid": "1b59fdfa-9ffe-433c-8d8f-fc1d25708fd8", + "uuid": "ee3c5e95-be74-458c-8032-b0cfaa69e615", "control-id": "rhel-09.255150", "description": "REPLACE_ME", "props": [ @@ -10955,7 +10955,7 @@ ] }, { - "uuid": "33c2bb3b-52ac-4064-87ea-1a90557f6f7c", + "uuid": "6ca36175-f329-4120-8052-01c96685a63c", "control-id": "rhel-09.255155", "description": "REPLACE_ME", "props": [ @@ -10972,7 +10972,7 @@ ] }, { - "uuid": "b6ee64a1-5f1f-448d-aed2-fa8e2f43c5ef", + "uuid": "465c9013-9c6a-4068-9192-56d893f0cee5", "control-id": "rhel-09.255160", "description": "REPLACE_ME", "props": [ @@ -10989,7 +10989,7 @@ ] }, { - "uuid": "fbf1cbb2-3ea8-4bc3-a421-fe73e538f322", + "uuid": "fc4f1818-593a-428a-99e4-e8c87161de3c", "control-id": "rhel-09.255165", "description": "REPLACE_ME", "props": [ @@ -11006,7 +11006,7 @@ ] }, { - "uuid": "2413b7f2-0be4-4790-b99f-325b845f65d0", + "uuid": "53941fc4-4ec4-41ec-8425-00e76efa2db7", "control-id": "rhel-09.255175", "description": "REPLACE_ME", "props": [ @@ -11023,7 +11023,7 @@ ] }, { - "uuid": "15932010-22c1-46be-9037-8287614816ab", + "uuid": "c73e73ca-88c5-41fa-90ef-35df4eb3d154", "control-id": "rhel-09.271010", "description": "REPLACE_ME", "props": [ @@ -11040,7 +11040,7 @@ ] }, { - "uuid": "efcefe27-65e2-4295-bc04-1bbb9c25e564", + "uuid": "6eacdac8-983c-4bf0-8dc5-c8c033277fb3", "control-id": "rhel-09.271015", "description": "REPLACE_ME", "props": [ @@ -11057,7 +11057,7 @@ ] }, { - "uuid": "883e3887-023e-43df-8c85-d04d5ca35102", + "uuid": "79084f68-d3c6-4a89-a2b2-c1ce11f3c644", "control-id": "rhel-09.271020", "description": "REPLACE_ME", "props": [ @@ -11074,7 +11074,7 @@ ] }, { - "uuid": "d5cccc52-a6c3-46c0-9bb8-6dc34dc7d8c5", + "uuid": "c1c26584-860e-4b33-8eeb-f8fe807bc76f", "control-id": "rhel-09.271025", "description": "REPLACE_ME", "props": [ @@ -11091,7 +11091,7 @@ ] }, { - "uuid": "728c6e7b-0847-4a72-9d42-64e0b693e6a8", + "uuid": "33433a30-71a5-4dfb-9187-da843e1d513f", "control-id": "rhel-09.271030", "description": "REPLACE_ME", "props": [ @@ -11108,7 +11108,7 @@ ] }, { - "uuid": "7c128037-25c8-4a19-b9d5-16d73d27c24a", + "uuid": "020873a5-d720-44fd-be0d-977abcdadc3e", "control-id": "rhel-09.271035", "description": "REPLACE_ME", "props": [ @@ -11125,7 +11125,7 @@ ] }, { - "uuid": "041a0bb7-da7f-4cf1-9b1a-94608fccd653", + "uuid": "bca70825-2360-458d-b156-4a4250e7f540", "control-id": "rhel-09.271045", "description": "REPLACE_ME", "props": [ @@ -11142,7 +11142,7 @@ ] }, { - "uuid": "1f4dd96f-c6aa-4e09-a35b-53d6a0e19dd9", + "uuid": "3518ecad-b4ab-4761-8f67-962f6c9fcd28", "control-id": "rhel-09.271050", "description": "REPLACE_ME", "props": [ @@ -11159,7 +11159,7 @@ ] }, { - "uuid": "38e76c25-89e5-4618-8a09-dd15b82e53af", + "uuid": "8496f270-fc53-4106-a369-f13ad6559827", "control-id": "rhel-09.271055", "description": "REPLACE_ME", "props": [ @@ -11176,7 +11176,7 @@ ] }, { - "uuid": "15706855-b438-4c0f-b935-4728b8cd5e22", + "uuid": "fbda1dd5-4734-45cc-a0f8-1d93e3a84ae8", "control-id": "rhel-09.271060", "description": "REPLACE_ME", "props": [ @@ -11193,7 +11193,7 @@ ] }, { - "uuid": "5d18dcc7-869e-42f6-9b71-bf96da371bd2", + "uuid": "3e78efc5-656e-44b3-a376-5399f6bb4883", "control-id": "rhel-09.271065", "description": "REPLACE_ME", "props": [ @@ -11210,7 +11210,7 @@ ] }, { - "uuid": "d32443f7-551f-4c8d-b979-a6f4893832f8", + "uuid": "5546cafb-0fc1-4d09-8d25-78d5ba40c084", "control-id": "rhel-09.271070", "description": "REPLACE_ME", "props": [ @@ -11227,7 +11227,7 @@ ] }, { - "uuid": "bf81c554-8a78-4f68-a436-905d36426164", + "uuid": "82c019da-4ab4-48f5-bcc9-df34b11d2cbc", "control-id": "rhel-09.271075", "description": "REPLACE_ME", "props": [ @@ -11244,7 +11244,7 @@ ] }, { - "uuid": "0697704b-251b-4e0f-835f-c4bdd8a97457", + "uuid": "ae7e78c3-6eb4-4d5f-91c7-85318b4d9e9e", "control-id": "rhel-09.271080", "description": "REPLACE_ME", "props": [ @@ -11261,7 +11261,7 @@ ] }, { - "uuid": "03f4fcd0-6254-4aba-8135-cdc8cfa487c9", + "uuid": "90c990ad-fad5-400f-bdcd-d26d5ad4c1d1", "control-id": "rhel-09.271085", "description": "REPLACE_ME", "props": [ @@ -11278,7 +11278,7 @@ ] }, { - "uuid": "acef3f85-1879-4be2-bd32-93a1e3b6e9c5", + "uuid": "f7aff3a3-f256-4eac-b909-ba8cda1455f3", "control-id": "rhel-09.271090", "description": "REPLACE_ME", "props": [ @@ -11295,7 +11295,7 @@ ] }, { - "uuid": "4521dcb6-4f95-4651-a34b-6ae1a6547a04", + "uuid": "78cfb561-4e1e-4127-a5bb-6526dbbaa738", "control-id": "rhel-09.271095", "description": "REPLACE_ME", "props": [ @@ -11312,7 +11312,7 @@ ] }, { - "uuid": "11858af2-ff24-4d8d-bea4-9586ea3745fa", + "uuid": "380f9a13-a0d4-4061-a691-316cb0829969", "control-id": "rhel-09.271100", "description": "REPLACE_ME", "props": [ @@ -11329,7 +11329,7 @@ ] }, { - "uuid": "80972d3c-a23d-4ab1-a797-85c61030b58a", + "uuid": "a967df63-a705-4808-b271-ef52e416793f", "control-id": "rhel-09.271105", "description": "REPLACE_ME", "props": [ @@ -11346,7 +11346,7 @@ ] }, { - "uuid": "2da192bc-d104-49b4-9c91-036111b9af81", + "uuid": "b19f5438-13a2-42d4-af2a-8ad01be5ddc6", "control-id": "rhel-09.271110", "description": "REPLACE_ME", "props": [ @@ -11363,7 +11363,7 @@ ] }, { - "uuid": "0b9922da-ac97-46a1-997f-5c9c90f73a0d", + "uuid": "a7e6f666-1b0e-4ec3-a699-813c20bd615b", "control-id": "rhel-09.271115", "description": "REPLACE_ME", "props": [ @@ -11380,7 +11380,7 @@ ] }, { - "uuid": "af1116c8-06a4-41ec-99d9-dcab90fd0644", + "uuid": "9a251856-e154-46a4-a4e2-2eb890b5399a", "control-id": "rhel-09.291010", "description": "REPLACE_ME", "props": [ @@ -11397,7 +11397,7 @@ ] }, { - "uuid": "0cf0e579-856b-4e6b-bd3a-7b31e4b50539", + "uuid": "6071df58-beea-4c1b-9cbb-edd5782ce47f", "control-id": "rhel-09.291015", "description": "REPLACE_ME", "props": [ @@ -11414,7 +11414,7 @@ ] }, { - "uuid": "c339a4a6-53ff-4c4d-ba7e-fe0949e23f8b", + "uuid": "7bce129e-60df-4550-886c-814cab1f981d", "control-id": "rhel-09.291020", "description": "REPLACE_ME", "props": [ @@ -11431,7 +11431,7 @@ ] }, { - "uuid": "6742614a-4c58-4a0b-b837-abc576fa4605", + "uuid": "c783b499-7453-4a76-8075-0b0dc1276ea1", "control-id": "rhel-09.291030", "description": "REPLACE_ME", "props": [ @@ -11448,7 +11448,7 @@ ] }, { - "uuid": "cd23f037-1cc2-4c13-902b-d7621bed9faa", + "uuid": "7b1ed88e-4f5a-4dfa-a5a9-6dd5abcc301c", "control-id": "rhel-09.291035", "description": "REPLACE_ME", "props": [ @@ -11465,7 +11465,7 @@ ] }, { - "uuid": "b401aeca-b387-4a90-bd16-53f65a2edc8c", + "uuid": "3f68077a-fae5-41e7-8cd2-446845bd6b7b", "control-id": "rhel-09.291040", "description": "REPLACE_ME", "props": [ @@ -11482,7 +11482,7 @@ ] }, { - "uuid": "0ce734d5-fc56-4a68-8aad-18e57c43489b", + "uuid": "04b4d59e-8103-4fec-94b4-13cc20216351", "control-id": "rhel-09.411010", "description": "REPLACE_ME", "props": [ @@ -11499,7 +11499,7 @@ ] }, { - "uuid": "e17c7734-ff72-4a2d-af60-9107f73d81a2", + "uuid": "b0fe6dc0-0c0f-497f-bbbb-0fbcd88fe9bc", "control-id": "rhel-09.411015", "description": "REPLACE_ME", "props": [ @@ -11516,7 +11516,7 @@ ] }, { - "uuid": "dedbf3a6-ccab-45a7-87d8-c1361b4c0544", + "uuid": "82b37136-7950-4f97-8b0a-8acc2f1fc1a6", "control-id": "rhel-09.411020", "description": "REPLACE_ME", "props": [ @@ -11533,7 +11533,7 @@ ] }, { - "uuid": "5a877800-23a0-4e77-bf99-42822d018797", + "uuid": "0ca3498e-0476-4d40-abf2-68bbb1d30ed7", "control-id": "rhel-09.411025", "description": "REPLACE_ME", "props": [ @@ -11550,7 +11550,7 @@ ] }, { - "uuid": "a599f047-8523-4d5e-8ff3-b3bae59da2ae", + "uuid": "7340acf8-6f67-46d9-95a8-c2071b9c9073", "control-id": "rhel-09.411030", "description": "REPLACE_ME", "props": [ @@ -11567,7 +11567,7 @@ ] }, { - "uuid": "3a1006c9-5080-4d91-a3fb-0961ddfadc1a", + "uuid": "df888838-da13-4a8e-9242-361c01dd7060", "control-id": "rhel-09.411035", "description": "REPLACE_ME", "props": [ @@ -11584,7 +11584,7 @@ ] }, { - "uuid": "bc265c3d-0e23-46fb-9a47-255aff03f962", + "uuid": "c7a254af-f604-441c-8360-a0d423f800e2", "control-id": "rhel-09.411040", "description": "REPLACE_ME", "props": [ @@ -11601,7 +11601,7 @@ ] }, { - "uuid": "d44cca49-9895-48fb-9fed-17fc91f0ce2b", + "uuid": "08d8e66c-591b-4aec-8881-f472e32d42d8", "control-id": "rhel-09.411045", "description": "REPLACE_ME", "props": [ @@ -11618,7 +11618,7 @@ ] }, { - "uuid": "3bbcfbf9-7e21-48ce-a475-68d6490068a1", + "uuid": "766a4ea2-ffef-47de-9ec9-67653786cde5", "control-id": "rhel-09.411050", "description": "REPLACE_ME", "props": [ @@ -11635,7 +11635,7 @@ ] }, { - "uuid": "54506d82-eee3-4598-87e7-7d62693cd231", + "uuid": "952ce7f3-8bcf-49ff-842f-cb0472162fb8", "control-id": "rhel-09.411055", "description": "REPLACE_ME", "props": [ @@ -11652,7 +11652,7 @@ ] }, { - "uuid": "190562af-a530-4e21-bfe7-2eff585af531", + "uuid": "35bedf6e-777a-4474-987b-c3421b30d47e", "control-id": "rhel-09.411060", "description": "REPLACE_ME", "props": [ @@ -11669,7 +11669,7 @@ ] }, { - "uuid": "5e108219-d7c6-4f39-bfda-3fa306ba94bc", + "uuid": "3640585c-997d-4207-9bf6-d9941a7d279c", "control-id": "rhel-09.411065", "description": "REPLACE_ME", "props": [ @@ -11686,7 +11686,7 @@ ] }, { - "uuid": "b07a635d-7404-4281-8b52-34233d46fdbc", + "uuid": "c13d7f54-7307-43c3-81ee-a22a29bc9671", "control-id": "rhel-09.411070", "description": "REPLACE_ME", "props": [ @@ -11703,7 +11703,7 @@ ] }, { - "uuid": "4edb5daa-78d3-4ec8-a1ce-51816e24e1a5", + "uuid": "7e4ce74e-61fd-4077-bd02-2f0e3221c8f3", "control-id": "rhel-09.411075", "description": "REPLACE_ME", "props": [ @@ -11720,7 +11720,7 @@ ] }, { - "uuid": "844c80f8-9aa0-4b3a-9899-48807228385b", + "uuid": "8bc852c9-d267-442b-ace4-8d277771321c", "control-id": "rhel-09.411080", "description": "REPLACE_ME", "props": [ @@ -11737,7 +11737,7 @@ ] }, { - "uuid": "e6cbab7c-08b4-4d30-80d9-55607783f19b", + "uuid": "948e9190-6fcb-4756-a111-4457f23332c0", "control-id": "rhel-09.411085", "description": "REPLACE_ME", "props": [ @@ -11754,7 +11754,7 @@ ] }, { - "uuid": "0b716377-7b5f-4f8f-b1d6-8231c532f257", + "uuid": "15fc8ec9-dad4-4f45-a47b-76a86f3d6839", "control-id": "rhel-09.411090", "description": "REPLACE_ME", "props": [ @@ -11771,7 +11771,7 @@ ] }, { - "uuid": "4225ffa2-548d-42ef-9f59-6c001d802a93", + "uuid": "82b2d507-0758-422e-9fa7-9edda5c34065", "control-id": "rhel-09.411095", "description": "REPLACE_ME", "props": [ @@ -11788,7 +11788,7 @@ ] }, { - "uuid": "b20b2006-f298-4cfc-981f-3df5b00fc813", + "uuid": "245f562b-4a1e-4b36-b8bc-b98eb4511432", "control-id": "rhel-09.411105", "description": "REPLACE_ME", "props": [ @@ -11805,7 +11805,7 @@ ] }, { - "uuid": "2625a9fb-606b-45ca-b519-26cc5e5b7461", + "uuid": "078fcf2c-a2bc-401a-bafc-5bd85f6144cb", "control-id": "rhel-09.411110", "description": "REPLACE_ME", "props": [ @@ -11822,7 +11822,7 @@ ] }, { - "uuid": "5fa722ec-3002-43de-a60f-c5960a0cc0b7", + "uuid": "a92849f2-65a6-4b72-af63-ad5f8832ac8f", "control-id": "rhel-09.411115", "description": "REPLACE_ME", "props": [ @@ -11839,7 +11839,7 @@ ] }, { - "uuid": "7dbabfcf-9b6d-4cb3-90fc-725333e125d2", + "uuid": "e9a79456-1eee-406d-948d-bc230e46234b", "control-id": "rhel-09.412035", "description": "REPLACE_ME", "props": [ @@ -11856,7 +11856,7 @@ ] }, { - "uuid": "6b6879cd-2af1-4241-9c28-f99599e3e6c1", + "uuid": "a6357f36-a3c2-408d-88c0-19bf5364977f", "control-id": "rhel-09.412045", "description": "REPLACE_ME", "props": [ @@ -11873,7 +11873,7 @@ ] }, { - "uuid": "a8cad8d1-0421-4a07-b8da-7755e7170425", + "uuid": "8480fa3a-9a9c-4de2-b0d4-88de7eb639ae", "control-id": "rhel-09.412050", "description": "REPLACE_ME", "props": [ @@ -11890,7 +11890,7 @@ ] }, { - "uuid": "145fbaf2-68a9-4ae6-af2c-c53bc578137e", + "uuid": "18de045f-95e6-4415-bba9-b70dd4678162", "control-id": "rhel-09.412055", "description": "REPLACE_ME", "props": [ @@ -11907,7 +11907,7 @@ ] }, { - "uuid": "b8b4ed80-4c65-4488-9848-9c65cc991280", + "uuid": "e0d64a13-b501-4785-b273-8dc4c9262d3a", "control-id": "rhel-09.412060", "description": "REPLACE_ME", "props": [ @@ -11924,7 +11924,7 @@ ] }, { - "uuid": "06970597-359d-4405-b8ae-a3340e3297cb", + "uuid": "4010b1e2-769b-4749-8119-ad5475666ace", "control-id": "rhel-09.412065", "description": "REPLACE_ME", "props": [ @@ -11941,7 +11941,7 @@ ] }, { - "uuid": "4a1879a5-3b05-4a14-8870-c5286100711c", + "uuid": "1c872e4e-6e58-4733-8c7b-d75627c8ae05", "control-id": "rhel-09.412070", "description": "REPLACE_ME", "props": [ @@ -11958,7 +11958,7 @@ ] }, { - "uuid": "00243d24-7504-4c57-aedb-ad104842026b", + "uuid": "5e53f027-1862-4c46-99d3-0f766afdfc9b", "control-id": "rhel-09.412080", "description": "REPLACE_ME", "props": [ @@ -11975,7 +11975,7 @@ ] }, { - "uuid": "cc6c5e3e-acba-4b72-ac8c-e9b5cfc4973e", + "uuid": "ee1c87fb-ddbd-496d-a829-ae0b373707c4", "control-id": "rhel-09.431015", "description": "REPLACE_ME", "props": [ @@ -11992,7 +11992,7 @@ ] }, { - "uuid": "bb1c7201-5234-4979-ac23-e560c726c0a0", + "uuid": "3e4770c7-88c1-4757-a123-d0a99173080c", "control-id": "rhel-09.431020", "description": "REPLACE_ME", "props": [ @@ -12009,7 +12009,7 @@ ] }, { - "uuid": "132e35b6-8919-4221-bb05-02f5264c9c10", + "uuid": "99c7b4ae-203a-400c-bd5c-f91c3f69b6e1", "control-id": "rhel-09.431025", "description": "REPLACE_ME", "props": [ @@ -12026,7 +12026,7 @@ ] }, { - "uuid": "d9e3f73a-17cd-445a-969e-208dceada646", + "uuid": "fe17a578-aab2-47b9-9b9f-a0c35eb9b165", "control-id": "rhel-09.431030", "description": "REPLACE_ME", "props": [ @@ -12043,7 +12043,7 @@ ] }, { - "uuid": "d0cca972-cfa4-4d98-aa62-750c4dfdecc5", + "uuid": "0e034dcf-04a8-417d-aadd-83dd7ed8f519", "control-id": "rhel-09.432010", "description": "REPLACE_ME", "props": [ @@ -12060,7 +12060,7 @@ ] }, { - "uuid": "78bd66b9-5dd6-4045-b758-ec1343681d63", + "uuid": "8911cf35-41fb-43ea-89bd-81134c5a9d5e", "control-id": "rhel-09.432015", "description": "REPLACE_ME", "props": [ @@ -12077,7 +12077,7 @@ ] }, { - "uuid": "ff10bf6b-57ac-4700-b5f6-4d1e87be593f", + "uuid": "1c4e880e-80d8-4d3b-b8a3-36737b616f7b", "control-id": "rhel-09.432020", "description": "REPLACE_ME", "props": [ @@ -12094,7 +12094,7 @@ ] }, { - "uuid": "ade13cbe-81ce-49dd-826e-37b7c40c9a1b", + "uuid": "84f47650-1400-4748-9a50-29d2afe3622b", "control-id": "rhel-09.432025", "description": "REPLACE_ME", "props": [ @@ -12111,7 +12111,7 @@ ] }, { - "uuid": "fb026184-a67e-425e-864a-106990af286c", + "uuid": "cfce4999-8fa9-4c81-98dd-6acf8d381414", "control-id": "rhel-09.432030", "description": "REPLACE_ME", "props": [ @@ -12128,7 +12128,7 @@ ] }, { - "uuid": "a7bd72b4-6670-4de8-bb18-c5a3a8aa86f1", + "uuid": "342dfcd0-58cc-48cf-b4f6-221e497212d9", "control-id": "rhel-09.432035", "description": "REPLACE_ME", "props": [ @@ -12145,7 +12145,7 @@ ] }, { - "uuid": "157f9566-2514-4e7a-9e01-97a3334344e7", + "uuid": "cf89ff70-854b-47cc-af8c-32bc39a33724", "control-id": "rhel-09.433010", "description": "REPLACE_ME", "props": [ @@ -12162,7 +12162,7 @@ ] }, { - "uuid": "065e9b93-adbc-40b0-890e-855cbdf0e5e6", + "uuid": "14f08a1b-c520-4099-ab3c-0a2232eec149", "control-id": "rhel-09.433015", "description": "REPLACE_ME", "props": [ @@ -12179,7 +12179,7 @@ ] }, { - "uuid": "f31b0ceb-d450-4a9a-b436-8765aaab6a5c", + "uuid": "11c3db08-6a33-4e59-84b1-3a79b03cc0e1", "control-id": "rhel-09.433016", "description": "REPLACE_ME", "props": [ @@ -12196,7 +12196,7 @@ ] }, { - "uuid": "33f77b6c-b0ef-4a57-9743-89d1c0b11492", + "uuid": "8e7e1bf8-78c3-449c-ae15-98d26e220391", "control-id": "rhel-09.611010", "description": "REPLACE_ME", "props": [ @@ -12213,7 +12213,7 @@ ] }, { - "uuid": "c5f34a15-03c4-4e05-99ff-e79deaadf190", + "uuid": "34821aa1-a6f6-4b67-a32a-3a9b56ad76eb", "control-id": "rhel-09.611030", "description": "REPLACE_ME", "props": [ @@ -12230,7 +12230,7 @@ ] }, { - "uuid": "52086e6a-b54c-4a9c-b482-ac4929d7eabd", + "uuid": "9ad316ab-6a6c-4d0f-906b-9d5b0e13aa96", "control-id": "rhel-09.611035", "description": "REPLACE_ME", "props": [ @@ -12247,7 +12247,7 @@ ] }, { - "uuid": "098e015b-0fc6-4996-b374-7dc99efef250", + "uuid": "5ba7b430-6565-4a84-b2ed-7722db2bd2e4", "control-id": "rhel-09.611040", "description": "REPLACE_ME", "props": [ @@ -12264,7 +12264,7 @@ ] }, { - "uuid": "c89f6dc5-a9d6-493d-8eb2-0dbea966b85a", + "uuid": "2d562464-5351-4170-bf70-f2cd27c8eba6", "control-id": "rhel-09.611045", "description": "REPLACE_ME", "props": [ @@ -12281,7 +12281,7 @@ ] }, { - "uuid": "a684bd12-8fbe-4bed-b15b-507aa1fa4e29", + "uuid": "165dfa43-36f7-4765-be3b-bf67c67853c5", "control-id": "rhel-09.611050", "description": "REPLACE_ME", "props": [ @@ -12298,7 +12298,7 @@ ] }, { - "uuid": "b19696a8-62c9-4944-8276-e8f13ba2a3f6", + "uuid": "abdd3006-c16f-4e2e-8b78-f621bbc7a719", "control-id": "rhel-09.611055", "description": "REPLACE_ME", "props": [ @@ -12315,7 +12315,7 @@ ] }, { - "uuid": "03e672c7-e2a9-4561-9625-44e675a07b25", + "uuid": "ab11a095-09f1-4a59-9fc7-20c3753371f2", "control-id": "rhel-09.611060", "description": "REPLACE_ME", "props": [ @@ -12332,7 +12332,7 @@ ] }, { - "uuid": "6c29b50f-b98e-4c0b-8331-7394ef87e93f", + "uuid": "0f6b2418-95e6-484d-9931-2043e0b44ae9", "control-id": "rhel-09.611065", "description": "REPLACE_ME", "props": [ @@ -12349,7 +12349,7 @@ ] }, { - "uuid": "36583f04-853f-49af-8ee0-d134ae785e18", + "uuid": "0cdf1e3d-a3ff-45a4-8b55-f1d0d9a84cbd", "control-id": "rhel-09.611070", "description": "REPLACE_ME", "props": [ @@ -12366,7 +12366,7 @@ ] }, { - "uuid": "57e72007-0b00-465a-9288-888fbf93e2d6", + "uuid": "69e119a7-a302-447a-9553-381bd90715ab", "control-id": "rhel-09.611075", "description": "REPLACE_ME", "props": [ @@ -12383,7 +12383,7 @@ ] }, { - "uuid": "a70cd7e0-6f19-49ba-b821-4ba07594beb3", + "uuid": "d072d5d1-1efe-4e36-b5b7-9c89aadb3b9b", "control-id": "rhel-09.611080", "description": "REPLACE_ME", "props": [ @@ -12400,7 +12400,7 @@ ] }, { - "uuid": "e3c920cb-cae9-4581-9ae9-e86a31c6aa4d", + "uuid": "da778037-d5b0-4aa1-be27-fb986c68f0e9", "control-id": "rhel-09.611085", "description": "REPLACE_ME", "props": [ @@ -12417,7 +12417,7 @@ ] }, { - "uuid": "18e1ff5d-7062-4067-bc30-3679e3b2ee8d", + "uuid": "6188f447-6718-4a7b-9519-08359e67b214", "control-id": "rhel-09.611090", "description": "REPLACE_ME", "props": [ @@ -12434,7 +12434,7 @@ ] }, { - "uuid": "3d0af4fa-14b7-49f3-98e7-e0ab4d83d5bc", + "uuid": "c1240cfb-01d8-4d1b-8257-dfed39e28885", "control-id": "rhel-09.611100", "description": "REPLACE_ME", "props": [ @@ -12451,7 +12451,7 @@ ] }, { - "uuid": "3cedfbcd-f657-4c49-9e9a-c0610551a308", + "uuid": "b9ee646f-96bf-47bc-bcb0-c38f4778fec5", "control-id": "rhel-09.611105", "description": "REPLACE_ME", "props": [ @@ -12468,7 +12468,7 @@ ] }, { - "uuid": "7acd1065-f52d-4662-9b2f-02b7ad1b1fb4", + "uuid": "c367c2a6-173f-4946-915e-759e9517a188", "control-id": "rhel-09.611110", "description": "REPLACE_ME", "props": [ @@ -12485,7 +12485,7 @@ ] }, { - "uuid": "1ef83b76-32d7-446c-a945-d5d31bc41679", + "uuid": "fc3426bd-99f6-41b1-9e5a-3d4b5e40dcdb", "control-id": "rhel-09.611115", "description": "REPLACE_ME", "props": [ @@ -12502,7 +12502,7 @@ ] }, { - "uuid": "ac2cc79a-814e-424b-ad6f-b4645eb540e7", + "uuid": "db7a720f-ff60-4728-8219-a568b63292c1", "control-id": "rhel-09.611120", "description": "REPLACE_ME", "props": [ @@ -12519,7 +12519,7 @@ ] }, { - "uuid": "5a092f16-fcf4-48fc-91f1-f5840f7b0001", + "uuid": "d28632a0-177a-47dd-a6ea-930ab35c4e6d", "control-id": "rhel-09.611125", "description": "REPLACE_ME", "props": [ @@ -12536,7 +12536,7 @@ ] }, { - "uuid": "fdd6d21b-380c-46aa-9fe9-af4b68ac60e5", + "uuid": "b13fc254-2448-430e-ac76-5f422443ff05", "control-id": "rhel-09.611130", "description": "REPLACE_ME", "props": [ @@ -12553,7 +12553,7 @@ ] }, { - "uuid": "a2ae3e24-b692-453d-b634-05d70ffff350", + "uuid": "c1f8be57-547f-4062-a57e-8283972b2fac", "control-id": "rhel-09.611135", "description": "REPLACE_ME", "props": [ @@ -12570,7 +12570,7 @@ ] }, { - "uuid": "b3a8adb5-e878-420f-87ff-1dacd1a9d85c", + "uuid": "d0f676f0-3eac-48e0-b75b-b6239adaccd9", "control-id": "rhel-09.611140", "description": "REPLACE_ME", "props": [ @@ -12587,7 +12587,7 @@ ] }, { - "uuid": "7009e185-dc4d-4170-b1d7-e308319c3068", + "uuid": "be86daac-b356-424a-94a6-a253d7780b02", "control-id": "rhel-09.611145", "description": "REPLACE_ME", "props": [ @@ -12604,7 +12604,7 @@ ] }, { - "uuid": "0da79ba4-64a8-4cf2-87b9-3fcbea94ed17", + "uuid": "e1162d68-2ecd-4b79-9e33-7c231008e1b8", "control-id": "rhel-09.611155", "description": "REPLACE_ME", "props": [ @@ -12621,7 +12621,7 @@ ] }, { - "uuid": "ec4f1433-6488-43c5-bd3d-665b007ee568", + "uuid": "f0525b65-94d5-45a6-ae29-805acd1d8b53", "control-id": "rhel-09.611160", "description": "REPLACE_ME", "props": [ @@ -12638,7 +12638,7 @@ ] }, { - "uuid": "d6a5f385-6df2-4021-b488-d81086fb8f30", + "uuid": "8635e05b-1106-4003-ae53-4084a7424ee3", "control-id": "rhel-09.611165", "description": "REPLACE_ME", "props": [ @@ -12655,7 +12655,7 @@ ] }, { - "uuid": "56aa8f0a-34f3-498d-83da-9c8e1e4de2b2", + "uuid": "c4c261cf-6dd4-4b53-ae06-8d34934761dd", "control-id": "rhel-09.611170", "description": "REPLACE_ME", "props": [ @@ -12672,7 +12672,7 @@ ] }, { - "uuid": "258c9434-a90c-43ab-862c-49d7f7aec2ad", + "uuid": "37345c7c-5c64-4bdd-86c8-544175fe6be9", "control-id": "rhel-09.611175", "description": "REPLACE_ME", "props": [ @@ -12689,7 +12689,7 @@ ] }, { - "uuid": "79541895-0511-494a-9287-3e2302898dbc", + "uuid": "e42464ae-29f2-444f-9c6c-3969b8472c31", "control-id": "rhel-09.611180", "description": "REPLACE_ME", "props": [ @@ -12706,7 +12706,7 @@ ] }, { - "uuid": "bfa54bd8-cc5a-40d6-8a5a-40968433c028", + "uuid": "24eeb248-03c6-4b49-9c80-21e23d40f114", "control-id": "rhel-09.611185", "description": "REPLACE_ME", "props": [ @@ -12723,7 +12723,7 @@ ] }, { - "uuid": "f021edff-e124-415f-becb-6caf7e089b32", + "uuid": "51f5df01-0ba0-4190-ac72-a9b6003769a2", "control-id": "rhel-09.611190", "description": "REPLACE_ME", "props": [ @@ -12740,7 +12740,7 @@ ] }, { - "uuid": "41e53fd9-be97-4f84-9116-cf16caf2794e", + "uuid": "12173481-f74d-498b-9f3d-e55f90fda024", "control-id": "rhel-09.611195", "description": "REPLACE_ME", "props": [ @@ -12757,7 +12757,7 @@ ] }, { - "uuid": "35c60b98-8bee-46d1-97cf-7b730e248059", + "uuid": "6bc51ed4-bd19-4eb6-83b4-7283df6ee3c2", "control-id": "rhel-09.611200", "description": "REPLACE_ME", "props": [ @@ -12774,7 +12774,7 @@ ] }, { - "uuid": "815f0bbd-20ec-421e-bc24-253e64553a3a", + "uuid": "902db94f-879d-4022-b4a7-0bbdcefc00ca", "control-id": "rhel-09.631010", "description": "REPLACE_ME", "props": [ @@ -12791,7 +12791,7 @@ ] }, { - "uuid": "332c668b-2cbf-40a4-9ab6-eb962c8d46e5", + "uuid": "022ad92c-4669-4c1a-9e83-8db2d559ecd7", "control-id": "rhel-09.631015", "description": "REPLACE_ME", "props": [ @@ -12808,7 +12808,7 @@ ] }, { - "uuid": "1307cde6-10f3-4128-8e07-fc1b702c6ea6", + "uuid": "0c19e9e2-0720-4827-bb5c-372111faa8df", "control-id": "rhel-09.631020", "description": "REPLACE_ME", "props": [ @@ -12825,7 +12825,7 @@ ] }, { - "uuid": "fcc68b68-ab6e-46c9-b909-7cc5028ecf4b", + "uuid": "ddb0d91d-fe0d-402d-ba85-5b5f9f95bc9b", "control-id": "rhel-09.651010", "description": "REPLACE_ME", "props": [ @@ -12847,7 +12847,7 @@ ] }, { - "uuid": "1da5165a-230a-4716-8e03-384b30333ef6", + "uuid": "13557c2b-adcd-4393-ab33-b4534164f5c0", "control-id": "rhel-09.651015", "description": "REPLACE_ME", "props": [ @@ -12869,7 +12869,7 @@ ] }, { - "uuid": "e19833eb-83d8-4aa0-ab72-c8f45a200078", + "uuid": "5e9bafe3-6db4-413b-b143-42349ed8464b", "control-id": "rhel-09.651020", "description": "REPLACE_ME", "props": [ @@ -12886,7 +12886,7 @@ ] }, { - "uuid": "4e6375cc-b95e-4c58-904f-f63742a3f3c1", + "uuid": "efeea79f-b529-4ef3-8a23-cc5af926c531", "control-id": "rhel-09.651025", "description": "REPLACE_ME", "props": [ @@ -12903,7 +12903,7 @@ ] }, { - "uuid": "d4c5b979-088d-4c2a-846b-4386dd7c40ca", + "uuid": "92d75039-79a6-4da3-b1c9-4583fe1829bb", "control-id": "rhel-09.652010", "description": "REPLACE_ME", "props": [ @@ -12920,7 +12920,7 @@ ] }, { - "uuid": "2d004917-aeeb-468d-9208-087a1f00b93a", + "uuid": "1ade679c-5e21-4f3a-9978-4006db898a84", "control-id": "rhel-09.652015", "description": "REPLACE_ME", "props": [ @@ -12937,7 +12937,7 @@ ] }, { - "uuid": "32ebf964-6df3-43b6-a377-145bdeff729b", + "uuid": "733d1125-2065-44bf-a7b6-5623a3d104c0", "control-id": "rhel-09.652020", "description": "REPLACE_ME", "props": [ @@ -12954,7 +12954,7 @@ ] }, { - "uuid": "ec7652fb-6486-4ce8-b82e-13ba6d973713", + "uuid": "a10ebb0e-f347-4fa6-b434-cb7bfd42f2fe", "control-id": "rhel-09.652025", "description": "REPLACE_ME", "props": [ @@ -12971,7 +12971,7 @@ ] }, { - "uuid": "d116d72c-f5e4-4f45-9486-f64843dbf672", + "uuid": "4ef678f4-ff07-44c3-ae9c-9c2a48710f01", "control-id": "rhel-09.652030", "description": "REPLACE_ME", "props": [ @@ -12988,7 +12988,7 @@ ] }, { - "uuid": "747fde1f-c0a1-44f3-985d-b5775428f649", + "uuid": "e8e59dfd-c47d-4b53-acf1-51f4a57e6783", "control-id": "rhel-09.652040", "description": "REPLACE_ME", "props": [ @@ -13005,7 +13005,7 @@ ] }, { - "uuid": "386bbcdb-14ba-4d53-a599-162ab7a368ae", + "uuid": "bc151edf-0915-4d71-bfd8-b94a94bb7679", "control-id": "rhel-09.652045", "description": "REPLACE_ME", "props": [ @@ -13022,7 +13022,7 @@ ] }, { - "uuid": "b3dcbf68-8791-41e6-a0be-9b5240bb6507", + "uuid": "d5d7f383-d8a4-4e3e-9591-f600df3f644f", "control-id": "rhel-09.652050", "description": "REPLACE_ME", "props": [ @@ -13039,7 +13039,7 @@ ] }, { - "uuid": "4c04893c-c643-42a6-9ee4-10abbe7ed724", + "uuid": "1c7a970e-429a-4fc0-bb7f-9f9684816c92", "control-id": "rhel-09.652055", "description": "REPLACE_ME", "props": [ @@ -13056,7 +13056,7 @@ ] }, { - "uuid": "45b41a1b-abc5-4155-9950-61d674183939", + "uuid": "9d975c5c-88cf-446a-ab09-109a0250c090", "control-id": "rhel-09.652060", "description": "REPLACE_ME", "props": [ @@ -13073,7 +13073,7 @@ ] }, { - "uuid": "ac0da413-c5a0-49e7-baa9-4e6099e65d92", + "uuid": "a5ca62cb-226e-414d-8e3e-1901916302bb", "control-id": "rhel-09.653010", "description": "REPLACE_ME", "props": [ @@ -13090,7 +13090,7 @@ ] }, { - "uuid": "1b9a4446-79bc-4a37-a38d-c2d24cdbc53f", + "uuid": "47abf957-4f20-42b6-9d50-218bebd1a237", "control-id": "rhel-09.653015", "description": "REPLACE_ME", "props": [ @@ -13107,7 +13107,7 @@ ] }, { - "uuid": "eece884c-a051-44dc-9439-76922636ed20", + "uuid": "3f905e87-8317-49d7-aa89-ed8c672cf239", "control-id": "rhel-09.653020", "description": "REPLACE_ME", "props": [ @@ -13124,7 +13124,7 @@ ] }, { - "uuid": "aac164e4-e39e-4f6d-8273-a6c65bca2b77", + "uuid": "ae9b47f1-798a-45c9-b59b-12e334076e8c", "control-id": "rhel-09.653025", "description": "REPLACE_ME", "props": [ @@ -13141,7 +13141,7 @@ ] }, { - "uuid": "55d9a4b0-602b-4834-a22e-0fc5ad7c866d", + "uuid": "442f1173-38f7-4435-afc0-b7b3735e426f", "control-id": "rhel-09.653030", "description": "REPLACE_ME", "props": [ @@ -13158,7 +13158,7 @@ ] }, { - "uuid": "c784ed7f-61e3-41ac-bf24-fcbe2ca75a31", + "uuid": "226b1e0f-2e71-4f96-9030-e1eb728f24ac", "control-id": "rhel-09.653035", "description": "REPLACE_ME", "props": [ @@ -13175,7 +13175,7 @@ ] }, { - "uuid": "2c95484a-1aba-432b-8080-d3f224462a72", + "uuid": "901d8bc3-d423-43a1-9ad7-d90f0f7dc8f2", "control-id": "rhel-09.653040", "description": "REPLACE_ME", "props": [ @@ -13192,7 +13192,7 @@ ] }, { - "uuid": "fe1d9c26-4388-4e6d-adae-a6b726edd391", + "uuid": "6e9a92f3-97cd-421f-a32e-b3e35ca3da20", "control-id": "rhel-09.653045", "description": "REPLACE_ME", "props": [ @@ -13209,7 +13209,7 @@ ] }, { - "uuid": "0e9b4419-c057-490e-8eb9-1a7eedba15d9", + "uuid": "ebaa36a3-32b4-48b8-acef-6ca6a284bd05", "control-id": "rhel-09.653050", "description": "REPLACE_ME", "props": [ @@ -13226,7 +13226,7 @@ ] }, { - "uuid": "f9193eba-5346-46b5-a2f8-af4fb0380f0e", + "uuid": "84413e98-a94e-4112-bd61-0c1f77931425", "control-id": "rhel-09.653055", "description": "REPLACE_ME", "props": [ @@ -13243,7 +13243,7 @@ ] }, { - "uuid": "d9dccf6e-e1fe-42a5-b2b8-3f886978d4c0", + "uuid": "316c2b4b-1449-404b-9d47-e8490dda1f07", "control-id": "rhel-09.653060", "description": "REPLACE_ME", "props": [ @@ -13260,7 +13260,7 @@ ] }, { - "uuid": "6bb4978a-9958-4441-8b3d-0e028db4749f", + "uuid": "68ce9ddf-a9ae-415f-acb8-44fd2abc33cf", "control-id": "rhel-09.653065", "description": "REPLACE_ME", "props": [ @@ -13277,7 +13277,7 @@ ] }, { - "uuid": "067156eb-4803-41d7-860a-687934ecd4f2", + "uuid": "e81a080b-571c-4594-93b1-91568a9a2d09", "control-id": "rhel-09.653070", "description": "REPLACE_ME", "props": [ @@ -13294,7 +13294,7 @@ ] }, { - "uuid": "d174f12f-37f7-47e9-8b9f-19d450849fd7", + "uuid": "f85f6b81-fd99-48cf-afa5-385e32812333", "control-id": "rhel-09.653075", "description": "REPLACE_ME", "props": [ @@ -13311,7 +13311,7 @@ ] }, { - "uuid": "b7fe9cd8-eba4-4b96-9a51-4cff2213b8b2", + "uuid": "b7e62251-2b29-4f12-8811-0c5f03ee099b", "control-id": "rhel-09.653080", "description": "REPLACE_ME", "props": [ @@ -13328,7 +13328,7 @@ ] }, { - "uuid": "0fef5ce8-b38a-4eb0-b231-8247295b0bc2", + "uuid": "4f111445-0165-4860-a09f-65c1ec403a76", "control-id": "rhel-09.653085", "description": "REPLACE_ME", "props": [ @@ -13345,7 +13345,7 @@ ] }, { - "uuid": "e134bb59-a24e-4448-bb4a-56b4b02374c0", + "uuid": "8d3437ca-cd69-4073-9b30-a2fae61ace01", "control-id": "rhel-09.653090", "description": "REPLACE_ME", "props": [ @@ -13362,7 +13362,7 @@ ] }, { - "uuid": "29b793b5-a407-46f5-98f8-db30bf2f60b7", + "uuid": "fc051437-8ac9-4a6a-8d5b-8bea915811f0", "control-id": "rhel-09.653095", "description": "REPLACE_ME", "props": [ @@ -13379,7 +13379,7 @@ ] }, { - "uuid": "88b17686-c1e2-4544-9a44-760776c859ab", + "uuid": "61cc1bfb-6db9-4d63-af35-e49dd75001b0", "control-id": "rhel-09.653100", "description": "REPLACE_ME", "props": [ @@ -13396,7 +13396,7 @@ ] }, { - "uuid": "5376eeb2-872b-4297-81ef-d44b22e4f1ca", + "uuid": "17fa40d4-65ff-4943-82ae-230154dc2ceb", "control-id": "rhel-09.653105", "description": "REPLACE_ME", "props": [ @@ -13413,7 +13413,7 @@ ] }, { - "uuid": "0a1beee3-7345-4b82-a6a7-4c284ab97cfa", + "uuid": "6fae5082-5c5c-491c-897e-932580df49ac", "control-id": "rhel-09.653110", "description": "REPLACE_ME", "props": [ @@ -13430,7 +13430,7 @@ ] }, { - "uuid": "5159be90-faa7-4f08-ba05-47e13a544cb7", + "uuid": "b3134d0c-b92a-4067-a723-6097523e53cd", "control-id": "rhel-09.653115", "description": "REPLACE_ME", "props": [ @@ -13447,7 +13447,7 @@ ] }, { - "uuid": "9cc99d0d-831a-4459-a2f4-3b76bb0b3521", + "uuid": "ee7a024e-9038-4b44-8e22-8eb07bc865fe", "control-id": "rhel-09.653125", "description": "REPLACE_ME", "props": [ @@ -13464,7 +13464,7 @@ ] }, { - "uuid": "19fa6259-92b3-4602-a96c-9801c806107f", + "uuid": "973e6bae-681f-4232-83dd-023893e664a2", "control-id": "rhel-09.653130", "description": "REPLACE_ME", "props": [ @@ -13481,7 +13481,7 @@ ] }, { - "uuid": "3a5e7d44-3bec-40dd-b25b-bc0167bf5f36", + "uuid": "247db9d6-87db-40c9-a23b-2acfa65df755", "control-id": "rhel-09.654010", "description": "REPLACE_ME", "props": [ @@ -13498,7 +13498,7 @@ ] }, { - "uuid": "9112e14f-5265-4eb6-961a-28b1336cfa22", + "uuid": "17882e85-3527-461b-9d33-7371e2b44236", "control-id": "rhel-09.654015", "description": "REPLACE_ME", "props": [ @@ -13525,7 +13525,7 @@ ] }, { - "uuid": "b2746267-f777-4518-b5c3-c7e09325c069", + "uuid": "017c25df-0fac-43ac-9ebf-087cb2f1d6ff", "control-id": "rhel-09.654020", "description": "REPLACE_ME", "props": [ @@ -13557,7 +13557,7 @@ ] }, { - "uuid": "33cf683e-c788-4bbb-a60c-766ddff9e079", + "uuid": "33b2fd69-140f-4499-9057-7c657108f7b7", "control-id": "rhel-09.654025", "description": "REPLACE_ME", "props": [ @@ -13599,7 +13599,7 @@ ] }, { - "uuid": "70f7164e-ed2e-4368-8d10-d4101138eb51", + "uuid": "5e616f14-6d46-45b6-a0bb-e2cad6e1c46b", "control-id": "rhel-09.654030", "description": "REPLACE_ME", "props": [ @@ -13616,7 +13616,7 @@ ] }, { - "uuid": "7b4a73f9-1834-46c2-9876-e41615aa0f82", + "uuid": "642bea0d-1f82-480c-b229-f0f43f1d3112", "control-id": "rhel-09.654035", "description": "REPLACE_ME", "props": [ @@ -13633,7 +13633,7 @@ ] }, { - "uuid": "666491a7-0410-4e5d-9090-b7fa20d98c9f", + "uuid": "c3a05321-94bf-43bb-a6ff-700fc58848fa", "control-id": "rhel-09.654040", "description": "REPLACE_ME", "props": [ @@ -13650,7 +13650,7 @@ ] }, { - "uuid": "eb3c8a1a-9677-4077-bb4c-0403af135a3f", + "uuid": "5b1f52ff-e619-426e-ae92-1d56cc7cf1ba", "control-id": "rhel-09.654045", "description": "REPLACE_ME", "props": [ @@ -13667,7 +13667,7 @@ ] }, { - "uuid": "7c1a5cd1-4826-4b9a-9efa-5a44bb5e1d67", + "uuid": "48e9c2c4-6587-4119-9d7a-9b81965021e9", "control-id": "rhel-09.654050", "description": "REPLACE_ME", "props": [ @@ -13684,7 +13684,7 @@ ] }, { - "uuid": "4dd9f054-c76f-4d5a-b945-08e731b8ca2d", + "uuid": "4edd7eb9-550e-4150-b3d3-1cc72300532b", "control-id": "rhel-09.654055", "description": "REPLACE_ME", "props": [ @@ -13701,7 +13701,7 @@ ] }, { - "uuid": "7afbe0a1-c0e7-4874-a1c6-fdd4d2ab9884", + "uuid": "4ccac1ed-3fb1-442a-b5a7-9724847aa175", "control-id": "rhel-09.654060", "description": "REPLACE_ME", "props": [ @@ -13718,7 +13718,7 @@ ] }, { - "uuid": "8b5eac8c-aa5f-4629-a564-ed5a9685d656", + "uuid": "ce15948d-b7bc-4ec2-a64b-61f47329bf45", "control-id": "rhel-09.654065", "description": "REPLACE_ME", "props": [ @@ -13755,7 +13755,7 @@ ] }, { - "uuid": "fa3d3387-90a3-42c5-b87f-7aeb2e7c4300", + "uuid": "dc010c58-a15d-4820-b755-71e587d3034a", "control-id": "rhel-09.654070", "description": "REPLACE_ME", "props": [ @@ -13797,7 +13797,7 @@ ] }, { - "uuid": "083def7c-f876-43c1-89c1-f574d212dcc7", + "uuid": "78a9ef29-6916-42db-87f8-f388a0c27121", "control-id": "rhel-09.654075", "description": "REPLACE_ME", "props": [ @@ -13814,7 +13814,7 @@ ] }, { - "uuid": "de8ae3ae-ac0f-463c-b65e-10f12f5ee592", + "uuid": "f4e36b77-d250-4edc-bfb9-83dd987314d3", "control-id": "rhel-09.654080", "description": "REPLACE_ME", "props": [ @@ -13836,7 +13836,7 @@ ] }, { - "uuid": "807d1abf-413c-42a4-a102-f8b89eaf4224", + "uuid": "11959804-9df7-4f00-ad49-f6df53f890bd", "control-id": "rhel-09.654085", "description": "REPLACE_ME", "props": [ @@ -13853,7 +13853,7 @@ ] }, { - "uuid": "bd64d6d9-ab6b-491d-9413-d5542af79e3d", + "uuid": "3c266bf2-f27b-4ee4-9220-29fa6ef30625", "control-id": "rhel-09.654090", "description": "REPLACE_ME", "props": [ @@ -13870,7 +13870,7 @@ ] }, { - "uuid": "a8eab42c-7fc2-485f-b7b8-657d0ab48701", + "uuid": "228bd62b-3dc1-4c49-96e2-0da56e78c70d", "control-id": "rhel-09.654095", "description": "REPLACE_ME", "props": [ @@ -13887,7 +13887,7 @@ ] }, { - "uuid": "c0d1a536-7ed0-4dc5-b946-8b69ff112ae8", + "uuid": "85079568-3a9e-46b9-b030-d59e7c7a59d0", "control-id": "rhel-09.654100", "description": "REPLACE_ME", "props": [ @@ -13904,7 +13904,7 @@ ] }, { - "uuid": "3afc228a-9e1d-486c-90c4-5d63597f12eb", + "uuid": "8d95decd-dc80-4e81-9a2b-fe002ba20df0", "control-id": "rhel-09.654105", "description": "REPLACE_ME", "props": [ @@ -13921,7 +13921,7 @@ ] }, { - "uuid": "5c81ef56-7681-496c-ac16-f38348fb616c", + "uuid": "27b92e3b-b830-4548-b779-dd11513254c9", "control-id": "rhel-09.654110", "description": "REPLACE_ME", "props": [ @@ -13938,7 +13938,7 @@ ] }, { - "uuid": "ccbd104a-daa9-4239-adea-ba9da354587e", + "uuid": "0f492ad7-e262-420a-8b94-fccc92e836c0", "control-id": "rhel-09.654115", "description": "REPLACE_ME", "props": [ @@ -13955,7 +13955,7 @@ ] }, { - "uuid": "610f9ed0-e0db-4997-8a1b-3b122b0efe10", + "uuid": "84f05c70-4cf8-4c02-a10b-cbb22cca2261", "control-id": "rhel-09.654120", "description": "REPLACE_ME", "props": [ @@ -13972,7 +13972,7 @@ ] }, { - "uuid": "ff2fcdd1-f03b-4403-915f-e52054dfa7b9", + "uuid": "8fb66abc-ac9b-4c9b-bc06-d126679d6124", "control-id": "rhel-09.654125", "description": "REPLACE_ME", "props": [ @@ -13989,7 +13989,7 @@ ] }, { - "uuid": "d0f1bfce-b006-4b3a-b121-a3cfeab61d75", + "uuid": "675c5439-98b4-4661-bdc6-4e537fc2bbc0", "control-id": "rhel-09.654130", "description": "REPLACE_ME", "props": [ @@ -14006,7 +14006,7 @@ ] }, { - "uuid": "e87a8fb3-eb65-472b-8b9f-c00cbf918f28", + "uuid": "a6d4ab2e-6e4c-4cf4-9e77-3157783e3e48", "control-id": "rhel-09.654135", "description": "REPLACE_ME", "props": [ @@ -14023,7 +14023,7 @@ ] }, { - "uuid": "88f87775-79b2-4a6a-a573-1fca4449b041", + "uuid": "9bb0c322-04ae-41f7-b346-2d1417a2711a", "control-id": "rhel-09.654140", "description": "REPLACE_ME", "props": [ @@ -14040,7 +14040,7 @@ ] }, { - "uuid": "21d56001-9768-4a24-9933-2cfbffc18bec", + "uuid": "88f47011-4ecc-48bd-aa42-89907354d08d", "control-id": "rhel-09.654145", "description": "REPLACE_ME", "props": [ @@ -14057,7 +14057,7 @@ ] }, { - "uuid": "65e036c8-f62c-44fa-b297-1d1aa016e21d", + "uuid": "25227f42-6f67-4492-81f6-69448b2cb3eb", "control-id": "rhel-09.654150", "description": "REPLACE_ME", "props": [ @@ -14074,7 +14074,7 @@ ] }, { - "uuid": "eef0c733-da6b-4720-8b71-2ed6aa5d3612", + "uuid": "121919d2-d014-400e-a41e-f4473ff2f7d3", "control-id": "rhel-09.654155", "description": "REPLACE_ME", "props": [ @@ -14091,7 +14091,7 @@ ] }, { - "uuid": "4a16dd55-0951-4711-9df5-efe5fb6936e1", + "uuid": "9ebe4c78-af67-44b1-a458-a92af98d69b5", "control-id": "rhel-09.654160", "description": "REPLACE_ME", "props": [ @@ -14108,7 +14108,7 @@ ] }, { - "uuid": "b28011dc-b891-464c-91ce-3249325f6440", + "uuid": "0d5c173e-ebd5-4a9f-904d-99127bfedfb3", "control-id": "rhel-09.654165", "description": "REPLACE_ME", "props": [ @@ -14125,7 +14125,7 @@ ] }, { - "uuid": "87c63070-d9bd-4226-bd9d-322f50218045", + "uuid": "3a750e1b-7e13-4c77-814e-cb8c8e37352a", "control-id": "rhel-09.654170", "description": "REPLACE_ME", "props": [ @@ -14142,7 +14142,7 @@ ] }, { - "uuid": "53f88388-ddb9-4230-9bb1-ace25b78ff0a", + "uuid": "5ef3bbe3-4f89-4a78-b913-66d5ca39c545", "control-id": "rhel-09.654175", "description": "REPLACE_ME", "props": [ @@ -14159,7 +14159,7 @@ ] }, { - "uuid": "98ba3209-e7ed-48ee-a5b3-d5f655d0e1af", + "uuid": "72402bad-7579-4774-b6c3-38b108542e16", "control-id": "rhel-09.654180", "description": "REPLACE_ME", "props": [ @@ -14176,7 +14176,7 @@ ] }, { - "uuid": "7435ad96-7d5f-4a4a-bd07-f1307f09cc71", + "uuid": "24b6f056-fb45-47d6-9962-d8cbfd89b197", "control-id": "rhel-09.654185", "description": "REPLACE_ME", "props": [ @@ -14193,7 +14193,7 @@ ] }, { - "uuid": "f4010bd0-475b-4666-9f5f-ab3409d88cd9", + "uuid": "eb3e6681-df53-48ca-87a9-ea6f1778d15a", "control-id": "rhel-09.654190", "description": "REPLACE_ME", "props": [ @@ -14210,7 +14210,7 @@ ] }, { - "uuid": "ed8e78ea-e65a-49d5-8f26-fa99ebdfe621", + "uuid": "455cffae-219b-4f98-adde-b1ffad666c14", "control-id": "rhel-09.654195", "description": "REPLACE_ME", "props": [ @@ -14227,7 +14227,7 @@ ] }, { - "uuid": "ef3300d9-57d4-45a0-b9e6-12ce4ef4b805", + "uuid": "030de55a-2d5f-457e-b698-f91d14941d9c", "control-id": "rhel-09.654200", "description": "REPLACE_ME", "props": [ @@ -14244,7 +14244,7 @@ ] }, { - "uuid": "9a7f12ef-3848-4d77-97f1-7dd1dd7c4959", + "uuid": "f19be36f-c175-40bf-9b18-c487ac4a6ad9", "control-id": "rhel-09.654205", "description": "REPLACE_ME", "props": [ @@ -14261,7 +14261,7 @@ ] }, { - "uuid": "88ec5b93-2a19-41e1-82cc-526257f5c5cb", + "uuid": "5a571f4a-da47-40b3-b2a3-4492ddbd9b76", "control-id": "rhel-09.654210", "description": "REPLACE_ME", "props": [ @@ -14278,7 +14278,7 @@ ] }, { - "uuid": "945c7abf-f720-4875-8c69-64d37266c889", + "uuid": "dac6759a-17c9-470b-a982-f2d43025d109", "control-id": "rhel-09.654215", "description": "REPLACE_ME", "props": [ @@ -14295,7 +14295,7 @@ ] }, { - "uuid": "5cfffa8c-3c6f-4dc5-a86c-3ec01f82c80b", + "uuid": "3b949dff-0f5e-4508-8f76-e6f0bbc40bdc", "control-id": "rhel-09.654220", "description": "REPLACE_ME", "props": [ @@ -14312,7 +14312,7 @@ ] }, { - "uuid": "37bb7f21-cc24-4e19-9723-57f093a5e7dd", + "uuid": "e775e94c-51a6-40f6-bd71-4d107d697e7e", "control-id": "rhel-09.654225", "description": "REPLACE_ME", "props": [ @@ -14329,7 +14329,7 @@ ] }, { - "uuid": "679952df-233b-499d-828c-ab65bc091a8e", + "uuid": "68c594ab-0bfd-4c68-90b7-1be3cb9039a3", "control-id": "rhel-09.654230", "description": "REPLACE_ME", "props": [ @@ -14346,7 +14346,7 @@ ] }, { - "uuid": "014b75dd-3a5e-4c77-8edb-6844a2621b59", + "uuid": "eb6af253-f7ce-41b4-8c12-34c80f0525a6", "control-id": "rhel-09.654235", "description": "REPLACE_ME", "props": [ @@ -14363,7 +14363,7 @@ ] }, { - "uuid": "23e9fd2c-fbe4-4e66-86a6-77d4384c3530", + "uuid": "21a8a78d-b92b-445d-a82e-767ec4c0ec43", "control-id": "rhel-09.654240", "description": "REPLACE_ME", "props": [ @@ -14380,7 +14380,7 @@ ] }, { - "uuid": "8607fcee-1dff-45b4-abea-acce52d71ffd", + "uuid": "1546bf06-3740-460e-a637-84fef023892b", "control-id": "rhel-09.654245", "description": "REPLACE_ME", "props": [ @@ -14397,7 +14397,7 @@ ] }, { - "uuid": "acc7c956-520f-47cd-ac70-d453d77a8e8d", + "uuid": "7ea3e130-eeda-43ae-b2e5-69d2fe1ff155", "control-id": "rhel-09.654250", "description": "REPLACE_ME", "props": [ @@ -14414,7 +14414,7 @@ ] }, { - "uuid": "7a78c5cb-d197-449f-8c64-4f180c832586", + "uuid": "29332f64-d5e7-4bc7-91c4-8353bf7d3524", "control-id": "rhel-09.654255", "description": "REPLACE_ME", "props": [ @@ -14431,7 +14431,7 @@ ] }, { - "uuid": "688b3abe-739d-4e38-b315-3538d6307d91", + "uuid": "1f1c4d56-6c89-470a-ba1d-9690766c3bdd", "control-id": "rhel-09.654260", "description": "REPLACE_ME", "props": [ @@ -14448,7 +14448,7 @@ ] }, { - "uuid": "e125d021-7108-48ab-b905-2e3baf84e598", + "uuid": "268a0c9f-a011-4eac-902a-b6708a62fe4f", "control-id": "rhel-09.654265", "description": "REPLACE_ME", "props": [ @@ -14465,7 +14465,7 @@ ] }, { - "uuid": "8e1c364f-af18-40c1-a231-118525683caf", + "uuid": "bdb2446c-b802-4220-8d4d-942a30f50f0f", "control-id": "rhel-09.654270", "description": "REPLACE_ME", "props": [ @@ -14477,7 +14477,7 @@ ] }, { - "uuid": "5af534af-ac64-4cf7-a061-36af4b2375f5", + "uuid": "2eb5ed61-7dd9-4579-acad-e64359011b03", "control-id": "rhel-09.654275", "description": "REPLACE_ME", "props": [ @@ -14494,7 +14494,7 @@ ] }, { - "uuid": "42b7a2e8-b1bd-49e0-8146-59aa73e73ec1", + "uuid": "f3cc0bcd-cf9b-43b9-9629-6fd99c4ac03c", "control-id": "rhel-09.671015", "description": "REPLACE_ME", "props": [ @@ -14511,7 +14511,7 @@ ] }, { - "uuid": "894b0e25-495f-4305-97ba-7c3230680bbb", + "uuid": "20b407d7-3afe-40fb-8290-5874e9efb9bc", "control-id": "rhel-09.671020", "description": "REPLACE_ME", "props": [ @@ -14528,7 +14528,7 @@ ] }, { - "uuid": "c33dd005-ac28-40d2-8a57-fdcf69552eb1", + "uuid": "975e7745-5221-4da4-97cb-e4f43003e2d8", "control-id": "rhel-09.671025", "description": "REPLACE_ME", "props": [ @@ -14545,7 +14545,7 @@ ] }, { - "uuid": "ac15bffe-2a74-45d2-9338-9eabf34eb7a9", + "uuid": "33a724e8-73dc-4ef4-bc22-967e836aa636", "control-id": "rhel-09.672020", "description": "REPLACE_ME", "props": [ @@ -14558,7 +14558,7 @@ ] }, { - "uuid": "98c0d0ba-a652-46ec-bfd7-ba28de6cb9f6", + "uuid": "ffd59ebc-ccd5-4410-82b0-9eb23e25b16e", "control-id": "rhel-09.672025", "description": "REPLACE_ME", "props": [ @@ -14575,7 +14575,7 @@ ] }, { - "uuid": "6f28df8a-94f1-4dc0-8294-042e2c263f96", + "uuid": "a15db7f2-0828-4978-b9fc-ef3aa1e92759", "control-id": "rhel-09.672050", "description": "REPLACE_ME", "props": [ @@ -14928,7 +14928,7 @@ { "name": "Parameter_Value_Alternatives_16", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt'}", + "value": "{'default': 'single', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'single|halt', 'cis_rhel9': 'single|halt', 'cis_rhel10': 'single|halt'}", "remarks": "rule_set_000" }, { @@ -14964,7 +14964,7 @@ { "name": "Parameter_Value_Alternatives_18", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'syslog|single|halt', 'cis_rhel10': 'syslog|single|halt', 'cis_ubuntu2404': 'syslog|single|halt', 'cis_debian12': 'syslog|single|halt'}", "remarks": "rule_set_000" }, { @@ -14982,7 +14982,7 @@ { "name": "Parameter_Value_Alternatives_19", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", + "value": "{'default': 'single', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'ignore': 'ignore', 'rotate': 'rotate', 'ol8': 'syslog|single|halt', 'rhel8': 'syslog|single|halt', 'cis_rhel8': 'syslog|single|halt', 'cis_rhel9': 'halt|single', 'cis_rhel10': 'halt|single', 'cis_ubuntu2404': 'halt|single', 'cis_debian12': 'halt|single'}", "remarks": "rule_set_000" }, { @@ -15054,7 +15054,7 @@ { "name": "Parameter_Value_Alternatives_23", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt'}", + "value": "{'default': 'email', 'email': 'email', 'exec': 'exec', 'halt': 'halt', 'single': 'single', 'suspend': 'suspend', 'syslog': 'syslog', 'rotate': 'rotate', 'ignore': 'ignore', 'cis_rhel8': 'email|exec|single|halt', 'cis_rhel9': 'email|exec|single|halt', 'cis_rhel10': 'email|exec|single|halt'}", "remarks": "rule_set_000" }, { @@ -15576,7 +15576,7 @@ { "name": "Parameter_Value_Alternatives_52", "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", - "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", + "value": "{'default': 'DEFAULT', 'default_policy': 'DEFAULT', 'default_nosha1': 'DEFAULT:NO-SHA1', 'fips': 'FIPS', 'fips_ospp': 'FIPS:OSPP', 'fips_stig': 'FIPS:STIG', 'legacy': 'LEGACY', 'future': 'FUTURE', 'next': 'NEXT'}", "remarks": "rule_set_000" }, { @@ -27426,7 +27426,7 @@ ], "control-implementations": [ { - "uuid": "2eba6e52-24c6-42cf-9bce-e210ead853cc", + "uuid": "6811f8f9-2ccb-460e-adc6-669404754f9c", "source": "trestle://profiles/rhel9-stig_rhel9-medium/profile.json", "description": "REPLACE_ME", "props": [ @@ -27752,7 +27752,7 @@ { "param-id": "var_system_crypto_policy", "values": [ - "fips" + "fips_stig" ] }, { @@ -27770,7 +27770,7 @@ ], "implemented-requirements": [ { - "uuid": "487777a5-a027-416b-93a8-a593a946d901", + "uuid": "e6a7faaf-ce47-42dc-8387-41387f9f4006", "control-id": "needed_rules", "description": "REPLACE_ME", "props": [ @@ -27788,7 +27788,7 @@ ] }, { - "uuid": "0fbf050e-77a3-447d-b321-9daf5a387ae4", + "uuid": "4f1cda79-af7a-4bfc-b6d8-a5f537d1ac38", "control-id": "rhel-09.171011", "description": "REPLACE_ME", "props": [ @@ -27806,7 +27806,7 @@ ] }, { - "uuid": "ca0874b2-9e12-48c6-af7c-b7ab21821e1d", + "uuid": "016bd9fb-7807-4b5a-8577-64148854a996", "control-id": "rhel-09.211015", "description": "REPLACE_ME", "props": [ @@ -27823,7 +27823,7 @@ ] }, { - "uuid": "c9e01360-e909-4fe2-9ca5-7274e75352ea", + "uuid": "33bc692b-1da2-420a-8f29-606e875e517f", "control-id": "rhel-09.211020", "description": "REPLACE_ME", "props": [ @@ -27840,7 +27840,7 @@ ] }, { - "uuid": "499b4aa0-b157-4b2a-95ed-7bad06278fee", + "uuid": "de9ee4c6-75e7-4598-9927-fce53062b098", "control-id": "rhel-09.211030", "description": "REPLACE_ME", "props": [ @@ -27857,7 +27857,7 @@ ] }, { - "uuid": "3c90ccd6-2115-4fc1-af2f-90bf2b7dc55a", + "uuid": "f7c6a4d5-7aeb-4db5-90af-dd11c17e9a05", "control-id": "rhel-09.211040", "description": "REPLACE_ME", "props": [ @@ -27874,7 +27874,7 @@ ] }, { - "uuid": "8cd56f18-15f8-4488-bf12-abae55031ee7", + "uuid": "3c1950b3-6c60-4ff5-af9d-0ab5819b4ff1", "control-id": "rhel-09.211055", "description": "REPLACE_ME", "props": [ @@ -27891,7 +27891,7 @@ ] }, { - "uuid": "4e90693e-4616-4784-8fac-7d2f088908a8", + "uuid": "423781c0-9521-4528-bb4c-ae28abf193fd", "control-id": "rhel-09.212010", "description": "REPLACE_ME", "props": [ @@ -27908,7 +27908,7 @@ ] }, { - "uuid": "f2bd1c2c-f881-4975-b638-2a63fd7377c8", + "uuid": "09994adf-c47d-48d2-b139-5f9a804bd488", "control-id": "rhel-09.212015", "description": "REPLACE_ME", "props": [ @@ -27925,7 +27925,7 @@ ] }, { - "uuid": "3289b59f-ef4c-4652-9396-06db53418137", + "uuid": "5728b37d-2c2a-42c0-8d01-392cca312595", "control-id": "rhel-09.212025", "description": "REPLACE_ME", "props": [ @@ -27942,7 +27942,7 @@ ] }, { - "uuid": "fa127752-e89d-4e50-8f7b-88ca23cc1246", + "uuid": "60c68888-263d-4f2b-9ba6-fa6c1a430ce6", "control-id": "rhel-09.212030", "description": "REPLACE_ME", "props": [ @@ -27959,7 +27959,7 @@ ] }, { - "uuid": "a60f845e-da6b-434f-a633-af4dd04528b8", + "uuid": "19e4878b-289c-4666-8290-af1de1de1d51", "control-id": "rhel-09.212035", "description": "REPLACE_ME", "props": [ @@ -27976,7 +27976,7 @@ ] }, { - "uuid": "20bef916-9ac5-4215-be59-15c756d37627", + "uuid": "16c1ace1-7c9e-4a29-96bd-b46b976788cd", "control-id": "rhel-09.212040", "description": "REPLACE_ME", "props": [ @@ -27993,7 +27993,7 @@ ] }, { - "uuid": "0b6f63c5-7c28-4d21-a123-a456b349d1b0", + "uuid": "0f575844-0c49-4d1f-a258-ecedc23ab029", "control-id": "rhel-09.212045", "description": "REPLACE_ME", "props": [ @@ -28010,7 +28010,7 @@ ] }, { - "uuid": "ef29d096-5bbc-4aa1-9aae-d9c2e9bbd862", + "uuid": "b6e84fef-3c6c-444a-860d-54d619a01a4d", "control-id": "rhel-09.213010", "description": "REPLACE_ME", "props": [ @@ -28027,7 +28027,7 @@ ] }, { - "uuid": "3ace266e-3425-41ab-a1bb-c8f1f8a7630a", + "uuid": "bf74a6c3-7cdb-429f-b9fd-66649ad180df", "control-id": "rhel-09.213015", "description": "REPLACE_ME", "props": [ @@ -28044,7 +28044,7 @@ ] }, { - "uuid": "b4a42bd4-6878-41cf-9173-e1397a13478f", + "uuid": "69200a06-add9-401b-bedc-16a91972c131", "control-id": "rhel-09.213020", "description": "REPLACE_ME", "props": [ @@ -28061,7 +28061,7 @@ ] }, { - "uuid": "5609dc66-6db7-44be-b854-5b9dc7372b21", + "uuid": "03b48938-5ecd-4394-91c7-e190f2e0539a", "control-id": "rhel-09.213025", "description": "REPLACE_ME", "props": [ @@ -28078,7 +28078,7 @@ ] }, { - "uuid": "201224fe-35a2-4f08-a615-5c96f2dabaa3", + "uuid": "76b8a509-cc04-49d5-8fde-7fe345fe798a", "control-id": "rhel-09.213030", "description": "REPLACE_ME", "props": [ @@ -28095,7 +28095,7 @@ ] }, { - "uuid": "3c6adb54-85d8-49ec-845c-d1712d389cba", + "uuid": "6a2fa837-2f6f-48a0-983e-45285c7c0eaf", "control-id": "rhel-09.213035", "description": "REPLACE_ME", "props": [ @@ -28112,7 +28112,7 @@ ] }, { - "uuid": "0e6e9495-8c9c-41ea-8223-adeda27655f3", + "uuid": "737ce019-fee0-47c4-b69f-463b5114ffaf", "control-id": "rhel-09.213040", "description": "REPLACE_ME", "props": [ @@ -28129,7 +28129,7 @@ ] }, { - "uuid": "eeb27a5d-3363-4d86-b111-30a1f4cc9c48", + "uuid": "029b4dda-7205-47c6-829b-09752fbee93d", "control-id": "rhel-09.213045", "description": "REPLACE_ME", "props": [ @@ -28146,7 +28146,7 @@ ] }, { - "uuid": "3c6fe5ef-4687-4738-98a0-077267f891f1", + "uuid": "42e740c2-b6e9-4821-a058-d3780d758f97", "control-id": "rhel-09.213050", "description": "REPLACE_ME", "props": [ @@ -28163,7 +28163,7 @@ ] }, { - "uuid": "6e30f684-9980-496b-bcf9-f858cd0b4bfc", + "uuid": "f4d41816-d7fc-44bb-bba1-a291c0d15849", "control-id": "rhel-09.213055", "description": "REPLACE_ME", "props": [ @@ -28180,7 +28180,7 @@ ] }, { - "uuid": "9282e25d-3643-474c-83b4-ab1bd4d141f4", + "uuid": "fbe0cdfd-a842-463b-9c2b-6e287430f7c5", "control-id": "rhel-09.213060", "description": "REPLACE_ME", "props": [ @@ -28197,7 +28197,7 @@ ] }, { - "uuid": "180e50d8-6c3b-4a6b-a77c-995e9b001fd6", + "uuid": "c79cecaf-4b8a-4469-8b98-e9ef0fa8af36", "control-id": "rhel-09.213065", "description": "REPLACE_ME", "props": [ @@ -28214,7 +28214,7 @@ ] }, { - "uuid": "ca86e6f8-42eb-4799-9f93-a194c6f507e3", + "uuid": "243f8a19-6213-4f34-b479-524d0dfe752c", "control-id": "rhel-09.213070", "description": "REPLACE_ME", "props": [ @@ -28231,7 +28231,7 @@ ] }, { - "uuid": "4e022bd9-ef0d-4951-b694-2d003557c63e", + "uuid": "bbea7d63-4f5d-4230-b8c3-44cbcb2bbc15", "control-id": "rhel-09.213075", "description": "REPLACE_ME", "props": [ @@ -28248,7 +28248,7 @@ ] }, { - "uuid": "78a610d7-6603-43f4-8ff3-8de5709a8df1", + "uuid": "d1dd79d4-41ba-4e93-a6ae-dc0301b54761", "control-id": "rhel-09.213080", "description": "REPLACE_ME", "props": [ @@ -28265,7 +28265,7 @@ ] }, { - "uuid": "bd27f629-6b22-4d21-9bed-263f4f124134", + "uuid": "8a01988a-95a3-4884-8f78-d1049819a37f", "control-id": "rhel-09.213085", "description": "REPLACE_ME", "props": [ @@ -28282,7 +28282,7 @@ ] }, { - "uuid": "173ad002-2c11-45ec-8a06-005a65d9dd7c", + "uuid": "97046465-04a7-4f98-9877-b67181cc2a88", "control-id": "rhel-09.213090", "description": "REPLACE_ME", "props": [ @@ -28299,7 +28299,7 @@ ] }, { - "uuid": "a1d14c1a-9117-439b-b759-9d6d17e49030", + "uuid": "d303cd9c-fff8-4356-b158-a0ecbadfa202", "control-id": "rhel-09.213095", "description": "REPLACE_ME", "props": [ @@ -28316,7 +28316,7 @@ ] }, { - "uuid": "accfac83-1ee8-4b11-8085-0e9f660b9f96", + "uuid": "8a08c543-0a7d-4911-94b0-528e163b54cb", "control-id": "rhel-09.213100", "description": "REPLACE_ME", "props": [ @@ -28333,7 +28333,7 @@ ] }, { - "uuid": "9c7dbe32-285a-42b4-960b-12de6ca37940", + "uuid": "16647801-9a4b-4bb7-8301-07ef1b558f40", "control-id": "rhel-09.213105", "description": "REPLACE_ME", "props": [ @@ -28350,7 +28350,7 @@ ] }, { - "uuid": "e4c5b491-0cc7-4b79-956f-a442e6b3ff70", + "uuid": "4c776b1e-abfe-40ca-8524-493137d8a2b1", "control-id": "rhel-09.213110", "description": "REPLACE_ME", "props": [ @@ -28367,7 +28367,7 @@ ] }, { - "uuid": "9a83bd55-797f-45ee-ac14-aa8c37c0a795", + "uuid": "3aa646bf-b704-475a-a5d7-8462167d51b4", "control-id": "rhel-09.213115", "description": "REPLACE_ME", "props": [ @@ -28384,7 +28384,7 @@ ] }, { - "uuid": "968f7477-6642-40cd-b146-33d984bfe917", + "uuid": "1c896e0e-1d56-429b-8e1a-790d6a23a607", "control-id": "rhel-09.214010", "description": "REPLACE_ME", "props": [ @@ -28401,7 +28401,7 @@ ] }, { - "uuid": "f99b559b-67ea-4a5c-91d7-897b8416ebaf", + "uuid": "5a0791b9-b04d-4af4-9e5f-4caad32c37de", "control-id": "rhel-09.214030", "description": "REPLACE_ME", "props": [ @@ -28414,7 +28414,7 @@ ] }, { - "uuid": "05ba222d-c871-412c-80f6-d78edb0f54b3", + "uuid": "dc1231fb-0d59-4a61-913f-8026ea7397b5", "control-id": "rhel-09.215010", "description": "REPLACE_ME", "props": [ @@ -28431,7 +28431,7 @@ ] }, { - "uuid": "56a92262-7a09-4fcd-b6d0-940413f73b78", + "uuid": "6244fd7d-bd3e-4dea-b658-8f5f632202ea", "control-id": "rhel-09.215020", "description": "REPLACE_ME", "props": [ @@ -28448,7 +28448,7 @@ ] }, { - "uuid": "fa06be2d-5886-48c5-a0a9-eff0015fc595", + "uuid": "83ee6c22-662f-422a-9626-b4f447169d23", "control-id": "rhel-09.215025", "description": "REPLACE_ME", "props": [ @@ -28465,7 +28465,7 @@ ] }, { - "uuid": "337bd2ca-dc32-4128-b79f-5c5c47654186", + "uuid": "534d8c35-f001-4739-b2ff-2e67f6f44feb", "control-id": "rhel-09.215030", "description": "REPLACE_ME", "props": [ @@ -28478,7 +28478,7 @@ ] }, { - "uuid": "020997c3-862a-4d3e-af16-86434871ab7a", + "uuid": "6b39652a-f8ee-471a-ac47-0476574f91ce", "control-id": "rhel-09.215035", "description": "REPLACE_ME", "props": [ @@ -28491,7 +28491,7 @@ ] }, { - "uuid": "8460482e-4b90-4de7-9f48-be7e4c3d550d", + "uuid": "f21dc65e-a408-487b-8849-b906477e1ec0", "control-id": "rhel-09.215040", "description": "REPLACE_ME", "props": [ @@ -28508,7 +28508,7 @@ ] }, { - "uuid": "b2a6f99f-7e65-468d-8b45-bed21ecabd09", + "uuid": "db71c5d7-10c3-445d-a4d4-52b0023fb4a2", "control-id": "rhel-09.215045", "description": "REPLACE_ME", "props": [ @@ -28525,7 +28525,7 @@ ] }, { - "uuid": "3661134c-bf13-49fa-b208-7f41f2d16a6a", + "uuid": "3f2210d2-681a-4f5c-96a0-db18bad03e82", "control-id": "rhel-09.215050", "description": "REPLACE_ME", "props": [ @@ -28542,7 +28542,7 @@ ] }, { - "uuid": "a27bba00-0f90-4729-a612-6a24df47da78", + "uuid": "dd7ed1c1-a713-4b92-9f8d-e5c62bc6da76", "control-id": "rhel-09.215055", "description": "REPLACE_ME", "props": [ @@ -28559,7 +28559,7 @@ ] }, { - "uuid": "aa34c919-6523-4513-84be-748d8a570049", + "uuid": "a814c892-f7e7-4935-93c3-ae55a5e3df37", "control-id": "rhel-09.215065", "description": "REPLACE_ME", "props": [ @@ -28572,7 +28572,7 @@ ] }, { - "uuid": "c5f4b0df-a90b-4b52-9569-1b18fb4010cb", + "uuid": "32d800b6-aaf0-4760-8468-957792dc80d5", "control-id": "rhel-09.215070", "description": "REPLACE_ME", "props": [ @@ -28589,7 +28589,7 @@ ] }, { - "uuid": "77970eb9-5f91-46d5-be52-5c5efeeb3916", + "uuid": "a394bfb1-d5ec-4f95-8316-6707bbe82a9b", "control-id": "rhel-09.215075", "description": "REPLACE_ME", "props": [ @@ -28606,7 +28606,7 @@ ] }, { - "uuid": "0743e569-d9db-4b5c-a72b-9862abf9f40c", + "uuid": "a9ff234c-0f64-4a12-a96c-0e4d98cdf4d9", "control-id": "rhel-09.215080", "description": "REPLACE_ME", "props": [ @@ -28623,7 +28623,7 @@ ] }, { - "uuid": "f4c665c0-5418-457d-89a7-9c1b0a9774a7", + "uuid": "dd96783f-fcac-4bb9-af53-0541c901581d", "control-id": "rhel-09.215085", "description": "REPLACE_ME", "props": [ @@ -28640,7 +28640,7 @@ ] }, { - "uuid": "8093f3b3-5f7d-421e-b013-1ac683108e48", + "uuid": "91da7717-7d99-4f7f-8c68-ffab655ac196", "control-id": "rhel-09.215090", "description": "REPLACE_ME", "props": [ @@ -28657,7 +28657,7 @@ ] }, { - "uuid": "bdde816c-5866-40b2-9e75-3d304b9d45ac", + "uuid": "25d5a751-49e9-4b5e-8fdf-a7356291ebd2", "control-id": "rhel-09.215095", "description": "REPLACE_ME", "props": [ @@ -28674,7 +28674,7 @@ ] }, { - "uuid": "9b331e28-fcd7-47cf-9b4a-ace5e1c6a00b", + "uuid": "16292510-9581-4087-9365-9dc11951f21f", "control-id": "rhel-09.215100", "description": "REPLACE_ME", "props": [ @@ -28691,7 +28691,7 @@ ] }, { - "uuid": "922805cf-5f73-4a10-842b-94db85280dd3", + "uuid": "f0cc7495-138e-499e-84a7-ce92b97478f0", "control-id": "rhel-09.215101", "description": "REPLACE_ME", "props": [ @@ -28708,7 +28708,7 @@ ] }, { - "uuid": "50dbb0ea-85ca-4382-b9ff-8917f3463ddd", + "uuid": "8a2e9d91-c5cf-4373-9e3b-0d74a229a363", "control-id": "rhel-09.215105", "description": "REPLACE_ME", "props": [ @@ -28735,7 +28735,7 @@ ] }, { - "uuid": "6e36f41d-5e7e-4eea-b3a7-6955892f9265", + "uuid": "eb506500-b765-4e75-a51c-de5f14691ccc", "control-id": "rhel-09.231010", "description": "REPLACE_ME", "props": [ @@ -28752,7 +28752,7 @@ ] }, { - "uuid": "40694760-8f3f-47bb-9356-4652893ae3e7", + "uuid": "e1e23dc1-f97a-4238-916c-4acbaecd3c44", "control-id": "rhel-09.231015", "description": "REPLACE_ME", "props": [ @@ -28769,7 +28769,7 @@ ] }, { - "uuid": "539b7452-de94-483d-a50d-c5c1a379ab08", + "uuid": "72414eed-8a09-45a4-959b-4e12f8cf697e", "control-id": "rhel-09.231035", "description": "REPLACE_ME", "props": [ @@ -28786,7 +28786,7 @@ ] }, { - "uuid": "2dc66fe6-f16e-47a0-9c58-722d9390d3d2", + "uuid": "a47d6878-0afe-4ed4-84bd-027650a69d40", "control-id": "rhel-09.231040", "description": "REPLACE_ME", "props": [ @@ -28803,7 +28803,7 @@ ] }, { - "uuid": "93db4d6f-fd13-49e0-a57f-d89cd845d64f", + "uuid": "556cf637-1c99-475f-8b8a-f7235d066fb1", "control-id": "rhel-09.231045", "description": "REPLACE_ME", "props": [ @@ -28820,7 +28820,7 @@ ] }, { - "uuid": "c420299e-45a2-4dff-9f7d-cc9767422ab5", + "uuid": "457df9c2-f95b-42ec-8f9e-fef4d0375552", "control-id": "rhel-09.231050", "description": "REPLACE_ME", "props": [ @@ -28837,7 +28837,7 @@ ] }, { - "uuid": "6badd0db-676b-4604-8d5b-5e7629d03c0a", + "uuid": "69b9391c-64c7-4448-8799-3412c58d8c2f", "control-id": "rhel-09.231055", "description": "REPLACE_ME", "props": [ @@ -28854,7 +28854,7 @@ ] }, { - "uuid": "2372edae-9443-41a5-8100-b004d94e9b71", + "uuid": "9d78c524-fa5c-45c6-bcc4-c2677c48d056", "control-id": "rhel-09.231065", "description": "REPLACE_ME", "props": [ @@ -28871,7 +28871,7 @@ ] }, { - "uuid": "8f177cfc-ac08-4613-b8a8-5fdc4f2147bd", + "uuid": "c0714fe2-595b-40a0-8c3d-9131961a3eb2", "control-id": "rhel-09.231070", "description": "REPLACE_ME", "props": [ @@ -28888,7 +28888,7 @@ ] }, { - "uuid": "94436853-b5df-4409-b3e1-d287de6500dc", + "uuid": "f8ffadc6-1c3b-4a1c-9fb6-6589b6ab9311", "control-id": "rhel-09.231075", "description": "REPLACE_ME", "props": [ @@ -28905,7 +28905,7 @@ ] }, { - "uuid": "167017b6-4780-4319-bef9-a95b5e048bd1", + "uuid": "8b76705c-8bd8-4f3b-8d2e-5e7098c649fc", "control-id": "rhel-09.231080", "description": "REPLACE_ME", "props": [ @@ -28922,7 +28922,7 @@ ] }, { - "uuid": "eaadbae3-2f89-4e68-9086-82ce1da638b5", + "uuid": "b5217867-217f-4000-aa10-ab71142a58e4", "control-id": "rhel-09.231085", "description": "REPLACE_ME", "props": [ @@ -28939,7 +28939,7 @@ ] }, { - "uuid": "c469476a-84a7-4ecf-8734-fb94e12ebbc8", + "uuid": "15614716-a238-49d2-8909-0774b58c218d", "control-id": "rhel-09.231090", "description": "REPLACE_ME", "props": [ @@ -28956,7 +28956,7 @@ ] }, { - "uuid": "3a38c151-a7ff-4b35-b6df-830a6b69fe2d", + "uuid": "e390885d-ce16-4d58-a5a5-15aa4ab55ba9", "control-id": "rhel-09.231095", "description": "REPLACE_ME", "props": [ @@ -28973,7 +28973,7 @@ ] }, { - "uuid": "1b987242-cb18-48f9-9c44-442659ab7530", + "uuid": "2cd0dfb2-dcaf-4224-986b-5bba466a9210", "control-id": "rhel-09.231100", "description": "REPLACE_ME", "props": [ @@ -28990,7 +28990,7 @@ ] }, { - "uuid": "4baa55bb-6613-46fc-8e6e-dadf8bd4d0a2", + "uuid": "81a1a08a-e9d1-4462-b3d6-cb4116891e0a", "control-id": "rhel-09.231105", "description": "REPLACE_ME", "props": [ @@ -29007,7 +29007,7 @@ ] }, { - "uuid": "6aa2effc-d187-4926-93e0-19b5e8d95530", + "uuid": "021e580c-ecf4-4db0-b9b9-48a50c9883a0", "control-id": "rhel-09.231110", "description": "REPLACE_ME", "props": [ @@ -29024,7 +29024,7 @@ ] }, { - "uuid": "70ee586f-b4a2-4b26-83d1-8fe67ceaa594", + "uuid": "e12f1b1e-292d-42b3-836d-8929f42642de", "control-id": "rhel-09.231115", "description": "REPLACE_ME", "props": [ @@ -29041,7 +29041,7 @@ ] }, { - "uuid": "4ea4ea3b-aa3d-40f5-8fab-be1495e1b493", + "uuid": "4f4f1670-6d36-4e19-a965-4cd37e4f805d", "control-id": "rhel-09.231120", "description": "REPLACE_ME", "props": [ @@ -29058,7 +29058,7 @@ ] }, { - "uuid": "115da00c-64c2-4e7d-a515-54321c2f6c91", + "uuid": "f0654903-3876-4a9a-8bc9-77c23defb72d", "control-id": "rhel-09.231125", "description": "REPLACE_ME", "props": [ @@ -29075,7 +29075,7 @@ ] }, { - "uuid": "f14b97e7-3978-425a-8f4f-655424938ffa", + "uuid": "77f8474e-44ce-4d91-8a42-c6144c6df681", "control-id": "rhel-09.231130", "description": "REPLACE_ME", "props": [ @@ -29092,7 +29092,7 @@ ] }, { - "uuid": "8c9445a5-7b90-4bff-b4df-78e72efaff31", + "uuid": "c2fd08fe-6ed3-4baf-a1a3-b08cd007eefa", "control-id": "rhel-09.231135", "description": "REPLACE_ME", "props": [ @@ -29109,7 +29109,7 @@ ] }, { - "uuid": "da09c029-3a17-4083-95ae-5451e503c2a3", + "uuid": "814e7b11-98c4-4c27-8995-85bdb34e954e", "control-id": "rhel-09.231140", "description": "REPLACE_ME", "props": [ @@ -29126,7 +29126,7 @@ ] }, { - "uuid": "00d48d29-f25f-4600-9870-d0853c040b3a", + "uuid": "d1864028-5ec2-464a-b89c-0e10851f09da", "control-id": "rhel-09.231145", "description": "REPLACE_ME", "props": [ @@ -29143,7 +29143,7 @@ ] }, { - "uuid": "54492768-82f4-4698-b917-2773d0c38f3e", + "uuid": "4557c9d2-90da-4d35-a810-0758f368e876", "control-id": "rhel-09.231150", "description": "REPLACE_ME", "props": [ @@ -29160,7 +29160,7 @@ ] }, { - "uuid": "d059f60c-831e-4a3c-a509-30d42bfc4a70", + "uuid": "eed60c9c-4b51-42e6-a566-76040152f31c", "control-id": "rhel-09.231155", "description": "REPLACE_ME", "props": [ @@ -29177,7 +29177,7 @@ ] }, { - "uuid": "ebfdacfd-44d7-4ac9-94c7-310c0866e617", + "uuid": "6102e029-e484-4c6f-a7a7-df7259627a28", "control-id": "rhel-09.231160", "description": "REPLACE_ME", "props": [ @@ -29194,7 +29194,7 @@ ] }, { - "uuid": "101ef382-08a9-453c-a31d-2f9c9443d46b", + "uuid": "c0253e21-c09f-4d49-85b5-d7812ada6457", "control-id": "rhel-09.231165", "description": "REPLACE_ME", "props": [ @@ -29211,7 +29211,7 @@ ] }, { - "uuid": "d8806052-bea9-4949-8208-546034b84e01", + "uuid": "e20c2030-32de-4d4a-9968-01e2bffb342d", "control-id": "rhel-09.231170", "description": "REPLACE_ME", "props": [ @@ -29228,7 +29228,7 @@ ] }, { - "uuid": "f6a0c450-10d7-4d95-a9ad-b355303e7fe5", + "uuid": "1e3d2ee5-7b76-4a33-b3fc-b45fe9cda7fb", "control-id": "rhel-09.231175", "description": "REPLACE_ME", "props": [ @@ -29245,7 +29245,7 @@ ] }, { - "uuid": "271b5a1c-eca7-47dc-9df0-fcac5a91b088", + "uuid": "14875da1-412b-41f0-83ff-d97e956db88c", "control-id": "rhel-09.231180", "description": "REPLACE_ME", "props": [ @@ -29262,7 +29262,7 @@ ] }, { - "uuid": "e62014b7-d18a-4196-987c-ee8cd3713568", + "uuid": "486662fd-493d-41ff-a409-0780fc08e60d", "control-id": "rhel-09.231185", "description": "REPLACE_ME", "props": [ @@ -29279,7 +29279,7 @@ ] }, { - "uuid": "a57d3259-9655-495e-9cf2-54949d7ee915", + "uuid": "72b66a61-1228-4d52-a7b6-e6234d9b2cf2", "control-id": "rhel-09.231200", "description": "REPLACE_ME", "props": [ @@ -29296,7 +29296,7 @@ ] }, { - "uuid": "38a6358c-8622-4288-83c2-ca0cf3556fcb", + "uuid": "d2637120-d552-47b1-a044-fdaeec140744", "control-id": "rhel-09.232010", "description": "REPLACE_ME", "props": [ @@ -29313,7 +29313,7 @@ ] }, { - "uuid": "70c979ad-6ba3-42fe-85e4-f87772e741fd", + "uuid": "49102077-cafa-4886-b291-c53b5092deaf", "control-id": "rhel-09.232015", "description": "REPLACE_ME", "props": [ @@ -29330,7 +29330,7 @@ ] }, { - "uuid": "518c0737-973f-47bd-8bc9-68bdf9aac5b3", + "uuid": "8ee2c670-29f7-4ea2-90c1-413a2edcc161", "control-id": "rhel-09.232020", "description": "REPLACE_ME", "props": [ @@ -29347,7 +29347,7 @@ ] }, { - "uuid": "4d2771cd-8c27-497b-aadb-cb1715ff0284", + "uuid": "387914ec-e297-4ffc-9748-68fe25774d9e", "control-id": "rhel-09.232025", "description": "REPLACE_ME", "props": [ @@ -29364,7 +29364,7 @@ ] }, { - "uuid": "a264ffe8-06fb-46a9-9fd6-da4388f6228b", + "uuid": "8c46413c-0996-4753-b418-92b5dde2f187", "control-id": "rhel-09.232030", "description": "REPLACE_ME", "props": [ @@ -29381,7 +29381,7 @@ ] }, { - "uuid": "eac16b6c-6702-476b-b4d2-31019e4242a0", + "uuid": "3d88d77a-5b05-423a-9d10-a85c846855d4", "control-id": "rhel-09.232035", "description": "REPLACE_ME", "props": [ @@ -29398,7 +29398,7 @@ ] }, { - "uuid": "9a115f5a-912e-4bde-b81c-85ad68922b90", + "uuid": "6682e1d5-c7cb-4c66-8c12-42eea339f1b9", "control-id": "rhel-09.232040", "description": "REPLACE_ME", "props": [ @@ -29440,7 +29440,7 @@ ] }, { - "uuid": "cc07ca1a-7e70-46f6-b8d8-8661058f68f0", + "uuid": "6e6ef818-40ea-4ccd-beac-a59781f42cf5", "control-id": "rhel-09.232045", "description": "REPLACE_ME", "props": [ @@ -29462,7 +29462,7 @@ ] }, { - "uuid": "06c16890-e11a-4a3d-b258-6332a022808d", + "uuid": "3e3f73d1-30bc-4865-86e7-3caff80513b8", "control-id": "rhel-09.232050", "description": "REPLACE_ME", "props": [ @@ -29479,7 +29479,7 @@ ] }, { - "uuid": "d10f9247-925b-42b7-ba49-3aed4e29f2b6", + "uuid": "bfb89d7b-a2b8-4ef7-955e-55ac60c5ecee", "control-id": "rhel-09.232055", "description": "REPLACE_ME", "props": [ @@ -29496,7 +29496,7 @@ ] }, { - "uuid": "2bba69d8-a086-46b5-afad-b8d2e05b8d62", + "uuid": "b0a525a5-505f-4a47-bbb6-baf2b2344c89", "control-id": "rhel-09.232060", "description": "REPLACE_ME", "props": [ @@ -29513,7 +29513,7 @@ ] }, { - "uuid": "37b81f19-7621-4963-8f4d-63129c0d7b60", + "uuid": "0903d9a7-2805-4b3d-8fdf-59ec0a9868ab", "control-id": "rhel-09.232065", "description": "REPLACE_ME", "props": [ @@ -29530,7 +29530,7 @@ ] }, { - "uuid": "9c71c206-1c6b-402c-90a5-57a302e6d7fb", + "uuid": "fa4abcca-2ea4-45f3-8a42-b22a3d625a3b", "control-id": "rhel-09.232070", "description": "REPLACE_ME", "props": [ @@ -29547,7 +29547,7 @@ ] }, { - "uuid": "843d7de6-fcab-4a45-8db3-2404a122252e", + "uuid": "98acdfd5-aa91-46f5-9dda-a5b553bdc878", "control-id": "rhel-09.232075", "description": "REPLACE_ME", "props": [ @@ -29564,7 +29564,7 @@ ] }, { - "uuid": "513be45f-2429-4778-9ecd-49c2954d6868", + "uuid": "fcc1be35-14aa-4ff8-a7b8-8900f01520f3", "control-id": "rhel-09.232080", "description": "REPLACE_ME", "props": [ @@ -29581,7 +29581,7 @@ ] }, { - "uuid": "e9577fd1-9ca4-4ed1-aa41-3eab891674db", + "uuid": "f9233626-36a4-474b-a2bf-f3f923a4904a", "control-id": "rhel-09.232085", "description": "REPLACE_ME", "props": [ @@ -29598,7 +29598,7 @@ ] }, { - "uuid": "c6c2c912-c835-4f7f-8715-d7ead6e235d0", + "uuid": "9b24597e-cc30-4a83-b916-e8ab6c2af8e6", "control-id": "rhel-09.232090", "description": "REPLACE_ME", "props": [ @@ -29615,7 +29615,7 @@ ] }, { - "uuid": "73da9aac-8762-4beb-a645-daa5f4ce9751", + "uuid": "8c202ac7-bd6a-4a60-a928-961b082c50df", "control-id": "rhel-09.232095", "description": "REPLACE_ME", "props": [ @@ -29632,7 +29632,7 @@ ] }, { - "uuid": "c43f93c4-6cce-4c6d-8fc4-9fb541e34e34", + "uuid": "1f4dfa79-bf78-4a79-bcf0-2abf2a2c64d6", "control-id": "rhel-09.232100", "description": "REPLACE_ME", "props": [ @@ -29650,7 +29650,7 @@ ] }, { - "uuid": "da5b5490-1a98-41fc-b94d-eb23026552a0", + "uuid": "7e21ba42-feb4-465d-94a6-1d30fcaa0d39", "control-id": "rhel-09.232103", "description": "REPLACE_ME", "props": [ @@ -29667,7 +29667,7 @@ ] }, { - "uuid": "3b0b624d-377e-49ca-a33a-0b65941538ac", + "uuid": "361bcde5-b146-49cb-a8c8-90a68eec3829", "control-id": "rhel-09.232104", "description": "REPLACE_ME", "props": [ @@ -29685,7 +29685,7 @@ ] }, { - "uuid": "b0af122c-4a59-4a53-ade6-1007164dc5d1", + "uuid": "0a0f7a8e-1078-41aa-bd8b-c1e0c9d03cbe", "control-id": "rhel-09.232105", "description": "REPLACE_ME", "props": [ @@ -29702,7 +29702,7 @@ ] }, { - "uuid": "5687c84e-446d-4b54-b650-b0175c0378c1", + "uuid": "a79e94e7-56da-4efa-b839-744d95c5d58d", "control-id": "rhel-09.232110", "description": "REPLACE_ME", "props": [ @@ -29719,7 +29719,7 @@ ] }, { - "uuid": "8253032a-d85c-47dc-a78e-3a57c00b5127", + "uuid": "7f90c68c-e134-4e6b-9132-79637dace7e0", "control-id": "rhel-09.232115", "description": "REPLACE_ME", "props": [ @@ -29736,7 +29736,7 @@ ] }, { - "uuid": "a2d18132-80a7-4d4f-8f6a-2455a15bd5d4", + "uuid": "d0b2e3c9-00b2-4041-864c-ce28ad1067f8", "control-id": "rhel-09.232120", "description": "REPLACE_ME", "props": [ @@ -29753,7 +29753,7 @@ ] }, { - "uuid": "3a95c264-9066-4a29-868b-157b11944fcd", + "uuid": "c0a0796c-0b60-4009-87ac-72a9a7bf0145", "control-id": "rhel-09.232125", "description": "REPLACE_ME", "props": [ @@ -29770,7 +29770,7 @@ ] }, { - "uuid": "69b90af0-b87f-449a-92c2-1150d5bc92b5", + "uuid": "ffaff1d9-a99d-499b-ae0d-0851250e837c", "control-id": "rhel-09.232130", "description": "REPLACE_ME", "props": [ @@ -29787,7 +29787,7 @@ ] }, { - "uuid": "53c0e635-16a1-47a2-a3ec-5052324b0f1c", + "uuid": "87a6f454-c4fd-44ad-b88b-3274d41335ff", "control-id": "rhel-09.232135", "description": "REPLACE_ME", "props": [ @@ -29804,7 +29804,7 @@ ] }, { - "uuid": "a297ec99-885a-4860-b6fc-658016736c8e", + "uuid": "87e88e2b-b646-4dec-96a9-1e3f37a763d4", "control-id": "rhel-09.232140", "description": "REPLACE_ME", "props": [ @@ -29821,7 +29821,7 @@ ] }, { - "uuid": "ff6d4f85-15f7-4fd1-8d1d-b99d3f3717c6", + "uuid": "28aac013-453d-40cb-9cb2-50f069d44f62", "control-id": "rhel-09.232145", "description": "REPLACE_ME", "props": [ @@ -29838,7 +29838,7 @@ ] }, { - "uuid": "aaf75632-f925-47d4-9a83-a04b44ae28be", + "uuid": "af13ff93-4b96-483b-9798-53bd05f22501", "control-id": "rhel-09.232150", "description": "REPLACE_ME", "props": [ @@ -29855,7 +29855,7 @@ ] }, { - "uuid": "7bd65fd2-ca59-4fef-854d-a799127323b7", + "uuid": "ba06c105-25f3-4f63-9136-3d598c0d3593", "control-id": "rhel-09.232155", "description": "REPLACE_ME", "props": [ @@ -29872,7 +29872,7 @@ ] }, { - "uuid": "9cf0cec6-fe3f-4e1d-b51a-83a152464772", + "uuid": "32635e3e-f720-4b10-a75c-ea9bd36b4abd", "control-id": "rhel-09.232160", "description": "REPLACE_ME", "props": [ @@ -29889,7 +29889,7 @@ ] }, { - "uuid": "f6e70538-7d94-4275-b0e4-b19fcd1ae08b", + "uuid": "fac6bff5-071f-4bb2-9ef9-2cd43d80f363", "control-id": "rhel-09.232165", "description": "REPLACE_ME", "props": [ @@ -29906,7 +29906,7 @@ ] }, { - "uuid": "dfcdf10d-f936-4d40-abc8-650cd332c363", + "uuid": "d2b6b2a5-f64b-4354-9b4e-f64899be8a15", "control-id": "rhel-09.232170", "description": "REPLACE_ME", "props": [ @@ -29923,7 +29923,7 @@ ] }, { - "uuid": "aea392a2-066a-4e09-a1d5-a1c71bace399", + "uuid": "4a863f92-5dbb-48c7-8651-5f99c59062d7", "control-id": "rhel-09.232175", "description": "REPLACE_ME", "props": [ @@ -29940,7 +29940,7 @@ ] }, { - "uuid": "59f9b468-f306-4ef0-9948-acce65c7c2c1", + "uuid": "d83aa766-9c85-44c8-9faa-a8159b0518f1", "control-id": "rhel-09.232180", "description": "REPLACE_ME", "props": [ @@ -29957,7 +29957,7 @@ ] }, { - "uuid": "06b86d16-f05e-42d0-9e72-38bb7a94c69e", + "uuid": "ab93ec7c-7a5f-41b4-a7ee-800fe91958f3", "control-id": "rhel-09.232185", "description": "REPLACE_ME", "props": [ @@ -29974,7 +29974,7 @@ ] }, { - "uuid": "ed317348-ba02-4e32-a244-6b2216192e1d", + "uuid": "5dca06e3-a833-42ff-8c1b-fe1742f27e0f", "control-id": "rhel-09.232190", "description": "REPLACE_ME", "props": [ @@ -29991,7 +29991,7 @@ ] }, { - "uuid": "d78d5946-a2f5-405d-9768-d2016084831c", + "uuid": "6db47c08-a6d1-4663-9894-58cbcc6404c0", "control-id": "rhel-09.232195", "description": "REPLACE_ME", "props": [ @@ -30008,7 +30008,7 @@ ] }, { - "uuid": "2c025726-d466-4821-8d4b-49eaef9e207f", + "uuid": "76b13bcd-eace-4a07-9026-31232f487acb", "control-id": "rhel-09.232200", "description": "REPLACE_ME", "props": [ @@ -30025,7 +30025,7 @@ ] }, { - "uuid": "58986942-6fbb-4959-8e8b-28242eaf6a23", + "uuid": "ea8040ac-6e88-47c4-b1d8-bbf7f1799b62", "control-id": "rhel-09.232205", "description": "REPLACE_ME", "props": [ @@ -30042,7 +30042,7 @@ ] }, { - "uuid": "0abb4ae1-03a6-4804-b1ce-67a9c39560b0", + "uuid": "f2c728a4-09bd-40cd-9311-9005811976ba", "control-id": "rhel-09.232210", "description": "REPLACE_ME", "props": [ @@ -30059,7 +30059,7 @@ ] }, { - "uuid": "c7e68cac-97c9-4504-88b5-15779dda453a", + "uuid": "b22726f0-46a9-4392-a956-dbb329297076", "control-id": "rhel-09.232215", "description": "REPLACE_ME", "props": [ @@ -30076,7 +30076,7 @@ ] }, { - "uuid": "0c4c7bbd-51a8-49fa-8bc8-47a2f4534712", + "uuid": "ebdc5bb2-2846-41ea-8b6c-08477fa7cb45", "control-id": "rhel-09.232220", "description": "REPLACE_ME", "props": [ @@ -30093,7 +30093,7 @@ ] }, { - "uuid": "ddd1f654-4452-4bcf-a518-3fd02a393fda", + "uuid": "d6bfb3c7-c301-4a54-8782-f0bc23ed2911", "control-id": "rhel-09.232225", "description": "REPLACE_ME", "props": [ @@ -30110,7 +30110,7 @@ ] }, { - "uuid": "9f1f0129-b467-42bf-b744-67efccfe4687", + "uuid": "b0c2f44d-6589-43a2-aa6d-0dc73476c990", "control-id": "rhel-09.232230", "description": "REPLACE_ME", "props": [ @@ -30157,7 +30157,7 @@ ] }, { - "uuid": "a2ee1671-ff89-4bb3-a0bc-3678704c61f7", + "uuid": "85740dfd-6c92-4b21-b755-dab91999bdf2", "control-id": "rhel-09.232235", "description": "REPLACE_ME", "props": [ @@ -30204,7 +30204,7 @@ ] }, { - "uuid": "be733872-6422-4d2a-a6af-f90e37262b6a", + "uuid": "7f888b8e-c453-4c42-987c-a2535a844293", "control-id": "rhel-09.232240", "description": "REPLACE_ME", "props": [ @@ -30221,7 +30221,7 @@ ] }, { - "uuid": "1262f664-7b8b-4611-939f-461f8416d592", + "uuid": "24328f40-f07d-43f0-a191-5f7ad62752e3", "control-id": "rhel-09.232245", "description": "REPLACE_ME", "props": [ @@ -30238,7 +30238,7 @@ ] }, { - "uuid": "cd5bc85c-d8fb-431c-9c62-57006696e683", + "uuid": "2d0045db-a525-4b61-8892-123df7c2fb74", "control-id": "rhel-09.232250", "description": "REPLACE_ME", "props": [ @@ -30255,7 +30255,7 @@ ] }, { - "uuid": "95ddf0a8-a8e0-4862-909b-472e973282b3", + "uuid": "9c381bd9-2bb0-402a-96ce-904c2775c42d", "control-id": "rhel-09.232255", "description": "REPLACE_ME", "props": [ @@ -30272,7 +30272,7 @@ ] }, { - "uuid": "0cc9a75f-12c3-42d5-86e0-6cfa89909e6a", + "uuid": "39372e56-d4d8-4efd-81cf-c430c838c9d1", "control-id": "rhel-09.232260", "description": "REPLACE_ME", "props": [ @@ -30289,7 +30289,7 @@ ] }, { - "uuid": "68b3a0ce-c96a-4a8e-9255-25d7dae88eee", + "uuid": "3cf5901b-430a-4536-86a2-37d2d723a40a", "control-id": "rhel-09.232270", "description": "REPLACE_ME", "props": [ @@ -30306,7 +30306,7 @@ ] }, { - "uuid": "229119cf-ea5a-4003-b106-7e14916ff193", + "uuid": "eaa56862-98d4-4820-8504-8fd17b25a86f", "control-id": "rhel-09.251010", "description": "REPLACE_ME", "props": [ @@ -30323,7 +30323,7 @@ ] }, { - "uuid": "fcd26aa4-df9e-4d2f-8f78-cb08e9eaf7a1", + "uuid": "9c1ce881-caa3-4c01-9f97-6e930dfba505", "control-id": "rhel-09.251015", "description": "REPLACE_ME", "props": [ @@ -30340,7 +30340,7 @@ ] }, { - "uuid": "e5bee563-a171-49d2-8697-96a791cfdca1", + "uuid": "67b6097d-19d3-496e-9d42-d50e9871294e", "control-id": "rhel-09.251020", "description": "REPLACE_ME", "props": [ @@ -30357,7 +30357,7 @@ ] }, { - "uuid": "ee8049b9-3347-4725-a178-c60e025c0e36", + "uuid": "5470f902-6d7c-4226-bf62-9a09e6258cd6", "control-id": "rhel-09.251030", "description": "REPLACE_ME", "props": [ @@ -30374,7 +30374,7 @@ ] }, { - "uuid": "c6135ea7-63df-467b-ab4d-0115a8b8941f", + "uuid": "a1537b00-2768-474b-8b2f-1478d2321bae", "control-id": "rhel-09.251035", "description": "REPLACE_ME", "props": [ @@ -30391,7 +30391,7 @@ ] }, { - "uuid": "e9b44372-4205-45c1-9995-1d2b7f1e0f14", + "uuid": "c2de84c4-7c2e-4220-bbf8-3a64a7650aee", "control-id": "rhel-09.251040", "description": "REPLACE_ME", "props": [ @@ -30408,7 +30408,7 @@ ] }, { - "uuid": "1a716dc1-c7d9-487d-abb1-16ec5658483f", + "uuid": "c49c697a-9ae8-4dec-b0b6-e40cdfaf2f11", "control-id": "rhel-09.251045", "description": "REPLACE_ME", "props": [ @@ -30425,7 +30425,7 @@ ] }, { - "uuid": "0c95d6eb-7e95-4dca-babe-acabaafe2d95", + "uuid": "52b9de9a-0174-42b7-b811-58ad70341b1d", "control-id": "rhel-09.252010", "description": "REPLACE_ME", "props": [ @@ -30442,7 +30442,7 @@ ] }, { - "uuid": "1744b0f2-e0b7-4b55-a11a-cfbe280f3603", + "uuid": "06a652a2-d888-43b3-b1bd-26e988e79845", "control-id": "rhel-09.252015", "description": "REPLACE_ME", "props": [ @@ -30459,7 +30459,7 @@ ] }, { - "uuid": "36643cdf-5bbc-4e6e-8357-a7cd06399e99", + "uuid": "64764bcb-2c89-4296-aaaf-5adaff8afba4", "control-id": "rhel-09.252020", "description": "REPLACE_ME", "props": [ @@ -30486,7 +30486,7 @@ ] }, { - "uuid": "eaf22031-bf1c-4e6d-9d8c-f87ca5a747ed", + "uuid": "ee536288-b95f-41aa-a80a-d6f089f28fb1", "control-id": "rhel-09.252035", "description": "REPLACE_ME", "props": [ @@ -30503,7 +30503,7 @@ ] }, { - "uuid": "6eba3c89-88f0-470e-8b74-126446d18cc6", + "uuid": "174c6528-5111-4c03-b3ce-4a5da0ba1cf2", "control-id": "rhel-09.252040", "description": "REPLACE_ME", "props": [ @@ -30520,7 +30520,7 @@ ] }, { - "uuid": "49a7fd05-01d7-44b8-bd1a-8e756f309c98", + "uuid": "1f82ade9-4ce2-469f-b2c5-185c04e658b1", "control-id": "rhel-09.252045", "description": "REPLACE_ME", "props": [ @@ -30537,7 +30537,7 @@ ] }, { - "uuid": "734ff7ed-65be-4299-86f7-e24aab84eb33", + "uuid": "fa822ecb-d2ca-4086-ab20-34a5dc133337", "control-id": "rhel-09.252050", "description": "REPLACE_ME", "props": [ @@ -30554,7 +30554,7 @@ ] }, { - "uuid": "59c914d5-072b-4dc0-9753-159bd68478fa", + "uuid": "fe15d0e7-8f2f-45af-8847-089919d290a3", "control-id": "rhel-09.252060", "description": "REPLACE_ME", "props": [ @@ -30571,7 +30571,7 @@ ] }, { - "uuid": "9bc3afed-d8f7-43b2-aed7-8ca701706092", + "uuid": "2122d6d1-636d-48c6-9730-aa4070d54752", "control-id": "rhel-09.252065", "description": "REPLACE_ME", "props": [ @@ -30588,7 +30588,7 @@ ] }, { - "uuid": "a9be0e1c-cfa0-48a6-8e09-586b36499d2f", + "uuid": "b9f105f4-3bdf-436f-a18d-fcf96c6c6948", "control-id": "rhel-09.253010", "description": "REPLACE_ME", "props": [ @@ -30605,7 +30605,7 @@ ] }, { - "uuid": "2b92907f-a0cf-4be2-ba2c-f8332aa0701b", + "uuid": "d20b6d0e-1dac-4670-9fa8-3db6f8e8d002", "control-id": "rhel-09.253015", "description": "REPLACE_ME", "props": [ @@ -30622,7 +30622,7 @@ ] }, { - "uuid": "632c8051-914a-4cfe-aedf-187b66b324c5", + "uuid": "69d53c99-a0aa-4ce7-baf5-10d2537c692a", "control-id": "rhel-09.253020", "description": "REPLACE_ME", "props": [ @@ -30639,7 +30639,7 @@ ] }, { - "uuid": "6705e014-14f1-4a34-9e78-a22be3ffe156", + "uuid": "0b8f6c04-2048-41d0-85b4-0d185e8a88ca", "control-id": "rhel-09.253025", "description": "REPLACE_ME", "props": [ @@ -30656,7 +30656,7 @@ ] }, { - "uuid": "134e5b53-3d1a-4495-9b6a-78d15284adb5", + "uuid": "22e152fc-d179-4ee9-be06-9f4f44069adc", "control-id": "rhel-09.253030", "description": "REPLACE_ME", "props": [ @@ -30673,7 +30673,7 @@ ] }, { - "uuid": "c050205c-6660-46a6-91b6-aebf6bb677ec", + "uuid": "0a8d6180-61cf-4f0d-bbf8-13b400245622", "control-id": "rhel-09.253035", "description": "REPLACE_ME", "props": [ @@ -30690,7 +30690,7 @@ ] }, { - "uuid": "b783b8ff-f3e0-4a96-a500-3045cb19fb02", + "uuid": "ad0b2d1c-3274-4a54-ae5d-eaf8d2609284", "control-id": "rhel-09.253040", "description": "REPLACE_ME", "props": [ @@ -30707,7 +30707,7 @@ ] }, { - "uuid": "8530650b-a8ba-4730-acda-6c9319b537c2", + "uuid": "e333f343-7524-4144-957f-b34824915e92", "control-id": "rhel-09.253045", "description": "REPLACE_ME", "props": [ @@ -30724,7 +30724,7 @@ ] }, { - "uuid": "13f5bbc3-7109-49de-bf72-d6a22a8ef504", + "uuid": "d94c03f4-f6d2-4c3c-85a1-074a32cbd903", "control-id": "rhel-09.253050", "description": "REPLACE_ME", "props": [ @@ -30741,7 +30741,7 @@ ] }, { - "uuid": "bdc82b47-6e56-48eb-ae8f-bc41355f6d94", + "uuid": "0ffb9f4c-60ba-4b92-93c9-b808292a50ac", "control-id": "rhel-09.253055", "description": "REPLACE_ME", "props": [ @@ -30758,7 +30758,7 @@ ] }, { - "uuid": "f760343d-bda0-4083-8d6c-45ee2eef127f", + "uuid": "a2deca7e-4f7e-4039-87be-5b4bec7c7ee0", "control-id": "rhel-09.253060", "description": "REPLACE_ME", "props": [ @@ -30775,7 +30775,7 @@ ] }, { - "uuid": "aa13605d-0fe2-4cf8-b1a9-517fd21f275f", + "uuid": "0f16e9f2-3b1e-43e1-bf89-f69540a16685", "control-id": "rhel-09.253065", "description": "REPLACE_ME", "props": [ @@ -30792,7 +30792,7 @@ ] }, { - "uuid": "aad8ea55-961b-4cb2-ae62-00a5c1008b30", + "uuid": "60d37244-b640-46e5-919d-7ac1323a37ce", "control-id": "rhel-09.253070", "description": "REPLACE_ME", "props": [ @@ -30809,7 +30809,7 @@ ] }, { - "uuid": "46c32f57-6715-4bd7-8327-d96d5d3a1842", + "uuid": "b356099d-bf94-48ed-b86a-2f88990f7014", "control-id": "rhel-09.253075", "description": "REPLACE_ME", "props": [ @@ -30826,7 +30826,7 @@ ] }, { - "uuid": "b35a8e58-beeb-4ea9-82b6-43eb40b4f791", + "uuid": "6054ba3b-bc71-47a4-9ab1-78fac2b8a80e", "control-id": "rhel-09.254010", "description": "REPLACE_ME", "props": [ @@ -30843,7 +30843,7 @@ ] }, { - "uuid": "d1a1e99a-be2f-43ff-a6e9-1820b4301e09", + "uuid": "c39a3927-e7c9-45d2-bff8-6670f0dad701", "control-id": "rhel-09.254015", "description": "REPLACE_ME", "props": [ @@ -30860,7 +30860,7 @@ ] }, { - "uuid": "802d57c4-12d9-4e31-a5dc-e117db4ff7ab", + "uuid": "ff8fa0b9-b325-41b6-a0d9-568b2b752733", "control-id": "rhel-09.254020", "description": "REPLACE_ME", "props": [ @@ -30877,7 +30877,7 @@ ] }, { - "uuid": "fc0a28a3-221d-4f36-9c77-9d5301f38e6f", + "uuid": "b3ca2a63-d605-4f4a-8383-005cb2fce7a6", "control-id": "rhel-09.254025", "description": "REPLACE_ME", "props": [ @@ -30894,7 +30894,7 @@ ] }, { - "uuid": "954e7ffd-9add-437c-bc94-b9dc6ebebb82", + "uuid": "ede9b491-61da-4cf2-a699-a0cd871856a4", "control-id": "rhel-09.254030", "description": "REPLACE_ME", "props": [ @@ -30911,7 +30911,7 @@ ] }, { - "uuid": "45796da7-502c-49fb-b5ce-975952836fe4", + "uuid": "1ea4649d-3d17-4ebd-82c6-d4f2a3b750cf", "control-id": "rhel-09.254035", "description": "REPLACE_ME", "props": [ @@ -30928,7 +30928,7 @@ ] }, { - "uuid": "58652868-7740-4425-b3e0-487d26cde76e", + "uuid": "f78008f8-28b9-415e-b19f-a3185b895e31", "control-id": "rhel-09.254040", "description": "REPLACE_ME", "props": [ @@ -30945,7 +30945,7 @@ ] }, { - "uuid": "6e17d01e-a155-4dbc-900b-8ba8c71e9d0f", + "uuid": "f1958d2b-2613-4f0b-a651-8fcc6ebbc09b", "control-id": "rhel-09.255010", "description": "REPLACE_ME", "props": [ @@ -30962,7 +30962,7 @@ ] }, { - "uuid": "741b6c70-7897-4773-a94e-c75676dc5365", + "uuid": "fd25ede9-0dc6-4751-9d0f-5f1741193b7b", "control-id": "rhel-09.255015", "description": "REPLACE_ME", "props": [ @@ -30979,7 +30979,7 @@ ] }, { - "uuid": "d6b42b9c-8050-46e0-afc7-078fbfb34f1b", + "uuid": "06512c1f-a884-4dbe-81cd-752dd9d368ca", "control-id": "rhel-09.255020", "description": "REPLACE_ME", "props": [ @@ -30996,7 +30996,7 @@ ] }, { - "uuid": "b6d6bce9-d2fe-44bb-92f3-603249385c86", + "uuid": "1fb7c12d-2bf2-4e2c-8740-34516d3f2d3a", "control-id": "rhel-09.255025", "description": "REPLACE_ME", "props": [ @@ -31013,7 +31013,7 @@ ] }, { - "uuid": "71eb715e-a24a-4849-8dc2-15830fe84ba4", + "uuid": "5aad6f12-a452-4be4-98e6-29f881ada9f4", "control-id": "rhel-09.255030", "description": "REPLACE_ME", "props": [ @@ -31030,7 +31030,7 @@ ] }, { - "uuid": "15a1fbbf-0868-47a0-8939-e0c17d1c58b2", + "uuid": "a4e18acc-0042-480e-b767-27c108822033", "control-id": "rhel-09.255035", "description": "REPLACE_ME", "props": [ @@ -31047,7 +31047,7 @@ ] }, { - "uuid": "59cb4524-d94d-435c-b12a-9b47a6d0f59c", + "uuid": "cc101ef8-0b3d-4942-8ca7-2ede01868d46", "control-id": "rhel-09.255045", "description": "REPLACE_ME", "props": [ @@ -31064,7 +31064,7 @@ ] }, { - "uuid": "5bf59fe8-8910-428e-a873-816d103a1e43", + "uuid": "1587ca0c-1c71-4aa9-b2f0-e2f2dfb90266", "control-id": "rhel-09.255055", "description": "REPLACE_ME", "props": [ @@ -31086,7 +31086,7 @@ ] }, { - "uuid": "0ff634e0-5350-4ff2-9b14-c7767bb34710", + "uuid": "5cc2eb80-584a-4e4c-87e2-300c0fb03687", "control-id": "rhel-09.255060", "description": "REPLACE_ME", "props": [ @@ -31103,7 +31103,7 @@ ] }, { - "uuid": "1106bc1e-4b05-476f-bb29-24096239b5d1", + "uuid": "d6d29850-fb03-4363-852b-b198aab79bc3", "control-id": "rhel-09.255064", "description": "REPLACE_ME", "props": [ @@ -31121,7 +31121,7 @@ ] }, { - "uuid": "55b84498-ef56-427e-9c21-908506a7091c", + "uuid": "64aa84a5-a53d-4af1-9446-b8f5b68e3267", "control-id": "rhel-09.255065", "description": "REPLACE_ME", "props": [ @@ -31138,7 +31138,7 @@ ] }, { - "uuid": "d73dfce5-31a0-4a07-8c0d-865828ca2c6b", + "uuid": "7030cd22-759e-4b40-a1b1-59e49de73483", "control-id": "rhel-09.255070", "description": "REPLACE_ME", "props": [ @@ -31156,7 +31156,7 @@ ] }, { - "uuid": "48bf1cb6-3a9c-4f05-a28c-f8869a42ecca", + "uuid": "04940040-e6b9-4c8f-96e1-0d3e0aaa7161", "control-id": "rhel-09.255075", "description": "REPLACE_ME", "props": [ @@ -31173,7 +31173,7 @@ ] }, { - "uuid": "00e90f79-8d5d-4797-80ae-b90dd12c11f2", + "uuid": "af6f7a12-877e-4b06-868e-d658e475977a", "control-id": "rhel-09.255080", "description": "REPLACE_ME", "props": [ @@ -31190,7 +31190,7 @@ ] }, { - "uuid": "a9ea4b50-5675-4915-b8bb-98492b698468", + "uuid": "9e941af3-348c-4114-8a09-da01193703fe", "control-id": "rhel-09.255085", "description": "REPLACE_ME", "props": [ @@ -31207,7 +31207,7 @@ ] }, { - "uuid": "a2839aab-62e0-468f-a9b1-604b88a2417b", + "uuid": "9a5b482c-46eb-4ee8-b9c9-9f205a0a895f", "control-id": "rhel-09.255090", "description": "REPLACE_ME", "props": [ @@ -31224,7 +31224,7 @@ ] }, { - "uuid": "ca4f88d3-8749-41f5-8777-2a8c7ac21fec", + "uuid": "10acf397-b644-482d-980e-c3f669d4e78d", "control-id": "rhel-09.255095", "description": "REPLACE_ME", "props": [ @@ -31241,7 +31241,7 @@ ] }, { - "uuid": "3244c29f-a062-4300-93ea-46639bd3dfe5", + "uuid": "eabb94d4-4211-4d5b-989d-3024c966d14a", "control-id": "rhel-09.255100", "description": "REPLACE_ME", "props": [ @@ -31258,7 +31258,7 @@ ] }, { - "uuid": "5c0a9735-9803-40f5-b451-eba80c14f48e", + "uuid": "bc815ef9-ce71-4852-95fc-8a68a6fcbcfb", "control-id": "rhel-09.255105", "description": "REPLACE_ME", "props": [ @@ -31285,7 +31285,7 @@ ] }, { - "uuid": "63a25344-d783-40d8-887b-fcc3a285aef9", + "uuid": "07bd7b79-90d1-43ba-8ce2-aa45e492cd87", "control-id": "rhel-09.255110", "description": "REPLACE_ME", "props": [ @@ -31312,7 +31312,7 @@ ] }, { - "uuid": "2c825d95-ffe5-476b-a26b-8c2c95346787", + "uuid": "37b371a3-5e5d-4ae6-a948-4211fc61c53c", "control-id": "rhel-09.255115", "description": "REPLACE_ME", "props": [ @@ -31339,7 +31339,7 @@ ] }, { - "uuid": "d05baac1-2e80-473e-b4b5-2b5f3d2d568c", + "uuid": "487811c0-93df-4ac8-982b-713866fa1cc1", "control-id": "rhel-09.255120", "description": "REPLACE_ME", "props": [ @@ -31356,7 +31356,7 @@ ] }, { - "uuid": "7a83abf5-98b1-4943-bdc5-af23050801e1", + "uuid": "5a022b9f-6d0b-462c-9fba-fb6705a8298d", "control-id": "rhel-09.255125", "description": "REPLACE_ME", "props": [ @@ -31373,7 +31373,7 @@ ] }, { - "uuid": "b055ea2f-8677-4257-a073-71f44f678379", + "uuid": "1d1f9092-5f16-4bf6-a0a0-8ec1c083c92d", "control-id": "rhel-09.255130", "description": "REPLACE_ME", "props": [ @@ -31390,7 +31390,7 @@ ] }, { - "uuid": "1ebb84f1-7f14-48f6-ac89-9036af560aef", + "uuid": "4a005d2e-d195-48e3-ba7e-97705a7bdb0c", "control-id": "rhel-09.255135", "description": "REPLACE_ME", "props": [ @@ -31407,7 +31407,7 @@ ] }, { - "uuid": "4abbae83-3e7a-487a-bf6c-419413620c4b", + "uuid": "64ad8830-dbc0-4629-8cd4-a91b4a1233bc", "control-id": "rhel-09.255140", "description": "REPLACE_ME", "props": [ @@ -31424,7 +31424,7 @@ ] }, { - "uuid": "7c4f0c41-62aa-47c1-88e4-a4cc9850d977", + "uuid": "f3090c98-6bf9-40c6-9ec2-43345d6ba395", "control-id": "rhel-09.255145", "description": "REPLACE_ME", "props": [ @@ -31441,7 +31441,7 @@ ] }, { - "uuid": "a27a4e89-4d20-4d29-99e1-3d8328648674", + "uuid": "c23e1b4b-5dd1-4d90-a18f-f70cf2d419ec", "control-id": "rhel-09.255150", "description": "REPLACE_ME", "props": [ @@ -31458,7 +31458,7 @@ ] }, { - "uuid": "2ff5e2f5-61d6-4db1-9bc1-26b2fb625241", + "uuid": "8af25489-dcba-433d-8964-315d7dcdc3fc", "control-id": "rhel-09.255155", "description": "REPLACE_ME", "props": [ @@ -31475,7 +31475,7 @@ ] }, { - "uuid": "cb8d3439-5db6-405f-a66d-dae588608be8", + "uuid": "f07bb6c3-77f9-4166-98ae-13bb97277619", "control-id": "rhel-09.255160", "description": "REPLACE_ME", "props": [ @@ -31492,7 +31492,7 @@ ] }, { - "uuid": "2448df64-ac73-409a-af99-0587c5f832db", + "uuid": "b1f4a86b-8be6-4e03-bb88-86237f940175", "control-id": "rhel-09.255165", "description": "REPLACE_ME", "props": [ @@ -31509,7 +31509,7 @@ ] }, { - "uuid": "34442097-90cd-45c4-80e6-ebc546393c01", + "uuid": "d971e5e9-db18-49fc-80d9-49c99bb900f0", "control-id": "rhel-09.255175", "description": "REPLACE_ME", "props": [ @@ -31526,7 +31526,7 @@ ] }, { - "uuid": "78c71855-e338-4022-a1e1-c0b87169e6c2", + "uuid": "d255f1fb-b8a8-4e5e-b8cf-83367e3dd56e", "control-id": "rhel-09.271010", "description": "REPLACE_ME", "props": [ @@ -31543,7 +31543,7 @@ ] }, { - "uuid": "aa5aad8e-760e-4c1a-866f-04cb8bc19dd9", + "uuid": "8244ea24-7846-4cca-ae90-73df3fd2a84c", "control-id": "rhel-09.271015", "description": "REPLACE_ME", "props": [ @@ -31560,7 +31560,7 @@ ] }, { - "uuid": "3db8d63b-c5cd-4a1d-a356-4ca752d67f3a", + "uuid": "0678418c-c31a-44e9-91e3-36336368f8d9", "control-id": "rhel-09.271020", "description": "REPLACE_ME", "props": [ @@ -31577,7 +31577,7 @@ ] }, { - "uuid": "0f488ae6-dfa2-4471-9ca6-2f435af55fb2", + "uuid": "716f75bf-f61c-4ec9-a9a6-0409b4f566cf", "control-id": "rhel-09.271025", "description": "REPLACE_ME", "props": [ @@ -31594,7 +31594,7 @@ ] }, { - "uuid": "fbcb4112-1d09-4e4d-b8d7-ed3ea639f696", + "uuid": "17424cb7-6bc3-48a7-842a-c6c83617a73a", "control-id": "rhel-09.271030", "description": "REPLACE_ME", "props": [ @@ -31611,7 +31611,7 @@ ] }, { - "uuid": "9950cf29-628f-40a3-ab46-0383a0b70f41", + "uuid": "86e16d5b-45a5-4e26-bc9f-cd879db6b913", "control-id": "rhel-09.271035", "description": "REPLACE_ME", "props": [ @@ -31628,7 +31628,7 @@ ] }, { - "uuid": "f2af15c9-2077-4131-afa7-d97550042ea5", + "uuid": "1c27076c-f378-4e2f-87a9-4b78539c1d7b", "control-id": "rhel-09.271045", "description": "REPLACE_ME", "props": [ @@ -31645,7 +31645,7 @@ ] }, { - "uuid": "5608be11-6808-4395-8f51-638d298fdef8", + "uuid": "605f524e-872b-431a-a7ae-64cd1dfeb107", "control-id": "rhel-09.271050", "description": "REPLACE_ME", "props": [ @@ -31662,7 +31662,7 @@ ] }, { - "uuid": "99435e4f-cb7d-414e-94de-f3c0104868e4", + "uuid": "d72d096e-580b-4386-aa16-95dd17490ae0", "control-id": "rhel-09.271055", "description": "REPLACE_ME", "props": [ @@ -31679,7 +31679,7 @@ ] }, { - "uuid": "d8b6adaf-488b-4781-bdb7-1c93696a79c8", + "uuid": "66f3ccb2-5bea-47d8-af7f-57d060e844aa", "control-id": "rhel-09.271060", "description": "REPLACE_ME", "props": [ @@ -31696,7 +31696,7 @@ ] }, { - "uuid": "f7a0fd30-6100-4715-9917-b5da0c1aa249", + "uuid": "510200ac-4777-47cd-87bf-677c7f16d6c8", "control-id": "rhel-09.271065", "description": "REPLACE_ME", "props": [ @@ -31713,7 +31713,7 @@ ] }, { - "uuid": "3e393667-d732-4fdd-9292-ca38ba2a5854", + "uuid": "de7863cd-9ef8-4e38-a547-48aa6b19436c", "control-id": "rhel-09.271070", "description": "REPLACE_ME", "props": [ @@ -31730,7 +31730,7 @@ ] }, { - "uuid": "10fa95a0-0614-4dee-a9f1-5e1fa57f56ae", + "uuid": "2421b8e0-a6e2-4c2e-b890-5f67105b6be0", "control-id": "rhel-09.271075", "description": "REPLACE_ME", "props": [ @@ -31747,7 +31747,7 @@ ] }, { - "uuid": "4863f69e-1880-4368-aeaf-059cfd5a47e2", + "uuid": "46702a83-42a8-40e0-ab00-5f2e20618b36", "control-id": "rhel-09.271080", "description": "REPLACE_ME", "props": [ @@ -31764,7 +31764,7 @@ ] }, { - "uuid": "6757e2ee-12b0-438c-b3e2-02f19aa72985", + "uuid": "bf5caa68-5272-4a40-aa4d-e015dfce5f01", "control-id": "rhel-09.271085", "description": "REPLACE_ME", "props": [ @@ -31781,7 +31781,7 @@ ] }, { - "uuid": "64b05ce7-5364-4769-b386-fc873adebc7f", + "uuid": "f3ae30ae-ae4d-455a-80d2-c4adcd63c62a", "control-id": "rhel-09.271090", "description": "REPLACE_ME", "props": [ @@ -31798,7 +31798,7 @@ ] }, { - "uuid": "f0440271-a106-4551-ae8a-8882e8d8fb1f", + "uuid": "e8fbe710-4aee-49d8-96f4-b85f184341d4", "control-id": "rhel-09.271095", "description": "REPLACE_ME", "props": [ @@ -31815,7 +31815,7 @@ ] }, { - "uuid": "895078c4-112e-4001-b32f-eedc4f6d7240", + "uuid": "c423a662-54c9-4fd0-b5f0-7353d876659b", "control-id": "rhel-09.271100", "description": "REPLACE_ME", "props": [ @@ -31832,7 +31832,7 @@ ] }, { - "uuid": "0f2732b7-90c4-4015-a3b7-198df5a031b2", + "uuid": "c4a84a84-88e9-4864-8038-eb68f6ac1297", "control-id": "rhel-09.271105", "description": "REPLACE_ME", "props": [ @@ -31849,7 +31849,7 @@ ] }, { - "uuid": "e9ab1b81-2b52-4280-9105-dbc146dc681a", + "uuid": "d9542193-285f-4d29-a01a-080c6c73a221", "control-id": "rhel-09.271110", "description": "REPLACE_ME", "props": [ @@ -31866,7 +31866,7 @@ ] }, { - "uuid": "607e5fa3-4627-421d-9508-d3efffd2f332", + "uuid": "a1385d2b-0f15-4815-abb5-75227d2d0d81", "control-id": "rhel-09.271115", "description": "REPLACE_ME", "props": [ @@ -31883,7 +31883,7 @@ ] }, { - "uuid": "3cd1b432-0957-459a-8fee-4eab4ad84b97", + "uuid": "dd5488ca-a9d1-4f10-afb0-e912db8e43f8", "control-id": "rhel-09.291010", "description": "REPLACE_ME", "props": [ @@ -31900,7 +31900,7 @@ ] }, { - "uuid": "5453eb3f-051d-4c7b-b4b1-da9d8f8f0619", + "uuid": "ee39e83b-5f7d-4ec8-881f-d8535fd052d9", "control-id": "rhel-09.291015", "description": "REPLACE_ME", "props": [ @@ -31917,7 +31917,7 @@ ] }, { - "uuid": "152132ee-4459-4d6e-94e2-442602b1a87f", + "uuid": "61b5f4ac-9364-493f-831f-6b13b6535f79", "control-id": "rhel-09.291020", "description": "REPLACE_ME", "props": [ @@ -31934,7 +31934,7 @@ ] }, { - "uuid": "6bdf18db-e2f6-4ff8-acf9-878acf68a20c", + "uuid": "beacb81a-9046-46cf-8994-dad95d2da861", "control-id": "rhel-09.291030", "description": "REPLACE_ME", "props": [ @@ -31951,7 +31951,7 @@ ] }, { - "uuid": "c00005a0-a6c5-4c43-a04c-22a1f833c681", + "uuid": "79ba4309-e3bb-46e7-b818-6c1104711e88", "control-id": "rhel-09.291035", "description": "REPLACE_ME", "props": [ @@ -31968,7 +31968,7 @@ ] }, { - "uuid": "8660bab5-8f19-46ff-9b4e-b5d6ac66dd8f", + "uuid": "7d5f2439-c64e-4a31-857c-ac344259bb1a", "control-id": "rhel-09.291040", "description": "REPLACE_ME", "props": [ @@ -31985,7 +31985,7 @@ ] }, { - "uuid": "03776353-a4cc-4748-8944-c735273d075d", + "uuid": "f9663b73-b8d6-42ab-a4a9-1fd8ef3cfd1b", "control-id": "rhel-09.411010", "description": "REPLACE_ME", "props": [ @@ -32002,7 +32002,7 @@ ] }, { - "uuid": "db1cb22c-92df-490e-b9f5-820cd2207101", + "uuid": "13e18657-8919-44a2-9f1b-009922a1f4b2", "control-id": "rhel-09.411015", "description": "REPLACE_ME", "props": [ @@ -32019,7 +32019,7 @@ ] }, { - "uuid": "2764d4a0-f726-41bd-a98f-e82ebc48c30e", + "uuid": "8f6b918c-5485-463d-a580-c8a3c846ab3b", "control-id": "rhel-09.411020", "description": "REPLACE_ME", "props": [ @@ -32036,7 +32036,7 @@ ] }, { - "uuid": "358b06c3-c695-480b-9ae0-084ac1cd0d2f", + "uuid": "7e2d8d53-4274-4f27-91d0-def8d61bef31", "control-id": "rhel-09.411025", "description": "REPLACE_ME", "props": [ @@ -32053,7 +32053,7 @@ ] }, { - "uuid": "c3e5e907-5b9f-494f-9f5d-be40e61e8d92", + "uuid": "f586a939-fd1c-4221-a9fd-734924cd68cc", "control-id": "rhel-09.411030", "description": "REPLACE_ME", "props": [ @@ -32070,7 +32070,7 @@ ] }, { - "uuid": "bcf23f4d-3a1e-4347-9870-fecadaa98ad2", + "uuid": "24e3d011-981b-46dd-9c3c-718365c33955", "control-id": "rhel-09.411035", "description": "REPLACE_ME", "props": [ @@ -32087,7 +32087,7 @@ ] }, { - "uuid": "f88384b4-0036-4067-8acd-58fc96222668", + "uuid": "82e1f14f-4e13-4db1-b0a3-7d0641e3ee34", "control-id": "rhel-09.411040", "description": "REPLACE_ME", "props": [ @@ -32104,7 +32104,7 @@ ] }, { - "uuid": "e43b7cf4-81df-4dd9-b581-99cc16c85b40", + "uuid": "3aaa9a07-f718-4866-b2d9-da9f184e6caa", "control-id": "rhel-09.411045", "description": "REPLACE_ME", "props": [ @@ -32121,7 +32121,7 @@ ] }, { - "uuid": "23757f6b-4b0f-4bc2-b3da-94ad25f7145f", + "uuid": "e63d74ab-18b5-482c-ae1d-96ce11b19010", "control-id": "rhel-09.411050", "description": "REPLACE_ME", "props": [ @@ -32138,7 +32138,7 @@ ] }, { - "uuid": "b970d521-afa9-44b2-a548-b0445da314a2", + "uuid": "e9553c22-e435-4ac0-9a55-ccb4fa8f009e", "control-id": "rhel-09.411055", "description": "REPLACE_ME", "props": [ @@ -32155,7 +32155,7 @@ ] }, { - "uuid": "5b578a5b-4809-4b58-a54d-3370ea098057", + "uuid": "c4123fdd-2d98-4f83-a412-46db1ee1c353", "control-id": "rhel-09.411060", "description": "REPLACE_ME", "props": [ @@ -32172,7 +32172,7 @@ ] }, { - "uuid": "8ecbb696-1b5e-4739-9571-6c1ba87e2cbd", + "uuid": "a36ec61e-ec12-49f9-bee1-80a7780bb98f", "control-id": "rhel-09.411065", "description": "REPLACE_ME", "props": [ @@ -32189,7 +32189,7 @@ ] }, { - "uuid": "c1359d05-26b2-4be8-8b8a-99bb99f2a1f3", + "uuid": "45fa72dd-0ca5-4a30-9ecc-b09ddf92e37e", "control-id": "rhel-09.411070", "description": "REPLACE_ME", "props": [ @@ -32206,7 +32206,7 @@ ] }, { - "uuid": "f90ed131-5662-4747-99d5-c9584bcab3ce", + "uuid": "9ce43712-4d85-4b84-acd1-f74002998000", "control-id": "rhel-09.411075", "description": "REPLACE_ME", "props": [ @@ -32223,7 +32223,7 @@ ] }, { - "uuid": "00027d3f-2a87-49a5-a9b4-b4cda5d88299", + "uuid": "8fa1bc09-0d47-42f6-a601-7ece248ff15e", "control-id": "rhel-09.411080", "description": "REPLACE_ME", "props": [ @@ -32240,7 +32240,7 @@ ] }, { - "uuid": "aa5a5b79-63a5-4773-8af0-d1a82245604c", + "uuid": "43898db8-45c8-4e02-8e4c-24baddeb484b", "control-id": "rhel-09.411085", "description": "REPLACE_ME", "props": [ @@ -32257,7 +32257,7 @@ ] }, { - "uuid": "2603c4d9-ca1b-4319-82b7-bf309079dab1", + "uuid": "cffec8f5-6a28-4b65-a4e9-e6dc6e7653f6", "control-id": "rhel-09.411090", "description": "REPLACE_ME", "props": [ @@ -32274,7 +32274,7 @@ ] }, { - "uuid": "1ec217cd-c187-412b-93be-353dc9e19868", + "uuid": "1012ef20-9e15-4c34-a1bb-11b06284ce2b", "control-id": "rhel-09.411095", "description": "REPLACE_ME", "props": [ @@ -32291,7 +32291,7 @@ ] }, { - "uuid": "961a63f5-5ecf-414d-8c34-45c377ecca58", + "uuid": "fc7c578e-40b5-4fca-81fe-b6f0d95fdbc6", "control-id": "rhel-09.411105", "description": "REPLACE_ME", "props": [ @@ -32308,7 +32308,7 @@ ] }, { - "uuid": "e086cc22-1908-4f17-bdd4-5c10d3ddd8ea", + "uuid": "f381c390-5554-4d16-8a7e-8e3904c2b313", "control-id": "rhel-09.411110", "description": "REPLACE_ME", "props": [ @@ -32325,7 +32325,7 @@ ] }, { - "uuid": "ea16f9e2-f9a7-43d9-9cb8-31a2315ea23c", + "uuid": "781713ff-d9d5-44a6-b6e0-0654e9777bee", "control-id": "rhel-09.411115", "description": "REPLACE_ME", "props": [ @@ -32342,7 +32342,7 @@ ] }, { - "uuid": "d0de92d3-f528-402e-aab7-2f1d06b30c40", + "uuid": "c75f2231-4800-4762-8793-454e68b49e0c", "control-id": "rhel-09.412035", "description": "REPLACE_ME", "props": [ @@ -32359,7 +32359,7 @@ ] }, { - "uuid": "d3a16dbd-f204-4f23-b28c-828bec319087", + "uuid": "a8f54bbe-364c-4f31-8d42-d9dc2ec98180", "control-id": "rhel-09.412045", "description": "REPLACE_ME", "props": [ @@ -32376,7 +32376,7 @@ ] }, { - "uuid": "74031824-442a-4f7e-b4d2-5037443c3fd1", + "uuid": "64268947-c77f-4db0-8170-2b22f9c2d552", "control-id": "rhel-09.412050", "description": "REPLACE_ME", "props": [ @@ -32393,7 +32393,7 @@ ] }, { - "uuid": "58ab5d84-5484-4edc-afff-cae10b56da69", + "uuid": "e37fc5e2-48cd-4761-aec9-15bcc5d81c7c", "control-id": "rhel-09.412055", "description": "REPLACE_ME", "props": [ @@ -32410,7 +32410,7 @@ ] }, { - "uuid": "1b728e3b-f852-412a-aba6-f26da5c0d7b2", + "uuid": "6b70aa6d-3ab0-4ae5-8dc5-65eaff66b9b5", "control-id": "rhel-09.412060", "description": "REPLACE_ME", "props": [ @@ -32427,7 +32427,7 @@ ] }, { - "uuid": "9840c26d-eb2b-477a-b8df-089a36e32f97", + "uuid": "c4250437-d763-45fe-9a7c-24b31ec7670d", "control-id": "rhel-09.412065", "description": "REPLACE_ME", "props": [ @@ -32444,7 +32444,7 @@ ] }, { - "uuid": "1bfb9c2e-2355-44dd-ae7e-355ed3cd66c7", + "uuid": "ce422e53-e625-431f-9e81-ab851f5ce386", "control-id": "rhel-09.412070", "description": "REPLACE_ME", "props": [ @@ -32461,7 +32461,7 @@ ] }, { - "uuid": "dc374424-7cc9-4590-bb6f-7a999f2298be", + "uuid": "a8c2c217-3db6-4aa6-ba59-96dc99dedf9b", "control-id": "rhel-09.412080", "description": "REPLACE_ME", "props": [ @@ -32478,7 +32478,7 @@ ] }, { - "uuid": "967c251f-f3d6-404f-9921-bdced51799f0", + "uuid": "433c4f52-ffb4-4da1-93e1-cfc5a8b74d3a", "control-id": "rhel-09.431015", "description": "REPLACE_ME", "props": [ @@ -32495,7 +32495,7 @@ ] }, { - "uuid": "9d745470-11fc-4cac-9333-cb7054976e7a", + "uuid": "c58fddc8-045c-45b0-a21e-d654972fccd9", "control-id": "rhel-09.431020", "description": "REPLACE_ME", "props": [ @@ -32512,7 +32512,7 @@ ] }, { - "uuid": "fca0c890-c74a-4825-9fcf-6797254d6d9c", + "uuid": "e0613f20-024d-4884-924a-c1343f88c0e2", "control-id": "rhel-09.431025", "description": "REPLACE_ME", "props": [ @@ -32529,7 +32529,7 @@ ] }, { - "uuid": "d3e020e6-eb1d-4ebb-858e-9a99756437b3", + "uuid": "4fe18c3d-5aca-4280-b934-cda2dec31215", "control-id": "rhel-09.431030", "description": "REPLACE_ME", "props": [ @@ -32546,7 +32546,7 @@ ] }, { - "uuid": "cb988e46-4c30-4887-8b2d-1be64abf5c18", + "uuid": "680d7e9c-80b7-4aa5-9855-dce42364ba99", "control-id": "rhel-09.432010", "description": "REPLACE_ME", "props": [ @@ -32563,7 +32563,7 @@ ] }, { - "uuid": "5ff120fc-99c8-4802-bebb-1f7ff17e3f01", + "uuid": "56941318-cc15-42a7-b768-cfb80765277e", "control-id": "rhel-09.432015", "description": "REPLACE_ME", "props": [ @@ -32580,7 +32580,7 @@ ] }, { - "uuid": "bdfe46f4-301b-43ee-84ac-f5afaea0165f", + "uuid": "eede3329-5389-49b8-958d-7dbdff979dee", "control-id": "rhel-09.432020", "description": "REPLACE_ME", "props": [ @@ -32597,7 +32597,7 @@ ] }, { - "uuid": "488686f0-ecdf-4c67-bcbd-e840d01b6b24", + "uuid": "4aaaa7f3-4f74-4bed-9c35-f232ef8f0150", "control-id": "rhel-09.432025", "description": "REPLACE_ME", "props": [ @@ -32614,7 +32614,7 @@ ] }, { - "uuid": "2dadbc6d-dd43-4785-8a75-32010f11b750", + "uuid": "613756bc-3719-4d60-8314-27caa2c06a6c", "control-id": "rhel-09.432030", "description": "REPLACE_ME", "props": [ @@ -32631,7 +32631,7 @@ ] }, { - "uuid": "8331c876-3d31-4f5b-91ec-5bfd77600451", + "uuid": "c0c744bf-5164-4afc-935c-1a9cc724db04", "control-id": "rhel-09.432035", "description": "REPLACE_ME", "props": [ @@ -32648,7 +32648,7 @@ ] }, { - "uuid": "14865367-2289-4c9a-b9e5-04fe1e7407ba", + "uuid": "dfe50f5d-083e-4502-8b36-5c6f666a48c1", "control-id": "rhel-09.433010", "description": "REPLACE_ME", "props": [ @@ -32665,7 +32665,7 @@ ] }, { - "uuid": "90e208ff-2bc6-4d61-be37-cbbd651fa4bc", + "uuid": "0b3b217a-00be-4f6b-a861-121a76632ac5", "control-id": "rhel-09.433015", "description": "REPLACE_ME", "props": [ @@ -32682,7 +32682,7 @@ ] }, { - "uuid": "dc168d5a-0bce-4190-b807-825cae2466b4", + "uuid": "81908219-3db6-450e-a85a-f40d279f5893", "control-id": "rhel-09.433016", "description": "REPLACE_ME", "props": [ @@ -32699,7 +32699,7 @@ ] }, { - "uuid": "8e880d18-78de-4fa9-b7f8-269070acc325", + "uuid": "a975a723-a63e-405b-b969-3ed81d7ad21e", "control-id": "rhel-09.611010", "description": "REPLACE_ME", "props": [ @@ -32716,7 +32716,7 @@ ] }, { - "uuid": "c5dc6539-2397-4013-8e61-a666a10e5f9c", + "uuid": "24450685-59cc-4711-8a2a-b48c712633aa", "control-id": "rhel-09.611030", "description": "REPLACE_ME", "props": [ @@ -32733,7 +32733,7 @@ ] }, { - "uuid": "c4c56959-ea15-4e35-9c77-954dcc43ceed", + "uuid": "ff2bc757-4ca4-4201-a41e-4e119cca190b", "control-id": "rhel-09.611035", "description": "REPLACE_ME", "props": [ @@ -32750,7 +32750,7 @@ ] }, { - "uuid": "6967808a-72a8-4a3f-afd0-162b0043da0b", + "uuid": "0fb0c6d0-a1e5-47d5-8f3a-e35336111d59", "control-id": "rhel-09.611040", "description": "REPLACE_ME", "props": [ @@ -32767,7 +32767,7 @@ ] }, { - "uuid": "4d0dacbe-88b4-430b-8edb-5706ad14d391", + "uuid": "21058a5f-b9f4-4a90-b697-62f8f2fbf3ef", "control-id": "rhel-09.611045", "description": "REPLACE_ME", "props": [ @@ -32784,7 +32784,7 @@ ] }, { - "uuid": "7dc30176-e109-46e0-aa6c-c366ce256e26", + "uuid": "f78f6c01-9f14-4901-aef0-40b41ce06ecd", "control-id": "rhel-09.611050", "description": "REPLACE_ME", "props": [ @@ -32801,7 +32801,7 @@ ] }, { - "uuid": "59c33166-8b4c-4748-9717-e60ccab4c958", + "uuid": "9b958f9b-ad59-4367-acc5-20da557c37e0", "control-id": "rhel-09.611055", "description": "REPLACE_ME", "props": [ @@ -32818,7 +32818,7 @@ ] }, { - "uuid": "d17b30f0-0787-4ecf-b31f-c9d48e17aceb", + "uuid": "59e0e4ca-6e96-47bf-bd11-f3c5d7bed948", "control-id": "rhel-09.611060", "description": "REPLACE_ME", "props": [ @@ -32835,7 +32835,7 @@ ] }, { - "uuid": "e5559a0c-8008-4e83-be72-d32bb4ac6ea1", + "uuid": "7d9d5e13-7b52-4ecd-a115-b2c1313c9064", "control-id": "rhel-09.611065", "description": "REPLACE_ME", "props": [ @@ -32852,7 +32852,7 @@ ] }, { - "uuid": "a51217db-dbac-48a3-9f30-4a99b317308c", + "uuid": "3215611b-ebbc-4316-b2c0-b16d3dd436a3", "control-id": "rhel-09.611070", "description": "REPLACE_ME", "props": [ @@ -32869,7 +32869,7 @@ ] }, { - "uuid": "1ea0a9f9-ef11-4355-8725-859f79916512", + "uuid": "499ab896-5138-490e-bd56-b444ff28f595", "control-id": "rhel-09.611075", "description": "REPLACE_ME", "props": [ @@ -32886,7 +32886,7 @@ ] }, { - "uuid": "1b12b6b5-b503-456f-8208-3d26939334c7", + "uuid": "8bf7710e-6c87-4317-8dd4-e4006f8356a5", "control-id": "rhel-09.611080", "description": "REPLACE_ME", "props": [ @@ -32903,7 +32903,7 @@ ] }, { - "uuid": "c92e437d-f0f4-4331-b0e7-11f5d5b87627", + "uuid": "4ef307c5-75ef-4986-9514-d7a61c6a58ce", "control-id": "rhel-09.611085", "description": "REPLACE_ME", "props": [ @@ -32920,7 +32920,7 @@ ] }, { - "uuid": "cfaecf78-cf1e-413a-9ccc-07a0c13797ef", + "uuid": "650815bf-7264-4a85-8d2f-c0f77fc7cce9", "control-id": "rhel-09.611090", "description": "REPLACE_ME", "props": [ @@ -32937,7 +32937,7 @@ ] }, { - "uuid": "cc254655-33af-474a-a19d-c7360898c141", + "uuid": "0c2ae4e4-a651-434f-b834-d8a586189b0e", "control-id": "rhel-09.611100", "description": "REPLACE_ME", "props": [ @@ -32954,7 +32954,7 @@ ] }, { - "uuid": "b8ced46f-d6f5-4f50-9e03-a1628aa3b2f1", + "uuid": "88848cc0-d0c1-46dc-aea5-b87b018dfefe", "control-id": "rhel-09.611105", "description": "REPLACE_ME", "props": [ @@ -32971,7 +32971,7 @@ ] }, { - "uuid": "fdb137e0-7be2-4064-8347-fee8cd7feb07", + "uuid": "d5094cc7-efc2-4500-bfaf-172114a40935", "control-id": "rhel-09.611110", "description": "REPLACE_ME", "props": [ @@ -32988,7 +32988,7 @@ ] }, { - "uuid": "a27ae896-f304-464f-8b83-b208ed6e0403", + "uuid": "dc5d1ff1-3ca5-4f67-8f44-cbd8569ebba0", "control-id": "rhel-09.611115", "description": "REPLACE_ME", "props": [ @@ -33005,7 +33005,7 @@ ] }, { - "uuid": "f7034c67-2884-4a01-a5d2-37557dac3ffe", + "uuid": "49c49a33-ca84-4c2e-8b29-50cdff2dc022", "control-id": "rhel-09.611120", "description": "REPLACE_ME", "props": [ @@ -33022,7 +33022,7 @@ ] }, { - "uuid": "21b313dd-54ce-4883-99a8-a1f8f3de4674", + "uuid": "f68bc0d2-2163-4c3d-afcd-b6e2db8c7012", "control-id": "rhel-09.611125", "description": "REPLACE_ME", "props": [ @@ -33039,7 +33039,7 @@ ] }, { - "uuid": "19d335ce-ffdd-4458-8055-f3a7040800d1", + "uuid": "f0fc9ecc-dbfc-43f6-bd31-14e21c89066a", "control-id": "rhel-09.611130", "description": "REPLACE_ME", "props": [ @@ -33056,7 +33056,7 @@ ] }, { - "uuid": "07bfa2c3-d02c-428e-84cb-6e3ad0e27036", + "uuid": "e6eea8c9-0ce3-4d1c-99fb-8b998d59de77", "control-id": "rhel-09.611135", "description": "REPLACE_ME", "props": [ @@ -33073,7 +33073,7 @@ ] }, { - "uuid": "c903fbc0-0291-4473-aea3-24a447929c60", + "uuid": "c05c4773-587c-4da2-8d01-2b6c3f60ab37", "control-id": "rhel-09.611140", "description": "REPLACE_ME", "props": [ @@ -33090,7 +33090,7 @@ ] }, { - "uuid": "26a061cd-de03-4b4f-894b-2fc5c438026f", + "uuid": "a586d155-ebc4-49cd-9187-1057e9fb6b18", "control-id": "rhel-09.611145", "description": "REPLACE_ME", "props": [ @@ -33107,7 +33107,7 @@ ] }, { - "uuid": "6773e47e-bbb1-4bfd-935e-24a41a068363", + "uuid": "6a55403f-ba60-4a14-9f68-d83a12f093f5", "control-id": "rhel-09.611155", "description": "REPLACE_ME", "props": [ @@ -33124,7 +33124,7 @@ ] }, { - "uuid": "494a858d-354e-4ad2-ba6a-aef49fdf1e50", + "uuid": "a998acf7-aaa5-46b2-b13b-e4e537079678", "control-id": "rhel-09.611160", "description": "REPLACE_ME", "props": [ @@ -33141,7 +33141,7 @@ ] }, { - "uuid": "fd8b7acf-c687-4716-a0a0-380254317329", + "uuid": "4b277c25-12ec-4d94-a85b-dbced001bf70", "control-id": "rhel-09.611165", "description": "REPLACE_ME", "props": [ @@ -33158,7 +33158,7 @@ ] }, { - "uuid": "5c50fcb1-123f-46f3-bf08-d791b97c42e7", + "uuid": "94cd5f3e-d9e9-44ef-9b30-a0048b9dbcba", "control-id": "rhel-09.611170", "description": "REPLACE_ME", "props": [ @@ -33175,7 +33175,7 @@ ] }, { - "uuid": "a9d01cd8-d9e1-43f8-8588-49e5139d6d8e", + "uuid": "72760e54-850f-4c41-81a7-81d26f674fd0", "control-id": "rhel-09.611175", "description": "REPLACE_ME", "props": [ @@ -33192,7 +33192,7 @@ ] }, { - "uuid": "bacbcea1-7384-42bb-8ae3-4f6ab4a705fd", + "uuid": "119279bc-c6e4-42f6-943e-d2e783fc2975", "control-id": "rhel-09.611180", "description": "REPLACE_ME", "props": [ @@ -33209,7 +33209,7 @@ ] }, { - "uuid": "5ff5800f-b150-4660-b2fe-21184675ad1f", + "uuid": "38d6ce99-cc4a-47fd-b5a1-41731108fab5", "control-id": "rhel-09.611185", "description": "REPLACE_ME", "props": [ @@ -33226,7 +33226,7 @@ ] }, { - "uuid": "f65c1a3e-fe9b-477d-958f-cd316a219210", + "uuid": "4813c860-8f8c-426c-947a-f45bdc066289", "control-id": "rhel-09.611190", "description": "REPLACE_ME", "props": [ @@ -33243,7 +33243,7 @@ ] }, { - "uuid": "e70e9da0-1631-42d3-b2a8-1794864ef906", + "uuid": "3803dfae-4c3b-4a0a-9e91-28ded7511a96", "control-id": "rhel-09.611195", "description": "REPLACE_ME", "props": [ @@ -33260,7 +33260,7 @@ ] }, { - "uuid": "daf20fef-2031-427c-90e5-2e0daff69330", + "uuid": "cd035326-bfe1-4f7b-b37e-f959d52e525d", "control-id": "rhel-09.611200", "description": "REPLACE_ME", "props": [ @@ -33277,7 +33277,7 @@ ] }, { - "uuid": "8bd6cbaf-2d3f-46f6-9ea5-52dd1648dc5f", + "uuid": "95e21edc-ae44-4363-9ef8-07116175ec8d", "control-id": "rhel-09.631010", "description": "REPLACE_ME", "props": [ @@ -33294,7 +33294,7 @@ ] }, { - "uuid": "6a2494e3-a090-4a17-abf3-4dfa61732482", + "uuid": "6de5b906-7976-492c-b4ed-8d6f91c5fea3", "control-id": "rhel-09.631015", "description": "REPLACE_ME", "props": [ @@ -33311,7 +33311,7 @@ ] }, { - "uuid": "edf27236-be4e-4966-bb27-6ba5ecebd5f4", + "uuid": "e7f40a27-a7c8-470c-98c2-fa6cdb761365", "control-id": "rhel-09.631020", "description": "REPLACE_ME", "props": [ @@ -33328,7 +33328,7 @@ ] }, { - "uuid": "984fc07a-95b6-4f97-8544-1bb1f10f93ff", + "uuid": "3d62cd14-0850-4f33-86c6-87557cc1a2ef", "control-id": "rhel-09.651010", "description": "REPLACE_ME", "props": [ @@ -33350,7 +33350,7 @@ ] }, { - "uuid": "47566a98-22f4-4baf-8128-37d9add63e85", + "uuid": "8035ae47-8cc1-4a1d-9993-d56e15217970", "control-id": "rhel-09.651015", "description": "REPLACE_ME", "props": [ @@ -33372,7 +33372,7 @@ ] }, { - "uuid": "639d7b84-6e60-429a-8cbe-067f0dfa5669", + "uuid": "70229a48-6e74-41da-8e46-a4106747289e", "control-id": "rhel-09.651020", "description": "REPLACE_ME", "props": [ @@ -33389,7 +33389,7 @@ ] }, { - "uuid": "a15d5b3b-1c74-4362-9052-4574c160c7fc", + "uuid": "e79e74ea-05b4-4446-a8c7-c235d6e991f1", "control-id": "rhel-09.651025", "description": "REPLACE_ME", "props": [ @@ -33406,7 +33406,7 @@ ] }, { - "uuid": "25d15271-4298-44c3-a11d-59253f6b8c47", + "uuid": "06d8a4cd-80ee-4286-bbee-a7ea1c62b58c", "control-id": "rhel-09.652010", "description": "REPLACE_ME", "props": [ @@ -33423,7 +33423,7 @@ ] }, { - "uuid": "a8341878-eea3-4b9b-b391-00b38532e8cc", + "uuid": "17703e72-f1ec-409d-a540-52ce7c56e466", "control-id": "rhel-09.652015", "description": "REPLACE_ME", "props": [ @@ -33440,7 +33440,7 @@ ] }, { - "uuid": "d8c32512-5312-458d-9b70-3edfe666fa92", + "uuid": "dafa3ad8-87cb-4bee-8fdd-be03e6c355ab", "control-id": "rhel-09.652020", "description": "REPLACE_ME", "props": [ @@ -33457,7 +33457,7 @@ ] }, { - "uuid": "08baf521-33e4-4d49-97dd-f469a21d5b40", + "uuid": "56cd5ec6-62c5-4320-9d6a-bfb644c3a1fe", "control-id": "rhel-09.652025", "description": "REPLACE_ME", "props": [ @@ -33474,7 +33474,7 @@ ] }, { - "uuid": "e0d221ce-876c-4016-8ec3-73050b584da4", + "uuid": "0db68e03-ef54-4c36-8df1-2760bcbaf1ad", "control-id": "rhel-09.652030", "description": "REPLACE_ME", "props": [ @@ -33491,7 +33491,7 @@ ] }, { - "uuid": "151af561-1f2d-4fb3-b022-7437233542b2", + "uuid": "758925f9-36bb-46fd-a507-baf535b1d19c", "control-id": "rhel-09.652040", "description": "REPLACE_ME", "props": [ @@ -33508,7 +33508,7 @@ ] }, { - "uuid": "ee57e94a-43b4-464c-896e-c5f91f50f499", + "uuid": "93979e5f-2bb6-4544-9f09-1aaa5989fd79", "control-id": "rhel-09.652045", "description": "REPLACE_ME", "props": [ @@ -33525,7 +33525,7 @@ ] }, { - "uuid": "e2111e02-8250-4925-a519-634f491d0e1b", + "uuid": "5d24c0cf-3cc3-46f3-8ed6-7c9e1fb3c417", "control-id": "rhel-09.652050", "description": "REPLACE_ME", "props": [ @@ -33542,7 +33542,7 @@ ] }, { - "uuid": "912ea80e-19bf-44c8-8679-20940c4cb025", + "uuid": "7acc76d6-0227-4643-94c6-a2aea7f21a4c", "control-id": "rhel-09.652055", "description": "REPLACE_ME", "props": [ @@ -33559,7 +33559,7 @@ ] }, { - "uuid": "b1f6fb90-92b1-4adc-b4af-8da71c1cc39a", + "uuid": "135cf597-a2f9-4dc7-86bb-57270fa63c99", "control-id": "rhel-09.652060", "description": "REPLACE_ME", "props": [ @@ -33576,7 +33576,7 @@ ] }, { - "uuid": "5609d00b-ea08-475a-91b7-34566d895563", + "uuid": "c311e555-cbcb-4bd7-b47e-bdf91fab6e59", "control-id": "rhel-09.653010", "description": "REPLACE_ME", "props": [ @@ -33593,7 +33593,7 @@ ] }, { - "uuid": "0b75a57b-41dc-4674-bc05-748f64ec8cae", + "uuid": "80c89c06-a818-4492-b5e1-b98a31995262", "control-id": "rhel-09.653015", "description": "REPLACE_ME", "props": [ @@ -33610,7 +33610,7 @@ ] }, { - "uuid": "0597882f-64e8-4386-9979-004c6d76e8e1", + "uuid": "5f1dd9ce-36f4-43de-a013-c80973f11eb8", "control-id": "rhel-09.653020", "description": "REPLACE_ME", "props": [ @@ -33627,7 +33627,7 @@ ] }, { - "uuid": "6a9152af-4221-46a8-9bd0-06f02937a4c9", + "uuid": "eaaf21cb-d5a4-4c16-9bd0-09baa2693759", "control-id": "rhel-09.653025", "description": "REPLACE_ME", "props": [ @@ -33644,7 +33644,7 @@ ] }, { - "uuid": "c9cc686c-6f8a-4d51-8603-05fe87c4e6cb", + "uuid": "9360160b-1192-403a-aa68-a9664c215669", "control-id": "rhel-09.653030", "description": "REPLACE_ME", "props": [ @@ -33661,7 +33661,7 @@ ] }, { - "uuid": "b331a989-5c13-43d6-b0f5-2df9b3d74f3c", + "uuid": "4d85c3e7-1484-49a6-9ac6-7434d7a89213", "control-id": "rhel-09.653035", "description": "REPLACE_ME", "props": [ @@ -33678,7 +33678,7 @@ ] }, { - "uuid": "fbda97f6-e19f-45d8-96fc-8c2b865c0e85", + "uuid": "02f4d9bf-7171-4170-8ee8-3e87cde1d4d1", "control-id": "rhel-09.653040", "description": "REPLACE_ME", "props": [ @@ -33695,7 +33695,7 @@ ] }, { - "uuid": "9f65f946-8d60-497a-9cbd-3b11920051c3", + "uuid": "f345e243-d202-4421-9127-905f094c7758", "control-id": "rhel-09.653045", "description": "REPLACE_ME", "props": [ @@ -33712,7 +33712,7 @@ ] }, { - "uuid": "0e06506f-274a-49d0-adab-4f46cfa5ef49", + "uuid": "c7f86fb6-3ee2-48a0-b94e-4c3922680b78", "control-id": "rhel-09.653050", "description": "REPLACE_ME", "props": [ @@ -33729,7 +33729,7 @@ ] }, { - "uuid": "f53eb820-8542-415c-9561-68b289cd963a", + "uuid": "7eec886a-a6f2-4f4f-9bbe-334a93b0fd25", "control-id": "rhel-09.653055", "description": "REPLACE_ME", "props": [ @@ -33746,7 +33746,7 @@ ] }, { - "uuid": "68faa88c-0272-42a3-9c64-064eac3bad47", + "uuid": "33366919-d79d-4551-9ce3-d32a0121a2e1", "control-id": "rhel-09.653060", "description": "REPLACE_ME", "props": [ @@ -33763,7 +33763,7 @@ ] }, { - "uuid": "115511ec-ef66-49e1-9f83-b7200badad43", + "uuid": "6ff1d55f-bb5a-46c2-8ada-e769e344dd2a", "control-id": "rhel-09.653065", "description": "REPLACE_ME", "props": [ @@ -33780,7 +33780,7 @@ ] }, { - "uuid": "eb7e9fb8-c0d2-4f28-b964-d11cd638c2aa", + "uuid": "105adab8-db61-4f53-bc5c-040e97d8353c", "control-id": "rhel-09.653070", "description": "REPLACE_ME", "props": [ @@ -33797,7 +33797,7 @@ ] }, { - "uuid": "cac4be6a-efa8-4780-8671-05787d8f2df0", + "uuid": "cf26cbe9-1fb6-4f37-af0c-298d0311c430", "control-id": "rhel-09.653075", "description": "REPLACE_ME", "props": [ @@ -33814,7 +33814,7 @@ ] }, { - "uuid": "f916867f-505f-4c74-89ac-a67cb5638159", + "uuid": "bd380877-66c3-4bde-b142-6d71d02b9b8a", "control-id": "rhel-09.653080", "description": "REPLACE_ME", "props": [ @@ -33831,7 +33831,7 @@ ] }, { - "uuid": "9ef7a676-d73a-454b-9d91-b2c219a36be5", + "uuid": "acb5dfc4-96c0-48cb-aeb7-81306273fef2", "control-id": "rhel-09.653085", "description": "REPLACE_ME", "props": [ @@ -33848,7 +33848,7 @@ ] }, { - "uuid": "c5d8133e-ac53-477f-9a28-896e5ae2cfd5", + "uuid": "98fad999-f86f-4154-aeed-eba66da01d79", "control-id": "rhel-09.653090", "description": "REPLACE_ME", "props": [ @@ -33865,7 +33865,7 @@ ] }, { - "uuid": "c9e3bad6-6617-4bf6-a10b-46d3b27a83bd", + "uuid": "0b0c5035-7ce3-4226-96bc-0e1eacb1b82c", "control-id": "rhel-09.653095", "description": "REPLACE_ME", "props": [ @@ -33882,7 +33882,7 @@ ] }, { - "uuid": "a28ca266-ce8a-4e3b-8f1e-1638bf68480e", + "uuid": "aeb71aae-d1e7-42f1-8aae-a5cc8d3c79d5", "control-id": "rhel-09.653100", "description": "REPLACE_ME", "props": [ @@ -33899,7 +33899,7 @@ ] }, { - "uuid": "687e72bb-64d2-42de-a351-343ce7b928c7", + "uuid": "9abaa78b-ae0b-468b-8222-c26bec91e593", "control-id": "rhel-09.653105", "description": "REPLACE_ME", "props": [ @@ -33916,7 +33916,7 @@ ] }, { - "uuid": "d265f710-41b1-477c-8cc1-536bb2db9c17", + "uuid": "8e4abdc0-c2d5-4d25-9c79-29cafa2b060e", "control-id": "rhel-09.653110", "description": "REPLACE_ME", "props": [ @@ -33933,7 +33933,7 @@ ] }, { - "uuid": "3eb7e0be-66f3-4d11-9d06-0857333ffd33", + "uuid": "bbb46b3e-32bd-4dd4-94ad-99b6d124d197", "control-id": "rhel-09.653115", "description": "REPLACE_ME", "props": [ @@ -33950,7 +33950,7 @@ ] }, { - "uuid": "9b93e007-7e0f-47f9-80cc-1f4ce8149ddd", + "uuid": "108e7efe-c9c0-40b2-baa4-434509daa446", "control-id": "rhel-09.653125", "description": "REPLACE_ME", "props": [ @@ -33967,7 +33967,7 @@ ] }, { - "uuid": "cc537503-6414-4775-a1d7-1db149cfeeca", + "uuid": "ec86b6c9-2db2-4872-ba23-eb687416011f", "control-id": "rhel-09.653130", "description": "REPLACE_ME", "props": [ @@ -33984,7 +33984,7 @@ ] }, { - "uuid": "017dd977-1086-428f-add6-84cf11365ca9", + "uuid": "b1d954e5-3151-4f79-aee1-efcd68f778e9", "control-id": "rhel-09.654010", "description": "REPLACE_ME", "props": [ @@ -34001,7 +34001,7 @@ ] }, { - "uuid": "489e3c02-cf66-450f-b693-c310bd612483", + "uuid": "c6f16be1-d723-4f98-8931-6f96cf4af143", "control-id": "rhel-09.654015", "description": "REPLACE_ME", "props": [ @@ -34028,7 +34028,7 @@ ] }, { - "uuid": "f544f664-9c28-4aa7-8781-b8c3a7faada3", + "uuid": "fef7dba2-8fc4-4a42-ba9d-ad1d6c5890e3", "control-id": "rhel-09.654020", "description": "REPLACE_ME", "props": [ @@ -34060,7 +34060,7 @@ ] }, { - "uuid": "049ca2a1-8564-4973-bccd-995414ce0eb6", + "uuid": "34f2ba42-2241-49db-be43-5bc569302171", "control-id": "rhel-09.654025", "description": "REPLACE_ME", "props": [ @@ -34102,7 +34102,7 @@ ] }, { - "uuid": "a61ae546-fa05-4304-a8d6-ceb1991f6a77", + "uuid": "8da9044f-edac-4fdd-8397-5389a7ce33ec", "control-id": "rhel-09.654030", "description": "REPLACE_ME", "props": [ @@ -34119,7 +34119,7 @@ ] }, { - "uuid": "798bc66a-e76e-499f-83f4-3bf2a63d3f1c", + "uuid": "7697a766-55b1-445a-a141-e731c8059407", "control-id": "rhel-09.654035", "description": "REPLACE_ME", "props": [ @@ -34136,7 +34136,7 @@ ] }, { - "uuid": "4df399d7-8dcb-44ec-ae6e-1dc372ef2634", + "uuid": "af1ae6ea-7037-4fb2-a4ae-7f4eb95d5625", "control-id": "rhel-09.654040", "description": "REPLACE_ME", "props": [ @@ -34153,7 +34153,7 @@ ] }, { - "uuid": "43966118-1b52-45df-9b29-e2c0d5850585", + "uuid": "0a1764e6-e206-489f-b676-13d258dcb8b6", "control-id": "rhel-09.654045", "description": "REPLACE_ME", "props": [ @@ -34170,7 +34170,7 @@ ] }, { - "uuid": "f2bad939-be52-486c-a012-1298b5616785", + "uuid": "907cdc14-84c7-42e9-a8a7-c99ce113ab75", "control-id": "rhel-09.654050", "description": "REPLACE_ME", "props": [ @@ -34187,7 +34187,7 @@ ] }, { - "uuid": "9f6f98de-45cc-446b-b75a-fa8872cd77e6", + "uuid": "52479107-2c4a-429a-ac92-fb3d27f04a0c", "control-id": "rhel-09.654055", "description": "REPLACE_ME", "props": [ @@ -34204,7 +34204,7 @@ ] }, { - "uuid": "48385eb4-1153-44f0-90d3-0e2718c759ad", + "uuid": "4109e3bc-3b10-4975-b573-caeef42f3fcc", "control-id": "rhel-09.654060", "description": "REPLACE_ME", "props": [ @@ -34221,7 +34221,7 @@ ] }, { - "uuid": "c28c345a-d3c2-4c03-b0c8-9157bb141fa9", + "uuid": "9282606a-8d36-460c-9756-e7ccd1eb9665", "control-id": "rhel-09.654065", "description": "REPLACE_ME", "props": [ @@ -34258,7 +34258,7 @@ ] }, { - "uuid": "50efb445-4815-455a-85d3-fc1be3992270", + "uuid": "b967bf92-86cd-4266-a53c-c614c5664002", "control-id": "rhel-09.654070", "description": "REPLACE_ME", "props": [ @@ -34300,7 +34300,7 @@ ] }, { - "uuid": "440c9763-4db9-4d72-96f3-e0300e89b437", + "uuid": "3e1f2afc-bc6b-484c-b9b4-9e0a76f1f19b", "control-id": "rhel-09.654075", "description": "REPLACE_ME", "props": [ @@ -34317,7 +34317,7 @@ ] }, { - "uuid": "c193d136-e930-445b-8bde-e66f68e3acb7", + "uuid": "0dbe1a06-86b4-4e18-a616-cf089fde1d5e", "control-id": "rhel-09.654080", "description": "REPLACE_ME", "props": [ @@ -34339,7 +34339,7 @@ ] }, { - "uuid": "039df959-600c-4cd6-972d-9d952c57203d", + "uuid": "f91af20d-edf1-4469-93d4-9186bb5b4d1f", "control-id": "rhel-09.654085", "description": "REPLACE_ME", "props": [ @@ -34356,7 +34356,7 @@ ] }, { - "uuid": "5bc375cd-7023-44f2-9c20-2baefd33e2e1", + "uuid": "d24f96f6-6411-4e1a-94cb-b1fc2e107dd6", "control-id": "rhel-09.654090", "description": "REPLACE_ME", "props": [ @@ -34373,7 +34373,7 @@ ] }, { - "uuid": "b7cd89f4-f1e7-404e-9e00-ca8d2b112fee", + "uuid": "7801114c-6992-4391-80ef-84ae4a334a8a", "control-id": "rhel-09.654095", "description": "REPLACE_ME", "props": [ @@ -34390,7 +34390,7 @@ ] }, { - "uuid": "6cbd7c3a-2ba9-4dd0-ae39-399bccae657e", + "uuid": "af273112-cdcd-42f5-a193-e4c6b7f2fc1f", "control-id": "rhel-09.654100", "description": "REPLACE_ME", "props": [ @@ -34407,7 +34407,7 @@ ] }, { - "uuid": "ed5ba6c1-1177-44ed-9a51-26d1c1e1b0c0", + "uuid": "9b6f2f30-85e3-4c4c-9a53-fedce2a1f1f7", "control-id": "rhel-09.654105", "description": "REPLACE_ME", "props": [ @@ -34424,7 +34424,7 @@ ] }, { - "uuid": "b6a1fb57-26bd-4ee3-bd89-9b23d541b0e2", + "uuid": "292c83f1-dfd4-4e11-8468-3e85e67db3d5", "control-id": "rhel-09.654110", "description": "REPLACE_ME", "props": [ @@ -34441,7 +34441,7 @@ ] }, { - "uuid": "cc4d8d7a-61a6-486d-b0f1-7f1b7ac10649", + "uuid": "c09b1a5b-8ea0-4f40-8304-048e1868ecd4", "control-id": "rhel-09.654115", "description": "REPLACE_ME", "props": [ @@ -34458,7 +34458,7 @@ ] }, { - "uuid": "3860cd30-5967-4039-9479-d856c3f71d65", + "uuid": "72255c36-9990-4c7a-b648-3681f9da91af", "control-id": "rhel-09.654120", "description": "REPLACE_ME", "props": [ @@ -34475,7 +34475,7 @@ ] }, { - "uuid": "a9fbf756-9cb5-495d-be5b-e9054d9d0e2a", + "uuid": "73d5bc1e-1ef3-4bec-bab1-a112c8996c0c", "control-id": "rhel-09.654125", "description": "REPLACE_ME", "props": [ @@ -34492,7 +34492,7 @@ ] }, { - "uuid": "559ab021-6e3b-4539-9089-69d8ff58edc9", + "uuid": "f1ee80e8-f96b-4daa-8c19-d24cee6f2d43", "control-id": "rhel-09.654130", "description": "REPLACE_ME", "props": [ @@ -34509,7 +34509,7 @@ ] }, { - "uuid": "a135aafa-961d-420a-872d-57c693864d17", + "uuid": "4b2d0eb3-e980-41ce-bc39-c8a5dc1bbf8c", "control-id": "rhel-09.654135", "description": "REPLACE_ME", "props": [ @@ -34526,7 +34526,7 @@ ] }, { - "uuid": "c2980463-83f0-4e48-a06b-93bb391a8907", + "uuid": "3ddc6949-b21d-4567-9d2e-05117177abeb", "control-id": "rhel-09.654140", "description": "REPLACE_ME", "props": [ @@ -34543,7 +34543,7 @@ ] }, { - "uuid": "97f8c71f-0431-4c94-a8f4-44aacf46b409", + "uuid": "69a6c992-23ae-4f79-885d-bfbf5a79a2b8", "control-id": "rhel-09.654145", "description": "REPLACE_ME", "props": [ @@ -34560,7 +34560,7 @@ ] }, { - "uuid": "d27b0142-c099-408e-80a4-af6ff73a17df", + "uuid": "fc06c065-edba-4d35-a708-1cdfde3a5f69", "control-id": "rhel-09.654150", "description": "REPLACE_ME", "props": [ @@ -34577,7 +34577,7 @@ ] }, { - "uuid": "1cfabc36-b403-42d5-81c0-3fce83f7c31d", + "uuid": "8477fe1d-f973-4673-b43d-93a41b381325", "control-id": "rhel-09.654155", "description": "REPLACE_ME", "props": [ @@ -34594,7 +34594,7 @@ ] }, { - "uuid": "3a7dde54-4a04-46d9-8b8b-2c2335210ad2", + "uuid": "0016fbae-f52d-4177-b4d2-db686f34e70a", "control-id": "rhel-09.654160", "description": "REPLACE_ME", "props": [ @@ -34611,7 +34611,7 @@ ] }, { - "uuid": "27bc7807-4b2e-4bdc-808c-a14d7476d0a5", + "uuid": "a19fd8af-e67c-4860-a654-65ba661d46fb", "control-id": "rhel-09.654165", "description": "REPLACE_ME", "props": [ @@ -34628,7 +34628,7 @@ ] }, { - "uuid": "a35d96ec-be6e-43bc-bc13-4f2c8e3ea7ea", + "uuid": "e2c9da2a-526f-43c6-9fa5-3f2e7127eba2", "control-id": "rhel-09.654170", "description": "REPLACE_ME", "props": [ @@ -34645,7 +34645,7 @@ ] }, { - "uuid": "7d70acc9-cd5a-42f3-b790-d3953479a094", + "uuid": "57e9daf4-7e2b-431f-955d-8d3400ed1cbd", "control-id": "rhel-09.654175", "description": "REPLACE_ME", "props": [ @@ -34662,7 +34662,7 @@ ] }, { - "uuid": "6a0aed8d-a18e-4012-90de-438769941185", + "uuid": "812a1315-0696-47e1-a07d-f1728cf9a7b1", "control-id": "rhel-09.654180", "description": "REPLACE_ME", "props": [ @@ -34679,7 +34679,7 @@ ] }, { - "uuid": "3ce51be9-c21f-448d-aaf6-915f4e71f65d", + "uuid": "2a94ca94-7a71-4614-bf09-7e02c1cc1dd2", "control-id": "rhel-09.654185", "description": "REPLACE_ME", "props": [ @@ -34696,7 +34696,7 @@ ] }, { - "uuid": "8ee469ca-b929-41cd-a323-60296657ddb0", + "uuid": "40c9197b-a213-40ef-a15d-3132c9f633b7", "control-id": "rhel-09.654190", "description": "REPLACE_ME", "props": [ @@ -34713,7 +34713,7 @@ ] }, { - "uuid": "e88fa10b-0d98-4d31-90f6-ec25682f305c", + "uuid": "93c61c90-3308-4d1c-8a0a-fd993d1fabc4", "control-id": "rhel-09.654195", "description": "REPLACE_ME", "props": [ @@ -34730,7 +34730,7 @@ ] }, { - "uuid": "01faac50-7727-4896-81a3-892825edd30c", + "uuid": "98a6d067-3f35-4adb-8bae-a5dd420b8467", "control-id": "rhel-09.654200", "description": "REPLACE_ME", "props": [ @@ -34747,7 +34747,7 @@ ] }, { - "uuid": "ecd56697-897e-43d6-a173-f808a669d00b", + "uuid": "e1fd9180-6e58-488c-9946-7e7a351cf2f1", "control-id": "rhel-09.654205", "description": "REPLACE_ME", "props": [ @@ -34764,7 +34764,7 @@ ] }, { - "uuid": "a52b1628-b3a3-48b8-961a-785b15baba16", + "uuid": "6782a21f-ee87-4cc0-944a-9ddf1cdde285", "control-id": "rhel-09.654210", "description": "REPLACE_ME", "props": [ @@ -34781,7 +34781,7 @@ ] }, { - "uuid": "ab5aae24-3729-4173-b134-baf8a9f3fcc9", + "uuid": "1233fdba-03f8-48fb-b7fa-5b218d857fe1", "control-id": "rhel-09.654215", "description": "REPLACE_ME", "props": [ @@ -34798,7 +34798,7 @@ ] }, { - "uuid": "74af9de5-fe33-432a-8628-f4fac196fdfc", + "uuid": "30616e4e-3918-45ee-8bb8-2f8331271780", "control-id": "rhel-09.654220", "description": "REPLACE_ME", "props": [ @@ -34815,7 +34815,7 @@ ] }, { - "uuid": "477196c4-3b20-4799-a243-54cc23892bd7", + "uuid": "798d486e-ebd2-4056-80df-8de88f26bf80", "control-id": "rhel-09.654225", "description": "REPLACE_ME", "props": [ @@ -34832,7 +34832,7 @@ ] }, { - "uuid": "dfb02855-dfa4-49c6-9978-1ebae24f95a2", + "uuid": "6641b80b-39ab-4d21-a737-1ec51750bcf8", "control-id": "rhel-09.654230", "description": "REPLACE_ME", "props": [ @@ -34849,7 +34849,7 @@ ] }, { - "uuid": "7e09c298-f806-4350-8967-930dc82bdf33", + "uuid": "2a343cc1-00bc-4714-86a7-5d6b1744e020", "control-id": "rhel-09.654235", "description": "REPLACE_ME", "props": [ @@ -34866,7 +34866,7 @@ ] }, { - "uuid": "4bb2d089-733c-462e-a51a-4e544f9de41c", + "uuid": "14db97aa-708d-4e20-a08b-27bef3a03b05", "control-id": "rhel-09.654240", "description": "REPLACE_ME", "props": [ @@ -34883,7 +34883,7 @@ ] }, { - "uuid": "8d170b76-c9d0-4d79-9b67-694d75f83af2", + "uuid": "aae00850-5cab-4a1e-b6b3-eb05c40e8a2a", "control-id": "rhel-09.654245", "description": "REPLACE_ME", "props": [ @@ -34900,7 +34900,7 @@ ] }, { - "uuid": "2267afac-53ab-41f1-aa52-d2cf5ad6c4f0", + "uuid": "1c224b95-50d1-43cc-b302-48d26f92840a", "control-id": "rhel-09.654250", "description": "REPLACE_ME", "props": [ @@ -34917,7 +34917,7 @@ ] }, { - "uuid": "481542d2-5905-448b-b65c-2b21d7fa7ddd", + "uuid": "a68eb032-1d9f-4f13-aab5-7ef8f4e2e6cd", "control-id": "rhel-09.654255", "description": "REPLACE_ME", "props": [ @@ -34934,7 +34934,7 @@ ] }, { - "uuid": "0f49687b-30d8-4c28-95b5-26576fa3d364", + "uuid": "c5195b73-78df-48f9-8c6a-e46a4efbf54f", "control-id": "rhel-09.654260", "description": "REPLACE_ME", "props": [ @@ -34951,7 +34951,7 @@ ] }, { - "uuid": "27dafb31-2dc2-4f87-a15d-bce47f4e5e1d", + "uuid": "b3c94636-4485-4eda-894e-390fd22d2107", "control-id": "rhel-09.654265", "description": "REPLACE_ME", "props": [ @@ -34968,7 +34968,7 @@ ] }, { - "uuid": "1aadd79d-fbca-49de-98a7-d75c325af108", + "uuid": "3b95b041-cd3e-47fa-a678-585dfe5c6ee5", "control-id": "rhel-09.654270", "description": "REPLACE_ME", "props": [ @@ -34980,7 +34980,7 @@ ] }, { - "uuid": "2b90bb8b-d525-4f95-a1c6-491b6b94ba11", + "uuid": "017d8240-d1f1-4bd7-9199-82c6f7cf6736", "control-id": "rhel-09.654275", "description": "REPLACE_ME", "props": [ @@ -34997,7 +34997,7 @@ ] }, { - "uuid": "dd9b2832-7c41-4def-b510-2196e2956777", + "uuid": "8af2be88-be01-434d-bf42-1f39538845ba", "control-id": "rhel-09.671015", "description": "REPLACE_ME", "props": [ @@ -35014,7 +35014,7 @@ ] }, { - "uuid": "d4b6a03b-251a-4712-b23d-5c751045754e", + "uuid": "77f8c180-ac9a-4113-b1af-286230cf9064", "control-id": "rhel-09.671020", "description": "REPLACE_ME", "props": [ @@ -35031,7 +35031,7 @@ ] }, { - "uuid": "f56816c9-9bf1-4f03-8bab-b70248a772af", + "uuid": "d8679014-bc62-467a-aaea-3352fee6bc12", "control-id": "rhel-09.671025", "description": "REPLACE_ME", "props": [ @@ -35048,7 +35048,7 @@ ] }, { - "uuid": "2f9a98a4-4bdd-4a58-8ea0-772c3d28729c", + "uuid": "abb2083c-de67-4776-9251-7132b69dfe8d", "control-id": "rhel-09.672020", "description": "REPLACE_ME", "props": [ @@ -35061,7 +35061,7 @@ ] }, { - "uuid": "07058648-f1b4-421e-b0a6-fde1b57fa611", + "uuid": "7170066b-dc42-4a88-be4d-2f7fdf476b05", "control-id": "rhel-09.672025", "description": "REPLACE_ME", "props": [ @@ -35078,7 +35078,7 @@ ] }, { - "uuid": "18a9798f-f026-45b8-b2fc-3dc98c4ce060", + "uuid": "2e40f7af-5f77-4db4-8761-809e9c1907ef", "control-id": "rhel-09.672050", "description": "REPLACE_ME", "props": [ @@ -35100,4 +35100,4 @@ } ] } -} \ No newline at end of file +}