Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -27,6 +27,7 @@ references:
srg: SRG-OS-000480-GPOS-00226
stigid@sle12: SLES-12-010370
stigid@sle15: SLES-15-040010
stigid@ubuntu2204: UBTU-22-412010

ocil_clause: 'the value of delay is not set properly or the line is commented or missing'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,7 @@ references:
nist: AC-7 (a)
srg: SRG-OS-000021-GPOS-00005
stigid@ol8: OL08-00-020021
stigid@ubuntu2204: UBTU-22-411045

{{% if product == "rhel8" %}}
platform: os_linux[rhel]>=8.2 and package[pam]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -46,6 +46,7 @@ references:
srg: SRG-OS-000329-GPOS-00128,SRG-OS-000021-GPOS-00005
stigid@ol7: OL07-00-010320
stigid@ol8: OL08-00-020011
stigid@ubuntu2204: UBTU-22-411045

{{% if product == "ol8" %}}
platform: os_linux[ol]>=8.2 and package[pam]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -42,6 +42,7 @@ references:
srg: SRG-OS-000329-GPOS-00128,SRG-OS-000021-GPOS-00005
stigid@ol7: OL07-00-010320
stigid@ol8: OL08-00-020013
stigid@ubuntu2204: UBTU-22-411045

{{% if product == "ol8" %}}
platform: os_linux[ol]>=8.2 and package[pam]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -28,6 +28,7 @@ identifiers:
references:
srg: SRG-OS-000329-GPOS-00128,SRG-OS-000021-GPOS-00005
stigid@ol8: OL08-00-020019
stigid@ubuntu2204: UBTU-22-411045

ocil_clause: 'the system shows messages when three unsuccessful logon attempts occur'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -47,6 +47,7 @@ references:
srg: SRG-OS-000329-GPOS-00128,SRG-OS-000021-GPOS-00005
stigid@ol7: OL07-00-010320
stigid@ol8: OL08-00-020015
stigid@ubuntu2204: UBTU-22-411045

{{% if product == "ol8" %}}
platform: os_linux[ol]>=8.2 and package[pam]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -40,6 +40,7 @@ references:
stigid@ol8: OL08-00-020043
stigid@sle12: SLES-12-010070
stigid@sle15: SLES-15-010110
stigid@ubuntu2204: UBTU-22-412025

ocil_clause: 'the package is not installed'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -53,6 +53,7 @@ references:
stigid@ol8: OL08-00-020260
stigid@sle12: SLES-12-010340
stigid@sle15: SLES-15-020050
stigid@ubuntu2204: UBTU-22-411035

ocil_clause: 'the value of INACTIVE is greater than the expected value or is -1'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -47,6 +47,7 @@ references:
stigid@ol8: OL08-00-020000,OL08-00-020270
stigid@sle12: SLES-12-010331
stigid@sle15: SLES-15-020061
stigid@ubuntu2204: UBTU-22-411040

ocil_clause: 'any temporary accounts have no expiration date set or do not expire within 72 hours'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -50,6 +50,7 @@ references:
stigid@ol8: OL08-00-020200
stigid@sle12: SLES-12-010280
stigid@sle15: SLES-15-020220
stigid@ubuntu2204: UBTU-22-411030

ocil_clause: 'the "PASS_MAX_DAYS" parameter value is greater than "{{{ xccdf_value("var_accounts_maximum_age_login_defs") }}}", or commented out'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -50,6 +50,7 @@ references:
stigid@ol8: OL08-00-020190
stigid@sle12: SLES-12-010260
stigid@sle15: SLES-15-020200
stigid@ubuntu2204: UBTU-22-411025

ocil_clause: 'the "PASS_MIN_DAYS" parameter value is not "{{{ xccdf_value("var_accounts_minimum_age_login_defs") }}}" or greater, or is commented out'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,7 @@ severity: medium

references:
srg: SRG-OS-000134-GPOS-00068
stigid@ubuntu2204: UBTU-22-432015

warnings:
- general: |-
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,7 @@ severity: medium

references:
srg: SRG-OS-000104-GPOS-00051,SRG-OS-000121-GPOS-00062
stigid@ubuntu2204: UBTU-22-411015

warnings:
- general: |-
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,7 @@ severity: medium

references:
srg: SRG-OS-000109-GPOS-00056
stigid@ubuntu2204: UBTU-22-411010

ocil_clause: 'the output does not contain "L" in the second field'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -41,6 +41,7 @@ references:
stigid@ol8: OL08-00-020024
stigid@sle12: SLES-12-010120
stigid@sle15: SLES-15-020020
stigid@ubuntu2204: UBTU-22-412020

ocil_clause: |-
the "maxlogins" item is missing, commented out, or the value is set greater
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -65,6 +65,7 @@ references:
stigid@ol7: OL07-00-040160
stigid@sle12: SLES-12-010090
stigid@sle15: SLES-15-010130
stigid@ubuntu2204: UBTU-22-412030

ocil_clause: 'the TMOUT value is not configured, is set to 0, or is not less than or equal to the expected setting'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -40,6 +40,7 @@ references:
stigid@ol8: OL08-00-020351
stigid@sle12: SLES-12-010620
stigid@sle15: SLES-15-040420
stigid@ubuntu2204: UBTU-22-412035

ocil_clause: 'the value for the "UMASK" parameter is not "{{{ xccdf_value("var_accounts_user_umask") }}}", or the "UMASK" parameter is missing or is commented out'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -45,6 +45,7 @@ references:
srg: SRG-OS-000312-GPOS-00122,SRG-OS-000312-GPOS-00123,SRG-OS-000312-GPOS-00124,SRG-OS-000324-GPOS-00125,SRG-OS-000326-GPOS-00126,SRG-OS-000370-GPOS-00155,SRG-OS-000480-GPOS-00230,SRG-OS-000480-GPOS-00227,SRG-OS-000480-GPOS-00231,SRG-OS-000480-GPOS-00232
stigid@sle12: SLES-12-010600
stigid@sle15: SLES-15-010390
stigid@ubuntu2204: UBTU-22-431015

ocil_clause: 'it is not'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,7 @@ identifiers:

references:
srg: SRG-OS-000368-GPOS-00154,SRG-OS-000312-GPOS-00122,SRG-OS-000312-GPOS-00123,SRG-OS-000312-GPOS-00124,SRG-OS-000324-GPOS-00125,SRG-OS-000370-GPOS-00155
stigid@ubuntu2204: UBTU-22-431010

template:
name: package_installed
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -39,6 +39,7 @@ references:
stigid@ol8: OL08-00-010381
stigid@sle12: SLES-12-010110
stigid@sle15: SLES-15-010450
stigid@ubuntu2204: UBTU-22-432010

ocil_clause: "!authenticate is specified in the sudo config files"

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -40,6 +40,7 @@ references:
stigid@ol8: OL08-00-010380
stigid@sle12: SLES-12-010110
stigid@sle15: SLES-15-010450
stigid@ubuntu2204: UBTU-22-432011

ocil_clause: 'nopasswd is specified in the sudo config files'

Expand Down