52.8 MB
/srv/reproducible-results/rbuild-debian/r-b-build.rcacOdWr/b1/scap-security-guide_0.1.65-1_amd64.changes vs.
/srv/reproducible-results/rbuild-debian/r-b-build.rcacOdWr/b2/scap-security-guide_0.1.65-1_amd64.changes
822 B
Files
    
Offset 1, 6 lines modifiedOffset 1, 6 lines modified
  
1 ·18090169a6b08e51aa8cf98d1a67791d·181960·admin·optional·ssg-applications_0.1.65-1_all.deb1 ·c648e9dd369bd5db41cf2cabca7e639e·181916·admin·optional·ssg-applications_0.1.65-1_all.deb
2 ·f7bae0738ce4e633a16dbb487c1b30d5·27788·admin·optional·ssg-base_0.1.65-1_all.deb2 ·f7bae0738ce4e633a16dbb487c1b30d5·27788·admin·optional·ssg-base_0.1.65-1_all.deb
3 ·bcdc31fc8ce6187d18aa01992d8bdeff·3378672·admin·optional·ssg-debderived_0.1.65-1_all.deb 
4 ·56111c82ff654a02f0793cad2a4f9e4f·828680·admin·optional·ssg-debian_0.1.65-1_all.deb 
5 ·caed9acb69b15daa2c02d4ec76955caa·40217608·admin·optional·ssg-nondebian_0.1.65-1_all.deb3 ·cbf5117ebf59a4d85e284ac8798843b4·3380308·admin·optional·ssg-debderived_0.1.65-1_all.deb
 4 ·978245e3e4c24d53f4a7dfee5e0c9507·828692·admin·optional·ssg-debian_0.1.65-1_all.deb
 5 ·4c021df465c5f7e67d290321990173a1·40218524·admin·optional·ssg-nondebian_0.1.65-1_all.deb
20.3 KB
ssg-applications_0.1.65-1_all.deb
452 B
file list
    
Offset 1, 3 lines modifiedOffset 1, 3 lines modified
1 -rw-r--r--···0········0········0········4·2022-12-20·09:54:05.000000·debian-binary1 -rw-r--r--···0········0········0········4·2022-12-20·09:54:05.000000·debian-binary
2 -rw-r--r--···0········0········0·····1736·2022-12-20·09:54:05.000000·control.tar.xz2 -rw-r--r--···0········0········0·····1732·2022-12-20·09:54:05.000000·control.tar.xz
3 -rw-r--r--···0········0········0···180032·2022-12-20·09:54:05.000000·data.tar.xz3 -rw-r--r--···0········0········0···179992·2022-12-20·09:54:05.000000·data.tar.xz
98.0 B
control.tar.xz
70.0 B
control.tar
48.0 B
./md5sums
30.0 B
./md5sums
Files differ
19.7 KB
data.tar.xz
19.7 KB
data.tar
1.99 KB
./usr/share/doc/ssg-applications/ssg-chromium-guide-stig.html
    
Offset 14334, 16 lines modifiedOffset 14334, 16 lines modified
00037fd0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</00037fd0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</
00037fe0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve00037fe0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve
00037ff0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>000037ff0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>0
00038000:·2e31·2e36·353c·2f73·7472·6f6e·673e·3c2f··.1.65</strong></00038000:·2e31·2e36·353c·2f73·7472·6f6e·673e·3c2f··.1.65</strong></
00038010:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron00038010:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron
00038020:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>00038020:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>
00038030:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00038030:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00038040:·2020·2020·2028·6173·206f·6620·3230·3234·······(as·of·202400038040:·2020·2020·2028·6173·206f·6620·3230·3235·······(as·of·2025
00038050:·2d30·312d·3134·290a·2020·2020·2020·2020··-01-14).········00038050:·2d30·322d·3135·290a·2020·2020·2020·2020··-02-15).········
00038060:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u00038060:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u
00038070:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl00038070:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl
00038080:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h00038080:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h
00038090:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre00038090:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre
000380a0:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss000380a0:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss
000380b0:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content000380b0:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content
000380c0:·5f67·726f·7570·5f63·6872·6f6d·6975·6d22··_group_chromium"000380c0:·5f67·726f·7570·5f63·6872·6f6d·6975·6d22··_group_chromium"
651 B
html2text {}
    
Offset 50, 15 lines modifiedOffset 50, 15 lines modified
50 *****·Profile·Information·*****50 *****·Profile·Information·*****
51 Profile·Title·Upstream·STIG·for·Google·Chromium51 Profile·Title·Upstream·STIG·for·Google·Chromium
52 Profile·ID····xccdf_org.ssgproject.content_profile_stig52 Profile·ID····xccdf_org.ssgproject.content_profile_stig
53 ***·CPE·Platforms·***53 ***·CPE·Platforms·***
54 ····*·cpe:/a:google:chromium-browser54 ····*·cpe:/a:google:chromium-browser
55 *****·Revision·History·*****55 *****·Revision·History·*****
56 Current·version:·0.1.6556 Current·version:·0.1.65
57 ····*·draft·(as·of·2024-01-14)57 ····*·draft·(as·of·2025-02-15)
58 *****·Table·of·Contents·*****58 *****·Table·of·Contents·*****
59 ···1.·Chromium59 ···1.·Chromium
60 *****·Checklist·*****60 *****·Checklist·*****
61 Group  ·Guide·to·the·Secure·Configuration·of·Chromium·  Group·contains·1·group·and·3761 Group  ·Guide·to·the·Secure·Configuration·of·Chromium·  Group·contains·1·group·and·37
62 rules62 rules
63 Group  ·Chromium·  Group·contains·37·rules63 Group  ·Chromium·  Group·contains·37·rules
64 [ref]  ·Chromium·is·an·open-source·web·browser,·powered·by·WebKit·(Blink),·and64 [ref]  ·Chromium·is·an·open-source·web·browser,·powered·by·WebKit·(Blink),·and
1.9 KB
./usr/share/doc/ssg-applications/ssg-eks-guide-cis-node.html
    
Offset 14331, 15 lines modifiedOffset 14331, 15 lines modified
00037fa0:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current00037fa0:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current
00037fb0:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron00037fb0:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron
00037fc0:·673e·302e·312e·3635·3c2f·7374·726f·6e67··g>0.1.65</strong00037fc0:·673e·302e·312e·3635·3c2f·7374·726f·6e67··g>0.1.65</strong
00037fd0:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st00037fd0:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st
00037fe0:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro00037fe0:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro
00037ff0:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············00037ff0:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············
00038000:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·200038000:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·2
00038010:·3032·342d·3031·2d31·3429·0a20·2020·2020··024-01-14).·····00038010:·3032·352d·3032·2d31·3529·0a20·2020·2020··025-02-15).·····
00038020:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>00038020:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>
00038030:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T00038030:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T
00038040:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents00038040:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents
00038050:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·00038050:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·
00038060:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org00038060:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org
00038070:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont00038070:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont
00038080:·656e·745f·6772·6f75·705f·6f70·656e·7368··ent_group_opensh00038080:·656e·745f·6772·6f75·705f·6f70·656e·7368··ent_group_opensh
698 B
html2text {}
    
Offset 44, 15 lines modifiedOffset 44, 15 lines modified
44 Profile·ID····xccdf_org.ssgproject.content_profile_cis-node44 Profile·ID····xccdf_org.ssgproject.content_profile_cis-node
45 ***·CPE·Platforms·***45 ***·CPE·Platforms·***
46 ····*·cpe:/a:amazon:elastic_kubernetes_service_node:1.2146 ····*·cpe:/a:amazon:elastic_kubernetes_service_node:1.21
47 ····*·cpe:/o:amazon:elastic_kubernetes_service_node:147 ····*·cpe:/o:amazon:elastic_kubernetes_service_node:1
48 ····*·cpe:/a:amazon:elastic_kubernetes_service:148 ····*·cpe:/a:amazon:elastic_kubernetes_service:1
49 *****·Revision·History·*****49 *****·Revision·History·*****
50 Current·version:·0.1.6550 Current·version:·0.1.65
51 ····*·draft·(as·of·2024-01-14)51 ····*·draft·(as·of·2025-02-15)
52 *****·Table·of·Contents·*****52 *****·Table·of·Contents·*****
53 ···1.·Kubernetes_Settings53 ···1.·Kubernetes_Settings
54 ·········1.·Kubernetes_Kubelet_Settings54 ·········1.·Kubernetes_Kubelet_Settings
55 ·········2.·Kubernetes_-_Worker_Node_Settings55 ·········2.·Kubernetes_-_Worker_Node_Settings
56 *****·Checklist·*****56 *****·Checklist·*****
57 Group  ·Guide·to·the·Secure·Configuration·of·Amazon·Elastic·Kubernetes·Service·  Group57 Group  ·Guide·to·the·Secure·Configuration·of·Amazon·Elastic·Kubernetes·Service·  Group
58 contains·3·groups·and·7·rules58 contains·3·groups·and·7·rules
1.88 KB
./usr/share/doc/ssg-applications/ssg-eks-guide-cis.html
    
Offset 14330, 15 lines modifiedOffset 14330, 15 lines modified
00037f90:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>00037f90:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>
00037fa0:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:00037fa0:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:
00037fb0:·203c·7374·726f·6e67·3e30·2e31·2e36·353c···<strong>0.1.65<00037fb0:·203c·7374·726f·6e67·3e30·2e31·2e36·353c···<strong>0.1.65<
00037fc0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>00037fc0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>
00037fd0:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf00037fd0:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf
00037fe0:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····00037fe0:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····
00037ff0:·2020·2020·2020·2020·2020·2020·2020·2028·················(00037ff0:·2020·2020·2020·2020·2020·2020·2020·2028·················(
00038000:·6173·206f·6620·3230·3234·2d30·312d·3134··as·of·2024-01-1400038000:·6173·206f·6620·3230·3235·2d30·322d·3135··as·of·2025-02-15
00038010:·290a·2020·2020·2020·2020·2020·2020·2020··).··············00038010:·290a·2020·2020·2020·2020·2020·2020·2020··).··············
00038020:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di00038020:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di
00038030:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C00038030:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C
00038040:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>00038040:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>
00038050:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc00038050:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc
00038060:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje00038060:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje
00038070:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group00038070:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group
680 B
html2text {}
    
Offset 44, 15 lines modifiedOffset 44, 15 lines modified
44 Profile·ID····xccdf_org.ssgproject.content_profile_cis44 Profile·ID····xccdf_org.ssgproject.content_profile_cis
45 ***·CPE·Platforms·***45 ***·CPE·Platforms·***
46 ····*·cpe:/a:amazon:elastic_kubernetes_service_node:1.2146 ····*·cpe:/a:amazon:elastic_kubernetes_service_node:1.21
47 ····*·cpe:/o:amazon:elastic_kubernetes_service_node:147 ····*·cpe:/o:amazon:elastic_kubernetes_service_node:1
48 ····*·cpe:/a:amazon:elastic_kubernetes_service:148 ····*·cpe:/a:amazon:elastic_kubernetes_service:1
49 *****·Revision·History·*****49 *****·Revision·History·*****
50 Current·version:·0.1.6550 Current·version:·0.1.65
51 ····*·draft·(as·of·2024-01-14)51 ····*·draft·(as·of·2025-02-15)
52 *****·Table·of·Contents·*****52 *****·Table·of·Contents·*****
53 ···1.·Kubernetes_Settings53 ···1.·Kubernetes_Settings
54 ·········1.·Kubernetes_-_Account_and_Access_Control54 ·········1.·Kubernetes_-_Account_and_Access_Control
55 ·········2.·Authentication55 ·········2.·Authentication
56 ·········3.·Kubernetes_-_General_Security_Practices56 ·········3.·Kubernetes_-_General_Security_Practices
57 ·········4.·Kubernetes_Kubelet_Settings57 ·········4.·Kubernetes_Kubelet_Settings
58 ·········5.·OpenShift_-_Logging_Settings58 ·········5.·OpenShift_-_Logging_Settings
1.93 KB
./usr/share/doc/ssg-applications/ssg-firefox-guide-stig.html
    
Offset 14331, 15 lines modifiedOffset 14331, 15 lines modified
00037fa0:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>00037fa0:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>
00037fb0:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:00037fb0:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:
00037fc0:·203c·7374·726f·6e67·3e30·2e31·2e36·353c···<strong>0.1.65<00037fc0:·203c·7374·726f·6e67·3e30·2e31·2e36·353c···<strong>0.1.65<
00037fd0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>00037fd0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>
00037fe0:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf00037fe0:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf
00037ff0:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····00037ff0:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····
00038000:·2020·2020·2020·2020·2020·2020·2020·2028·················(00038000:·2020·2020·2020·2020·2020·2020·2020·2028·················(
00038010:·6173·206f·6620·3230·3234·2d30·312d·3134··as·of·2024-01-1400038010:·6173·206f·6620·3230·3235·2d30·322d·3135··as·of·2025-02-15
00038020:·290a·2020·2020·2020·2020·2020·2020·2020··).··············00038020:·290a·2020·2020·2020·2020·2020·2020·2020··).··············
00038030:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di00038030:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di
00038040:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C00038040:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C
00038050:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>00038050:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>
00038060:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc00038060:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc
00038070:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje00038070:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje
00038080:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group00038080:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group
730 B
html2text {}
    
Offset 50, 15 lines modifiedOffset 50, 15 lines modified
50 *****·Profile·Information·*****50 *****·Profile·Information·*****
51 Profile·Title·Mozilla·Firefox·STIG51 Profile·Title·Mozilla·Firefox·STIG
52 Profile·ID····xccdf_org.ssgproject.content_profile_stig52 Profile·ID····xccdf_org.ssgproject.content_profile_stig
53 ***·CPE·Platforms·***53 ***·CPE·Platforms·***
54 ····*·cpe:/a:mozilla:firefox54 ····*·cpe:/a:mozilla:firefox
55 *****·Revision·History·*****55 *****·Revision·History·*****
56 Current·version:·0.1.6556 Current·version:·0.1.65
57 ····*·draft·(as·of·2024-01-14)57 ····*·draft·(as·of·2025-02-15)
58 *****·Table·of·Contents·*****58 *****·Table·of·Contents·*****
59 ···1.·Firefox59 ···1.·Firefox
60 *****·Checklist·*****60 *****·Checklist·*****
61 Group  ·Guide·to·the·Secure·Configuration·of·Firefox·  Group·contains·1·group·and·33·rules61 Group  ·Guide·to·the·Secure·Configuration·of·Firefox·  Group·contains·1·group·and·33·rules
62 Group  ·Firefox·  Group·contains·33·rules62 Group  ·Firefox·  Group·contains·33·rules
63 [ref]  ·Firefox·is·an·open-source·web·browser·and·developed·by·Mozilla.·Web·browsers·such·as63 [ref]  ·Firefox·is·an·open-source·web·browser·and·developed·by·Mozilla.·Web·browsers·such·as
64 Firefox·are·used·for·a·number·of·reasons.·This·section·provides·settings·for·configuring64 Firefox·are·used·for·a·number·of·reasons.·This·section·provides·settings·for·configuring
1.4 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-ds-1.2.xml
1.29 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-ds-1.2.xml
    
Offset 28, 15 lines modifiedOffset 28, 15 lines modified
28 ········<cpe-dict:title·xml:lang="en-us">Google·Chromium·Browser</cpe-dict:title>28 ········<cpe-dict:title·xml:lang="en-us">Google·Chromium·Browser</cpe-dict:title>
29 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-chromium-cpe-oval.xml">oval:ssg-installed_app_is_chromium:def:1</cpe-dict:check>29 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-chromium-cpe-oval.xml">oval:ssg-installed_app_is_chromium:def:1</cpe-dict:check>
30 ······</cpe-dict:cpe-item>30 ······</cpe-dict:cpe-item>
31 ····</cpe-dict:cpe-list>31 ····</cpe-dict:cpe-list>
32 ··</ds:component>32 ··</ds:component>
33 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-xccdf.xml"·timestamp="2022-12-20T09:54:05">33 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-xccdf.xml"·timestamp="2022-12-20T09:54:05">
34 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_CHROMIUM"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">34 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_CHROMIUM"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
35 ······<xccdf-1.2:status·date="2024-01-14">draft</xccdf-1.2:status>35 ······<xccdf-1.2:status·date="2025-02-15">draft</xccdf-1.2:status>
36 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Chromium</xccdf-1.2:title>36 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Chromium</xccdf-1.2:title>
37 ······<xccdf-1.2:description>37 ······<xccdf-1.2:description>
38 ········This·guide·presents·a·catalog·of·security-relevant38 ········This·guide·presents·a·catalog·of·security-relevant
39 configuration·settings·for·Chromium.·It·is·a·rendering·of39 configuration·settings·for·Chromium.·It·is·a·rendering·of
40 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)40 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
41 in·order·to·support·security·automation.··The·SCAP·content·is41 in·order·to·support·security·automation.··The·SCAP·content·is
42 is·available·in·the42 is·available·in·the
1.38 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-ds.xml
1.28 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-ds.xml
    
Offset 28, 15 lines modifiedOffset 28, 15 lines modified
28 ········<cpe-dict:title·xml:lang="en-us">Google·Chromium·Browser</cpe-dict:title>28 ········<cpe-dict:title·xml:lang="en-us">Google·Chromium·Browser</cpe-dict:title>
29 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-chromium-cpe-oval.xml">oval:ssg-installed_app_is_chromium:def:1</cpe-dict:check>29 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-chromium-cpe-oval.xml">oval:ssg-installed_app_is_chromium:def:1</cpe-dict:check>
30 ······</cpe-dict:cpe-item>30 ······</cpe-dict:cpe-item>
31 ····</cpe-dict:cpe-list>31 ····</cpe-dict:cpe-list>
32 ··</ds:component>32 ··</ds:component>
33 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-xccdf.xml"·timestamp="2022-12-20T09:54:05">33 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-xccdf.xml"·timestamp="2022-12-20T09:54:05">
34 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_CHROMIUM"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">34 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_CHROMIUM"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
35 ······<xccdf-1.2:status·date="2024-01-14">draft</xccdf-1.2:status>35 ······<xccdf-1.2:status·date="2025-02-15">draft</xccdf-1.2:status>
36 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Chromium</xccdf-1.2:title>36 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Chromium</xccdf-1.2:title>
37 ······<xccdf-1.2:description>37 ······<xccdf-1.2:description>
38 ········This·guide·presents·a·catalog·of·security-relevant38 ········This·guide·presents·a·catalog·of·security-relevant
39 configuration·settings·for·Chromium.·It·is·a·rendering·of39 configuration·settings·for·Chromium.·It·is·a·rendering·of
40 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)40 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
41 in·order·to·support·security·automation.··The·SCAP·content·is41 in·order·to·support·security·automation.··The·SCAP·content·is
42 is·available·in·the42 is·available·in·the
1.17 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-xccdf.xml
1.06 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-xccdf.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Benchmark·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_CHROMIUM"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">2 <xccdf-1.2:Benchmark·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_CHROMIUM"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
3 ··<xccdf-1.2:status·date="2024-01-14">draft</xccdf-1.2:status>3 ··<xccdf-1.2:status·date="2025-02-15">draft</xccdf-1.2:status>
4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Chromium</xccdf-1.2:title>4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Chromium</xccdf-1.2:title>
5 ··<xccdf-1.2:description>5 ··<xccdf-1.2:description>
6 ····This·guide·presents·a·catalog·of·security-relevant6 ····This·guide·presents·a·catalog·of·security-relevant
7 configuration·settings·for·Chromium.·It·is·a·rendering·of7 configuration·settings·for·Chromium.·It·is·a·rendering·of
8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
9 in·order·to·support·security·automation.··The·SCAP·content·is9 in·order·to·support·security·automation.··The·SCAP·content·is
10 is·available·in·the10 is·available·in·the
1.42 KB
./usr/share/xml/scap/ssg/content/ssg-eks-ds-1.2.xml
1.33 KB
./usr/share/xml/scap/ssg/content/ssg-eks-ds-1.2.xml
    
Offset 36, 15 lines modifiedOffset 36, 15 lines modified
36 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service·Node</cpe-dict:title>36 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service·Node</cpe-dict:title>
37 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml">oval:ssg-installed_app_is_eks_node:def:1</cpe-dict:check>37 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml">oval:ssg-installed_app_is_eks_node:def:1</cpe-dict:check>
38 ······</cpe-dict:cpe-item>38 ······</cpe-dict:cpe-item>
39 ····</cpe-dict:cpe-list>39 ····</cpe-dict:cpe-list>
40 ··</ds:component>40 ··</ds:component>
41 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-xccdf.xml"·timestamp="2022-12-20T09:54:05">41 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-xccdf.xml"·timestamp="2022-12-20T09:54:05">
42 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_EKS"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">42 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_EKS"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
43 ······<xccdf-1.2:status·date="2024-01-14">draft</xccdf-1.2:status>43 ······<xccdf-1.2:status·date="2025-02-15">draft</xccdf-1.2:status>
44 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Elastic·Kubernetes·Service</xccdf-1.2:title>44 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Elastic·Kubernetes·Service</xccdf-1.2:title>
45 ······<xccdf-1.2:description>45 ······<xccdf-1.2:description>
46 ········This·guide·presents·a·catalog·of·security-relevant46 ········This·guide·presents·a·catalog·of·security-relevant
47 configuration·settings·for·Amazon·Elastic·Kubernetes·Service.·It·is·a·rendering·of47 configuration·settings·for·Amazon·Elastic·Kubernetes·Service.·It·is·a·rendering·of
48 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)48 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
49 in·order·to·support·security·automation.··The·SCAP·content·is49 in·order·to·support·security·automation.··The·SCAP·content·is
50 is·available·in·the50 is·available·in·the
1.41 KB
./usr/share/xml/scap/ssg/content/ssg-eks-ds.xml
1.32 KB
./usr/share/xml/scap/ssg/content/ssg-eks-ds.xml
    
Offset 36, 15 lines modifiedOffset 36, 15 lines modified
36 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service·Node</cpe-dict:title>36 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service·Node</cpe-dict:title>
37 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml">oval:ssg-installed_app_is_eks_node:def:1</cpe-dict:check>37 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml">oval:ssg-installed_app_is_eks_node:def:1</cpe-dict:check>
38 ······</cpe-dict:cpe-item>38 ······</cpe-dict:cpe-item>
39 ····</cpe-dict:cpe-list>39 ····</cpe-dict:cpe-list>
40 ··</ds:component>40 ··</ds:component>
41 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-xccdf.xml"·timestamp="2022-12-20T09:54:05">41 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-xccdf.xml"·timestamp="2022-12-20T09:54:05">
42 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_EKS"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">42 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_EKS"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
43 ······<xccdf-1.2:status·date="2024-01-14">draft</xccdf-1.2:status>43 ······<xccdf-1.2:status·date="2025-02-15">draft</xccdf-1.2:status>
44 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Elastic·Kubernetes·Service</xccdf-1.2:title>44 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Elastic·Kubernetes·Service</xccdf-1.2:title>
45 ······<xccdf-1.2:description>45 ······<xccdf-1.2:description>
46 ········This·guide·presents·a·catalog·of·security-relevant46 ········This·guide·presents·a·catalog·of·security-relevant
47 configuration·settings·for·Amazon·Elastic·Kubernetes·Service.·It·is·a·rendering·of47 configuration·settings·for·Amazon·Elastic·Kubernetes·Service.·It·is·a·rendering·of
48 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)48 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
49 in·order·to·support·security·automation.··The·SCAP·content·is49 in·order·to·support·security·automation.··The·SCAP·content·is
50 is·available·in·the50 is·available·in·the
1.25 KB
./usr/share/xml/scap/ssg/content/ssg-eks-xccdf.xml
1.15 KB
./usr/share/xml/scap/ssg/content/ssg-eks-xccdf.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_EKS"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_EKS"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
3 ··<xccdf-1.2:status·date="2024-01-14">draft</xccdf-1.2:status>3 ··<xccdf-1.2:status·date="2025-02-15">draft</xccdf-1.2:status>
4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Elastic·Kubernetes·Service</xccdf-1.2:title>4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Elastic·Kubernetes·Service</xccdf-1.2:title>
5 ··<xccdf-1.2:description>5 ··<xccdf-1.2:description>
6 ····This·guide·presents·a·catalog·of·security-relevant6 ····This·guide·presents·a·catalog·of·security-relevant
7 configuration·settings·for·Amazon·Elastic·Kubernetes·Service.·It·is·a·rendering·of7 configuration·settings·for·Amazon·Elastic·Kubernetes·Service.·It·is·a·rendering·of
8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
9 in·order·to·support·security·automation.··The·SCAP·content·is9 in·order·to·support·security·automation.··The·SCAP·content·is
10 is·available·in·the10 is·available·in·the
1.38 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-ds-1.2.xml
1.27 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-ds-1.2.xml
    
Offset 28, 15 lines modifiedOffset 28, 15 lines modified
28 ········<cpe-dict:title·xml:lang="en-us">Mozilla·Firefox</cpe-dict:title>28 ········<cpe-dict:title·xml:lang="en-us">Mozilla·Firefox</cpe-dict:title>
29 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-firefox-cpe-oval.xml">oval:ssg-installed_app_is_firefox:def:1</cpe-dict:check>29 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-firefox-cpe-oval.xml">oval:ssg-installed_app_is_firefox:def:1</cpe-dict:check>
30 ······</cpe-dict:cpe-item>30 ······</cpe-dict:cpe-item>
31 ····</cpe-dict:cpe-list>31 ····</cpe-dict:cpe-list>
32 ··</ds:component>32 ··</ds:component>
33 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-xccdf.xml"·timestamp="2022-12-20T09:54:05">33 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-xccdf.xml"·timestamp="2022-12-20T09:54:05">
34 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_FIREFOX"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">34 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_FIREFOX"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
35 ······<xccdf-1.2:status·date="2024-01-14">draft</xccdf-1.2:status>35 ······<xccdf-1.2:status·date="2025-02-15">draft</xccdf-1.2:status>
36 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Firefox</xccdf-1.2:title>36 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Firefox</xccdf-1.2:title>
37 ······<xccdf-1.2:description>37 ······<xccdf-1.2:description>
38 ········This·guide·presents·a·catalog·of·security-relevant38 ········This·guide·presents·a·catalog·of·security-relevant
39 configuration·settings·for·Firefox.·It·is·a·rendering·of39 configuration·settings·for·Firefox.·It·is·a·rendering·of
40 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)40 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
41 in·order·to·support·security·automation.··The·SCAP·content·is41 in·order·to·support·security·automation.··The·SCAP·content·is
42 is·available·in·the42 is·available·in·the
1.36 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-ds.xml
1.26 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-ds.xml
    
Offset 28, 15 lines modifiedOffset 28, 15 lines modified
28 ········<cpe-dict:title·xml:lang="en-us">Mozilla·Firefox</cpe-dict:title>28 ········<cpe-dict:title·xml:lang="en-us">Mozilla·Firefox</cpe-dict:title>
29 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-firefox-cpe-oval.xml">oval:ssg-installed_app_is_firefox:def:1</cpe-dict:check>29 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-firefox-cpe-oval.xml">oval:ssg-installed_app_is_firefox:def:1</cpe-dict:check>
30 ······</cpe-dict:cpe-item>30 ······</cpe-dict:cpe-item>
31 ····</cpe-dict:cpe-list>31 ····</cpe-dict:cpe-list>
32 ··</ds:component>32 ··</ds:component>
33 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-xccdf.xml"·timestamp="2022-12-20T09:54:05">33 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-xccdf.xml"·timestamp="2022-12-20T09:54:05">
34 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_FIREFOX"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">34 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_FIREFOX"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
35 ······<xccdf-1.2:status·date="2024-01-14">draft</xccdf-1.2:status>35 ······<xccdf-1.2:status·date="2025-02-15">draft</xccdf-1.2:status>
36 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Firefox</xccdf-1.2:title>36 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Firefox</xccdf-1.2:title>
37 ······<xccdf-1.2:description>37 ······<xccdf-1.2:description>
38 ········This·guide·presents·a·catalog·of·security-relevant38 ········This·guide·presents·a·catalog·of·security-relevant
39 configuration·settings·for·Firefox.·It·is·a·rendering·of39 configuration·settings·for·Firefox.·It·is·a·rendering·of
40 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)40 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
41 in·order·to·support·security·automation.··The·SCAP·content·is41 in·order·to·support·security·automation.··The·SCAP·content·is
42 is·available·in·the42 is·available·in·the
1.17 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-xccdf.xml
1.06 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-xccdf.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Benchmark·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_FIREFOX"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">2 <xccdf-1.2:Benchmark·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_FIREFOX"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
3 ··<xccdf-1.2:status·date="2024-01-14">draft</xccdf-1.2:status>3 ··<xccdf-1.2:status·date="2025-02-15">draft</xccdf-1.2:status>
4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Firefox</xccdf-1.2:title>4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Firefox</xccdf-1.2:title>
5 ··<xccdf-1.2:description>5 ··<xccdf-1.2:description>
6 ····This·guide·presents·a·catalog·of·security-relevant6 ····This·guide·presents·a·catalog·of·security-relevant
7 configuration·settings·for·Firefox.·It·is·a·rendering·of7 configuration·settings·for·Firefox.·It·is·a·rendering·of
8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
9 in·order·to·support·security·automation.··The·SCAP·content·is9 in·order·to·support·security·automation.··The·SCAP·content·is
10 is·available·in·the10 is·available·in·the
2.5 MB
ssg-debderived_0.1.65-1_all.deb
452 B
file list
    
Offset 1, 3 lines modifiedOffset 1, 3 lines modified
1 -rw-r--r--···0········0········0········4·2022-12-20·09:54:05.000000·debian-binary1 -rw-r--r--···0········0········0········4·2022-12-20·09:54:05.000000·debian-binary
2 -rw-r--r--···0········0········0·····2784·2022-12-20·09:54:05.000000·control.tar.xz2 -rw-r--r--···0········0········0·····2780·2022-12-20·09:54:05.000000·control.tar.xz
3 -rw-r--r--···0········0········0··3375696·2022-12-20·09:54:05.000000·data.tar.xz3 -rw-r--r--···0········0········0··3377336·2022-12-20·09:54:05.000000·data.tar.xz
98.0 B
control.tar.xz
70.0 B
control.tar
48.0 B
./md5sums
30.0 B
./md5sums
Files differ
2.5 MB
data.tar.xz
2.5 MB
data.tar
2.02 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu1604-guide-anssi_np_nt28_average.html
    
Offset 14286, 16 lines modifiedOffset 14286, 16 lines modified
00037cd0:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p00037cd0:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p
00037ce0:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version00037ce0:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version
00037cf0:·3a20·3c73·7472·6f6e·673e·302e·312e·3635··:·<strong>0.1.6500037cf0:·3a20·3c73·7472·6f6e·673e·302e·312e·3635··:·<strong>0.1.65
00037d00:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul00037d00:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul
00037d10:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra00037d10:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra
00037d20:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····00037d20:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····
00037d30:·2020·2020·2020·2020·2020·2020·2020·2020··················00037d30:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037d40:·2861·7320·6f66·2032·3032·342d·3031·2d31··(as·of·2024-01-100037d40:·2861·7320·6f66·2032·3032·352d·3032·2d31··(as·of·2025-02-1
00037d50:·3429·0a20·2020·2020·2020·2020·2020·2020··4).·············00037d50:·3529·0a20·2020·2020·2020·2020·2020·2020··5).·············
00037d60:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d00037d60:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d
00037d70:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·00037d70:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·
00037d80:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol00037d80:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol
00037d90:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x00037d90:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x
00037da0:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj00037da0:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj
00037db0:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou00037db0:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou
00037dc0:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System00037dc0:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System
645 B
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *****·Profile·Information·*****37 *****·Profile·Information·*****
38 Profile·Title·Profile·for·ANSSI·DAT-NT28·Average·(Intermediate)·Level38 Profile·Title·Profile·for·ANSSI·DAT-NT28·Average·(Intermediate)·Level
39 Profile·ID····xccdf_org.ssgproject.content_profile_anssi_np_nt28_average39 Profile·ID····xccdf_org.ssgproject.content_profile_anssi_np_nt28_average
40 ***·CPE·Platforms·***40 ***·CPE·Platforms·***
41 ····*·cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~41 ····*·cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~
42 *****·Revision·History·*****42 *****·Revision·History·*****
43 Current·version:·0.1.6543 Current·version:·0.1.65
44 ····*·draft·(as·of·2024-01-14)44 ····*·draft·(as·of·2025-02-15)
45 *****·Table·of·Contents·*****45 *****·Table·of·Contents·*****
46 ···1.·System_Settings46 ···1.·System_Settings
47 ·········1.·Installing_and_Maintaining_Software47 ·········1.·Installing_and_Maintaining_Software
48 ·········2.·Configure_Syslog48 ·········2.·Configure_Syslog
49 ·········3.·File_Permissions_and_Masks49 ·········3.·File_Permissions_and_Masks
50 ···2.·Services50 ···2.·Services
51 ·········1.·APT_service_configuration51 ·········1.·APT_service_configuration
1.9 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu1604-guide-anssi_np_nt28_high.html
    
Offset 14288, 15 lines modifiedOffset 14288, 15 lines modified
00037cf0:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v00037cf0:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v
00037d00:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>00037d00:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>
00037d10:·302e·312e·3635·3c2f·7374·726f·6e67·3e3c··0.1.65</strong><00037d10:·302e·312e·3635·3c2f·7374·726f·6e67·3e3c··0.1.65</strong><
00037d20:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro00037d20:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro
00037d30:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong00037d30:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong
00037d40:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············00037d40:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············
00037d50:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·20200037d50:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·202
00037d60:·342d·3031·2d31·3429·0a20·2020·2020·2020··4-01-14).·······00037d60:·352d·3032·2d31·3529·0a20·2020·2020·2020··5-02-15).·······
00037d70:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></00037d70:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></
00037d80:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab00037d80:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab
00037d90:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</00037d90:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</
00037da0:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr00037da0:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr
00037db0:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s00037db0:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s
00037dc0:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten00037dc0:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten
00037dd0:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">00037dd0:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">
667 B
html2text {}
    
Offset 38, 15 lines modifiedOffset 38, 15 lines modified
38 *****·Profile·Information·*****38 *****·Profile·Information·*****
39 Profile·Title·Profile·for·ANSSI·DAT-NT28·High·(Enforced)·Level39 Profile·Title·Profile·for·ANSSI·DAT-NT28·High·(Enforced)·Level
40 Profile·ID····xccdf_org.ssgproject.content_profile_anssi_np_nt28_high40 Profile·ID····xccdf_org.ssgproject.content_profile_anssi_np_nt28_high
41 ***·CPE·Platforms·***41 ***·CPE·Platforms·***
42 ····*·cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~42 ····*·cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~
43 *****·Revision·History·*****43 *****·Revision·History·*****
44 Current·version:·0.1.6544 Current·version:·0.1.65
45 ····*·draft·(as·of·2024-01-14)45 ····*·draft·(as·of·2025-02-15)
46 *****·Table·of·Contents·*****46 *****·Table·of·Contents·*****
47 ···1.·System_Settings47 ···1.·System_Settings
48 ·········1.·Installing_and_Maintaining_Software48 ·········1.·Installing_and_Maintaining_Software
49 ·········2.·System_Accounting_with_auditd49 ·········2.·System_Accounting_with_auditd
50 ·········3.·GRUB2_bootloader_configuration50 ·········3.·GRUB2_bootloader_configuration
51 ·········4.·Configure_Syslog51 ·········4.·Configure_Syslog
52 ·········5.·File_Permissions_and_Masks52 ·········5.·File_Permissions_and_Masks
1.87 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu1604-guide-anssi_np_nt28_minimal.html
    
Offset 14281, 15 lines modifiedOffset 14281, 15 lines modified
00037c80:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current00037c80:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current
00037c90:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron00037c90:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron
00037ca0:·673e·302e·312e·3635·3c2f·7374·726f·6e67··g>0.1.65</strong00037ca0:·673e·302e·312e·3635·3c2f·7374·726f·6e67··g>0.1.65</strong
00037cb0:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st00037cb0:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st
00037cc0:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro00037cc0:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro
00037cd0:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············00037cd0:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············
00037ce0:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·200037ce0:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·2
00037cf0:·3032·342d·3031·2d31·3429·0a20·2020·2020··024-01-14).·····00037cf0:·3032·352d·3032·2d31·3529·0a20·2020·2020··025-02-15).·····
00037d00:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>00037d00:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>
00037d10:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T00037d10:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T
00037d20:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents00037d20:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents
00037d30:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·00037d30:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·
00037d40:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org00037d40:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org
00037d50:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont00037d50:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont
00037d60:·656e·745f·6772·6f75·705f·7379·7374·656d··ent_group_system00037d60:·656e·745f·6772·6f75·705f·7379·7374·656d··ent_group_system
633 B
html2text {}
    
Offset 36, 15 lines modifiedOffset 36, 15 lines modified
36 *****·Profile·Information·*****36 *****·Profile·Information·*****
37 Profile·Title·Profile·for·ANSSI·DAT-NT28·Minimal·Level37 Profile·Title·Profile·for·ANSSI·DAT-NT28·Minimal·Level
38 Profile·ID····xccdf_org.ssgproject.content_profile_anssi_np_nt28_minimal38 Profile·ID····xccdf_org.ssgproject.content_profile_anssi_np_nt28_minimal
39 ***·CPE·Platforms·***39 ***·CPE·Platforms·***
40 ····*·cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~40 ····*·cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~
41 *****·Revision·History·*****41 *****·Revision·History·*****
42 Current·version:·0.1.6542 Current·version:·0.1.65
43 ····*·draft·(as·of·2024-01-14)43 ····*·draft·(as·of·2025-02-15)
44 *****·Table·of·Contents·*****44 *****·Table·of·Contents·*****
45 ···1.·System_Settings45 ···1.·System_Settings
46 ·········1.·Installing_and_Maintaining_Software46 ·········1.·Installing_and_Maintaining_Software
47 ·········2.·File_Permissions_and_Masks47 ·········2.·File_Permissions_and_Masks
48 ···2.·Services48 ···2.·Services
49 ·········1.·APT_service_configuration49 ·········1.·APT_service_configuration
50 ·········2.·Deprecated_services50 ·········2.·Deprecated_services
1.89 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu1604-guide-anssi_np_nt28_restrictive.html
    
Offset 14285, 15 lines modifiedOffset 14285, 15 lines modified
00037cc0:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current00037cc0:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current
00037cd0:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron00037cd0:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron
00037ce0:·673e·302e·312e·3635·3c2f·7374·726f·6e67··g>0.1.65</strong00037ce0:·673e·302e·312e·3635·3c2f·7374·726f·6e67··g>0.1.65</strong
00037cf0:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st00037cf0:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st
00037d00:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro00037d00:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro
00037d10:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············00037d10:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············
00037d20:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·200037d20:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·2
00037d30:·3032·342d·3031·2d31·3429·0a20·2020·2020··024-01-14).·····00037d30:·3032·352d·3032·2d31·3529·0a20·2020·2020··025-02-15).·····
00037d40:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>00037d40:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>
00037d50:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T00037d50:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T
00037d60:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents00037d60:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents
00037d70:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·00037d70:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·
00037d80:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org00037d80:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org
00037d90:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont00037d90:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont
00037da0:·656e·745f·6772·6f75·705f·7379·7374·656d··ent_group_system00037da0:·656e·745f·6772·6f75·705f·7379·7374·656d··ent_group_system
642 B
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *****·Profile·Information·*****37 *****·Profile·Information·*****
38 Profile·Title·Profile·for·ANSSI·DAT-NT28·Restrictive·Level38 Profile·Title·Profile·for·ANSSI·DAT-NT28·Restrictive·Level
39 Profile·ID····xccdf_org.ssgproject.content_profile_anssi_np_nt28_restrictive39 Profile·ID····xccdf_org.ssgproject.content_profile_anssi_np_nt28_restrictive
40 ***·CPE·Platforms·***40 ***·CPE·Platforms·***
41 ····*·cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~41 ····*·cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~
42 *****·Revision·History·*****42 *****·Revision·History·*****
43 Current·version:·0.1.6543 Current·version:·0.1.65
44 ····*·draft·(as·of·2024-01-14)44 ····*·draft·(as·of·2025-02-15)
45 *****·Table·of·Contents·*****45 *****·Table·of·Contents·*****
46 ···1.·System_Settings46 ···1.·System_Settings
47 ·········1.·Installing_and_Maintaining_Software47 ·········1.·Installing_and_Maintaining_Software
48 ·········2.·System_Accounting_with_auditd48 ·········2.·System_Accounting_with_auditd
49 ·········3.·Configure_Syslog49 ·········3.·Configure_Syslog
50 ·········4.·File_Permissions_and_Masks50 ·········4.·File_Permissions_and_Masks
51 ···2.·Services51 ···2.·Services
1.98 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu1604-guide-standard.html
    
Offset 14287, 16 lines modifiedOffset 14287, 16 lines modified
00037ce0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</00037ce0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</
00037cf0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve00037cf0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve
00037d00:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>000037d00:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>0
00037d10:·2e31·2e36·353c·2f73·7472·6f6e·673e·3c2f··.1.65</strong></00037d10:·2e31·2e36·353c·2f73·7472·6f6e·673e·3c2f··.1.65</strong></
00037d20:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron00037d20:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron
00037d30:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>00037d30:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>
00037d40:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00037d40:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00037d50:·2020·2020·2028·6173·206f·6620·3230·3234·······(as·of·202400037d50:·2020·2020·2028·6173·206f·6620·3230·3235·······(as·of·2025
00037d60:·2d30·312d·3134·290a·2020·2020·2020·2020··-01-14).········00037d60:·2d30·322d·3135·290a·2020·2020·2020·2020··-02-15).········
00037d70:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u00037d70:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u
00037d80:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl00037d80:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl
00037d90:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h00037d90:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h
00037da0:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre00037da0:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre
00037db0:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss00037db0:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss
00037dc0:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content00037dc0:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content
00037dd0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S00037dd0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S
630 B
html2text {}
    
Offset 38, 15 lines modifiedOffset 38, 15 lines modified
38 *****·Profile·Information·*****38 *****·Profile·Information·*****
39 Profile·Title·Standard·System·Security·Profile·for·Ubuntu·16.0439 Profile·Title·Standard·System·Security·Profile·for·Ubuntu·16.04
40 Profile·ID····xccdf_org.ssgproject.content_profile_standard40 Profile·ID····xccdf_org.ssgproject.content_profile_standard
41 ***·CPE·Platforms·***41 ***·CPE·Platforms·***
42 ····*·cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~42 ····*·cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~
43 *****·Revision·History·*****43 *****·Revision·History·*****
44 Current·version:·0.1.6544 Current·version:·0.1.65
45 ····*·draft·(as·of·2024-01-14)45 ····*·draft·(as·of·2025-02-15)
46 *****·Table·of·Contents·*****46 *****·Table·of·Contents·*****
47 ···1.·System_Settings47 ···1.·System_Settings
48 ·········1.·Installing_and_Maintaining_Software48 ·········1.·Installing_and_Maintaining_Software
49 ·········2.·System_Accounting_with_auditd49 ·········2.·System_Accounting_with_auditd
50 ·········3.·Configure_Syslog50 ·········3.·Configure_Syslog
51 ·········4.·File_Permissions_and_Masks51 ·········4.·File_Permissions_and_Masks
52 ···2.·Services52 ···2.·Services
2.02 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu1804-guide-anssi_np_nt28_average.html
    
Offset 14286, 16 lines modifiedOffset 14286, 16 lines modified
00037cd0:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p00037cd0:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p
00037ce0:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version00037ce0:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version
00037cf0:·3a20·3c73·7472·6f6e·673e·302e·312e·3635··:·<strong>0.1.6500037cf0:·3a20·3c73·7472·6f6e·673e·302e·312e·3635··:·<strong>0.1.65
00037d00:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul00037d00:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul
00037d10:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra00037d10:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra
00037d20:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····00037d20:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····
00037d30:·2020·2020·2020·2020·2020·2020·2020·2020··················00037d30:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037d40:·2861·7320·6f66·2032·3032·342d·3031·2d31··(as·of·2024-01-100037d40:·2861·7320·6f66·2032·3032·352d·3032·2d31··(as·of·2025-02-1
00037d50:·3429·0a20·2020·2020·2020·2020·2020·2020··4).·············00037d50:·3529·0a20·2020·2020·2020·2020·2020·2020··5).·············
00037d60:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d00037d60:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d
00037d70:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·00037d70:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·
00037d80:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol00037d80:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol
00037d90:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x00037d90:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x
00037da0:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj00037da0:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj
00037db0:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou00037db0:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou
00037dc0:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System00037dc0:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System
645 B
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *****·Profile·Information·*****37 *****·Profile·Information·*****
38 Profile·Title·Profile·for·ANSSI·DAT-NT28·Average·(Intermediate)·Level38 Profile·Title·Profile·for·ANSSI·DAT-NT28·Average·(Intermediate)·Level
39 Profile·ID····xccdf_org.ssgproject.content_profile_anssi_np_nt28_average39 Profile·ID····xccdf_org.ssgproject.content_profile_anssi_np_nt28_average
40 ***·CPE·Platforms·***40 ***·CPE·Platforms·***
41 ····*·cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~41 ····*·cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~
42 *****·Revision·History·*****42 *****·Revision·History·*****
43 Current·version:·0.1.6543 Current·version:·0.1.65
44 ····*·draft·(as·of·2024-01-14)44 ····*·draft·(as·of·2025-02-15)
45 *****·Table·of·Contents·*****45 *****·Table·of·Contents·*****
46 ···1.·System_Settings46 ···1.·System_Settings
47 ·········1.·Installing_and_Maintaining_Software47 ·········1.·Installing_and_Maintaining_Software
48 ·········2.·Configure_Syslog48 ·········2.·Configure_Syslog
49 ·········3.·File_Permissions_and_Masks49 ·········3.·File_Permissions_and_Masks
50 ···2.·Services50 ···2.·Services
51 ·········1.·APT_service_configuration51 ·········1.·APT_service_configuration
1.9 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu1804-guide-anssi_np_nt28_high.html
    
Offset 14288, 15 lines modifiedOffset 14288, 15 lines modified
00037cf0:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v00037cf0:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v
00037d00:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>00037d00:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>
00037d10:·302e·312e·3635·3c2f·7374·726f·6e67·3e3c··0.1.65</strong><00037d10:·302e·312e·3635·3c2f·7374·726f·6e67·3e3c··0.1.65</strong><
00037d20:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro00037d20:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro
00037d30:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong00037d30:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong
00037d40:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············00037d40:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············
00037d50:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·20200037d50:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·202
00037d60:·342d·3031·2d31·3429·0a20·2020·2020·2020··4-01-14).·······00037d60:·352d·3032·2d31·3529·0a20·2020·2020·2020··5-02-15).·······
00037d70:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></00037d70:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></
00037d80:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab00037d80:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab
00037d90:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</00037d90:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</
00037da0:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr00037da0:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr
00037db0:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s00037db0:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s
00037dc0:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten00037dc0:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten
00037dd0:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">00037dd0:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">
667 B
html2text {}
    
Offset 38, 15 lines modifiedOffset 38, 15 lines modified
38 *****·Profile·Information·*****38 *****·Profile·Information·*****
39 Profile·Title·Profile·for·ANSSI·DAT-NT28·High·(Enforced)·Level39 Profile·Title·Profile·for·ANSSI·DAT-NT28·High·(Enforced)·Level
40 Profile·ID····xccdf_org.ssgproject.content_profile_anssi_np_nt28_high40 Profile·ID····xccdf_org.ssgproject.content_profile_anssi_np_nt28_high
41 ***·CPE·Platforms·***41 ***·CPE·Platforms·***
42 ····*·cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~42 ····*·cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~
43 *****·Revision·History·*****43 *****·Revision·History·*****
44 Current·version:·0.1.6544 Current·version:·0.1.65
45 ····*·draft·(as·of·2024-01-14)45 ····*·draft·(as·of·2025-02-15)
46 *****·Table·of·Contents·*****46 *****·Table·of·Contents·*****
47 ···1.·System_Settings47 ···1.·System_Settings
48 ·········1.·Installing_and_Maintaining_Software48 ·········1.·Installing_and_Maintaining_Software
49 ·········2.·System_Accounting_with_auditd49 ·········2.·System_Accounting_with_auditd
50 ·········3.·GRUB2_bootloader_configuration50 ·········3.·GRUB2_bootloader_configuration
51 ·········4.·Configure_Syslog51 ·········4.·Configure_Syslog
52 ·········5.·File_Permissions_and_Masks52 ·········5.·File_Permissions_and_Masks
1.87 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu1804-guide-anssi_np_nt28_minimal.html
    
Offset 14281, 15 lines modifiedOffset 14281, 15 lines modified
00037c80:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current00037c80:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current
00037c90:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron00037c90:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron
00037ca0:·673e·302e·312e·3635·3c2f·7374·726f·6e67··g>0.1.65</strong00037ca0:·673e·302e·312e·3635·3c2f·7374·726f·6e67··g>0.1.65</strong
00037cb0:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st00037cb0:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st
00037cc0:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro00037cc0:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro
00037cd0:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············00037cd0:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············
00037ce0:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·200037ce0:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·2
00037cf0:·3032·342d·3031·2d31·3429·0a20·2020·2020··024-01-14).·····00037cf0:·3032·352d·3032·2d31·3529·0a20·2020·2020··025-02-15).·····
00037d00:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>00037d00:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>
00037d10:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T00037d10:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T
00037d20:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents00037d20:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents
00037d30:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·00037d30:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·
00037d40:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org00037d40:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org
00037d50:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont00037d50:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont
00037d60:·656e·745f·6772·6f75·705f·7379·7374·656d··ent_group_system00037d60:·656e·745f·6772·6f75·705f·7379·7374·656d··ent_group_system
633 B
html2text {}
    
Offset 36, 15 lines modifiedOffset 36, 15 lines modified
36 *****·Profile·Information·*****36 *****·Profile·Information·*****
37 Profile·Title·Profile·for·ANSSI·DAT-NT28·Minimal·Level37 Profile·Title·Profile·for·ANSSI·DAT-NT28·Minimal·Level
38 Profile·ID····xccdf_org.ssgproject.content_profile_anssi_np_nt28_minimal38 Profile·ID····xccdf_org.ssgproject.content_profile_anssi_np_nt28_minimal
39 ***·CPE·Platforms·***39 ***·CPE·Platforms·***
40 ····*·cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~40 ····*·cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~
41 *****·Revision·History·*****41 *****·Revision·History·*****
42 Current·version:·0.1.6542 Current·version:·0.1.65
43 ····*·draft·(as·of·2024-01-14)43 ····*·draft·(as·of·2025-02-15)
44 *****·Table·of·Contents·*****44 *****·Table·of·Contents·*****
45 ···1.·System_Settings45 ···1.·System_Settings
46 ·········1.·Installing_and_Maintaining_Software46 ·········1.·Installing_and_Maintaining_Software
47 ·········2.·File_Permissions_and_Masks47 ·········2.·File_Permissions_and_Masks
48 ···2.·Services48 ···2.·Services
49 ·········1.·APT_service_configuration49 ·········1.·APT_service_configuration
50 ·········2.·Deprecated_services50 ·········2.·Deprecated_services
1.89 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu1804-guide-anssi_np_nt28_restrictive.html
    
Offset 14285, 15 lines modifiedOffset 14285, 15 lines modified
00037cc0:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current00037cc0:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current
00037cd0:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron00037cd0:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron
00037ce0:·673e·302e·312e·3635·3c2f·7374·726f·6e67··g>0.1.65</strong00037ce0:·673e·302e·312e·3635·3c2f·7374·726f·6e67··g>0.1.65</strong
00037cf0:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st00037cf0:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st
00037d00:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro00037d00:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro
00037d10:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············00037d10:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············
00037d20:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·200037d20:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·2
00037d30:·3032·342d·3031·2d31·3429·0a20·2020·2020··024-01-14).·····00037d30:·3032·352d·3032·2d31·3529·0a20·2020·2020··025-02-15).·····
00037d40:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>00037d40:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>
00037d50:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T00037d50:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T
00037d60:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents00037d60:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents
00037d70:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·00037d70:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·
00037d80:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org00037d80:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org
00037d90:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont00037d90:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont
00037da0:·656e·745f·6772·6f75·705f·7379·7374·656d··ent_group_system00037da0:·656e·745f·6772·6f75·705f·7379·7374·656d··ent_group_system
642 B
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *****·Profile·Information·*****37 *****·Profile·Information·*****
38 Profile·Title·Profile·for·ANSSI·DAT-NT28·Restrictive·Level38 Profile·Title·Profile·for·ANSSI·DAT-NT28·Restrictive·Level
39 Profile·ID····xccdf_org.ssgproject.content_profile_anssi_np_nt28_restrictive39 Profile·ID····xccdf_org.ssgproject.content_profile_anssi_np_nt28_restrictive
40 ***·CPE·Platforms·***40 ***·CPE·Platforms·***
41 ····*·cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~41 ····*·cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~
42 *****·Revision·History·*****42 *****·Revision·History·*****
43 Current·version:·0.1.6543 Current·version:·0.1.65
44 ····*·draft·(as·of·2024-01-14)44 ····*·draft·(as·of·2025-02-15)
45 *****·Table·of·Contents·*****45 *****·Table·of·Contents·*****
46 ···1.·System_Settings46 ···1.·System_Settings
47 ·········1.·Installing_and_Maintaining_Software47 ·········1.·Installing_and_Maintaining_Software
48 ·········2.·System_Accounting_with_auditd48 ·········2.·System_Accounting_with_auditd
49 ·········3.·Configure_Syslog49 ·········3.·Configure_Syslog
50 ·········4.·File_Permissions_and_Masks50 ·········4.·File_Permissions_and_Masks
51 ···2.·Services51 ···2.·Services
1.83 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu1804-guide-cis.html
    
Offset 14282, 15 lines modifiedOffset 14282, 15 lines modified
00037c90:·6f72·793c·2f68·323e·3c70·3e43·7572·7265··ory</h2><p>Curre00037c90:·6f72·793c·2f68·323e·3c70·3e43·7572·7265··ory</h2><p>Curre
00037ca0:·6e74·2076·6572·7369·6f6e·3a20·3c73·7472··nt·version:·<str00037ca0:·6e74·2076·6572·7369·6f6e·3a20·3c73·7472··nt·version:·<str
00037cb0:·6f6e·673e·302e·312e·3635·3c2f·7374·726f··ong>0.1.65</stro00037cb0:·6f6e·673e·302e·312e·3635·3c2f·7374·726f··ong>0.1.65</stro
00037cc0:·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c··ng></p><ul><li><00037cc0:·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c··ng></p><ul><li><
00037cd0:·7374·726f·6e67·3e64·7261·6674·3c2f·7374··strong>draft</st00037cd0:·7374·726f·6e67·3e64·7261·6674·3c2f·7374··strong>draft</st
00037ce0:·726f·6e67·3e0a·2020·2020·2020·2020·2020··rong>.··········00037ce0:·726f·6e67·3e0a·2020·2020·2020·2020·2020··rong>.··········
00037cf0:·2020·2020·2020·2020·2020·2861·7320·6f66············(as·of00037cf0:·2020·2020·2020·2020·2020·2861·7320·6f66············(as·of
00037d00:·2032·3032·342d·3031·2d31·3429·0a20·2020···2024-01-14).···00037d00:·2032·3032·352d·3032·2d31·3529·0a20·2020···2025-02-15).···
00037d10:·2020·2020·2020·2020·2020·2020·203c·2f6c···············</l00037d10:·2020·2020·2020·2020·2020·2020·203c·2f6c···············</l
00037d20:·693e·3c2f·756c·3e3c·2f64·6976·3e3c·6832··i></ul></div><h200037d20:·693e·3c2f·756c·3e3c·2f64·6976·3e3c·6832··i></ul></div><h2
00037d30:·3e54·6162·6c65·206f·6620·436f·6e74·656e··>Table·of·Conten00037d30:·3e54·6162·6c65·206f·6620·436f·6e74·656e··>Table·of·Conten
00037d40:·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c··ts</h2><ol><li><00037d40:·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c··ts</h2><ol><li><
00037d50:·6120·6872·6566·3d22·2378·6363·6466·5f6f··a·href="#xccdf_o00037d50:·6120·6872·6566·3d22·2378·6363·6466·5f6f··a·href="#xccdf_o
00037d60:·7267·2e73·7367·7072·6f6a·6563·742e·636f··rg.ssgproject.co00037d60:·7267·2e73·7367·7072·6f6a·6563·742e·636f··rg.ssgproject.co
00037d70:·6e74·656e·745f·6772·6f75·705f·7379·7374··ntent_group_syst00037d70:·6e74·656e·745f·6772·6f75·705f·7379·7374··ntent_group_syst
625 B
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *****·Profile·Information·*****37 *****·Profile·Information·*****
38 Profile·Title·CIS·Ubuntu·18.04·LTS·Benchmark38 Profile·Title·CIS·Ubuntu·18.04·LTS·Benchmark
39 Profile·ID····xccdf_org.ssgproject.content_profile_cis39 Profile·ID····xccdf_org.ssgproject.content_profile_cis
40 ***·CPE·Platforms·***40 ***·CPE·Platforms·***
41 ····*·cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~41 ····*·cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~
42 *****·Revision·History·*****42 *****·Revision·History·*****
43 Current·version:·0.1.6543 Current·version:·0.1.65
44 ····*·draft·(as·of·2024-01-14)44 ····*·draft·(as·of·2025-02-15)
45 *****·Table·of·Contents·*****45 *****·Table·of·Contents·*****
46 ···1.·System_Settings46 ···1.·System_Settings
47 ·········1.·Installing_and_Maintaining_Software47 ·········1.·Installing_and_Maintaining_Software
48 ·········2.·System_Accounting_with_auditd48 ·········2.·System_Accounting_with_auditd
49 ·········3.·Network_Configuration_and_Firewalls49 ·········3.·Network_Configuration_and_Firewalls
50 ·········4.·File_Permissions_and_Masks50 ·········4.·File_Permissions_and_Masks
51 ···2.·Services51 ···2.·Services
1.98 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu1804-guide-standard.html
    
Offset 14287, 16 lines modifiedOffset 14287, 16 lines modified
00037ce0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</00037ce0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</
00037cf0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve00037cf0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve
00037d00:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>000037d00:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>0
00037d10:·2e31·2e36·353c·2f73·7472·6f6e·673e·3c2f··.1.65</strong></00037d10:·2e31·2e36·353c·2f73·7472·6f6e·673e·3c2f··.1.65</strong></
00037d20:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron00037d20:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron
00037d30:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>00037d30:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>
00037d40:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00037d40:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00037d50:·2020·2020·2028·6173·206f·6620·3230·3234·······(as·of·202400037d50:·2020·2020·2028·6173·206f·6620·3230·3235·······(as·of·2025
00037d60:·2d30·312d·3134·290a·2020·2020·2020·2020··-01-14).········00037d60:·2d30·322d·3135·290a·2020·2020·2020·2020··-02-15).········
00037d70:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u00037d70:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u
00037d80:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl00037d80:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl
00037d90:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h00037d90:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h
00037da0:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre00037da0:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre
00037db0:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss00037db0:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss
00037dc0:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content00037dc0:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content
00037dd0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S00037dd0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S
630 B
html2text {}
    
Offset 38, 15 lines modifiedOffset 38, 15 lines modified
38 *****·Profile·Information·*****38 *****·Profile·Information·*****
39 Profile·Title·Standard·System·Security·Profile·for·Ubuntu·18.0439 Profile·Title·Standard·System·Security·Profile·for·Ubuntu·18.04
40 Profile·ID····xccdf_org.ssgproject.content_profile_standard40 Profile·ID····xccdf_org.ssgproject.content_profile_standard
41 ***·CPE·Platforms·***41 ***·CPE·Platforms·***
42 ····*·cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~42 ····*·cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~
43 *****·Revision·History·*****43 *****·Revision·History·*****
44 Current·version:·0.1.6544 Current·version:·0.1.65
45 ····*·draft·(as·of·2024-01-14)45 ····*·draft·(as·of·2025-02-15)
46 *****·Table·of·Contents·*****46 *****·Table·of·Contents·*****
47 ···1.·System_Settings47 ···1.·System_Settings
48 ·········1.·Installing_and_Maintaining_Software48 ·········1.·Installing_and_Maintaining_Software
49 ·········2.·System_Accounting_with_auditd49 ·········2.·System_Accounting_with_auditd
50 ·········3.·Configure_Syslog50 ·········3.·Configure_Syslog
51 ·········4.·File_Permissions_and_Masks51 ·········4.·File_Permissions_and_Masks
52 ···2.·Services52 ···2.·Services
1.9 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2004-guide-cis_level1_server.html
    
Offset 14284, 15 lines modifiedOffset 14284, 15 lines modified
00037cb0:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C00037cb0:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C
00037cc0:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·00037cc0:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·
00037cd0:·3c73·7472·6f6e·673e·302e·312e·3635·3c2f··<strong>0.1.65</00037cd0:·3c73·7472·6f6e·673e·302e·312e·3635·3c2f··<strong>0.1.65</
00037ce0:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><00037ce0:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><
00037cf0:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft00037cf0:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft
00037d00:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······00037d00:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······
00037d10:·2020·2020·2020·2020·2020·2020·2020·2861················(a00037d10:·2020·2020·2020·2020·2020·2020·2020·2861················(a
00037d20:·7320·6f66·2032·3032·342d·3031·2d31·3429··s·of·2024-01-14)00037d20:·7320·6f66·2032·3032·352d·3032·2d31·3529··s·of·2025-02-15)
00037d30:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00037d30:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00037d40:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div00037d40:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div
00037d50:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co00037d50:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co
00037d60:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><00037d60:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><
00037d70:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc00037d70:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc
00037d80:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec00037d80:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec
00037d90:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_00037d90:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_
665 B
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *****·Profile·Information·*****37 *****·Profile·Information·*****
38 Profile·Title·CIS·Ubuntu·20.04·Level·1·Server·Benchmark38 Profile·Title·CIS·Ubuntu·20.04·Level·1·Server·Benchmark
39 Profile·ID····xccdf_org.ssgproject.content_profile_cis_level1_server39 Profile·ID····xccdf_org.ssgproject.content_profile_cis_level1_server
40 ***·CPE·Platforms·***40 ***·CPE·Platforms·***
41 ····*·cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~41 ····*·cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~
42 *****·Revision·History·*****42 *****·Revision·History·*****
43 Current·version:·0.1.6543 Current·version:·0.1.65
44 ····*·draft·(as·of·2024-01-14)44 ····*·draft·(as·of·2025-02-15)
45 *****·Table·of·Contents·*****45 *****·Table·of·Contents·*****
46 ···1.·System_Settings46 ···1.·System_Settings
47 ·········1.·Installing_and_Maintaining_Software47 ·········1.·Installing_and_Maintaining_Software
48 ·········2.·Account_and_Access_Control48 ·········2.·Account_and_Access_Control
49 ·········3.·GRUB2_bootloader_configuration49 ·········3.·GRUB2_bootloader_configuration
50 ·········4.·Configure_Syslog50 ·········4.·Configure_Syslog
51 ·········5.·Network_Configuration_and_Firewalls51 ·········5.·Network_Configuration_and_Firewalls
1.92 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2004-guide-cis_level1_workstation.html
    
Offset 14285, 15 lines modifiedOffset 14285, 15 lines modified
00037cc0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu00037cc0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu
00037cd0:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<00037cd0:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<
00037ce0:·7374·726f·6e67·3e30·2e31·2e36·353c·2f73··strong>0.1.65</s00037ce0:·7374·726f·6e67·3e30·2e31·2e36·353c·2f73··strong>0.1.65</s
00037cf0:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l00037cf0:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l
00037d00:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<00037d00:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<
00037d10:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······00037d10:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······
00037d20:·2020·2020·2020·2020·2020·2020·2028·6173···············(as00037d20:·2020·2020·2020·2020·2020·2020·2028·6173···············(as
00037d30:·206f·6620·3230·3234·2d30·312d·3134·290a···of·2024-01-14).00037d30:·206f·6620·3230·3235·2d30·322d·3135·290a···of·2025-02-15).
00037d40:·2020·2020·2020·2020·2020·2020·2020·2020··················00037d40:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037d50:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>00037d50:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>
00037d60:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con00037d60:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con
00037d70:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l00037d70:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l
00037d80:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd00037d80:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd
00037d90:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject00037d90:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject
00037da0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s00037da0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s
675 B
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *****·Profile·Information·*****37 *****·Profile·Information·*****
38 Profile·Title·CIS·Ubuntu·20.04·Level·1·Workstation·Benchmark38 Profile·Title·CIS·Ubuntu·20.04·Level·1·Workstation·Benchmark
39 Profile·ID····xccdf_org.ssgproject.content_profile_cis_level1_workstation39 Profile·ID····xccdf_org.ssgproject.content_profile_cis_level1_workstation
40 ***·CPE·Platforms·***40 ***·CPE·Platforms·***
41 ····*·cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~41 ····*·cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~
42 *****·Revision·History·*****42 *****·Revision·History·*****
43 Current·version:·0.1.6543 Current·version:·0.1.65
44 ····*·draft·(as·of·2024-01-14)44 ····*·draft·(as·of·2025-02-15)
45 *****·Table·of·Contents·*****45 *****·Table·of·Contents·*****
46 ···1.·System_Settings46 ···1.·System_Settings
47 ·········1.·Installing_and_Maintaining_Software47 ·········1.·Installing_and_Maintaining_Software
48 ·········2.·Account_and_Access_Control48 ·········2.·Account_and_Access_Control
49 ·········3.·GRUB2_bootloader_configuration49 ·········3.·GRUB2_bootloader_configuration
50 ·········4.·Configure_Syslog50 ·········4.·Configure_Syslog
51 ·········5.·Network_Configuration_and_Firewalls51 ·········5.·Network_Configuration_and_Firewalls
1.89 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2004-guide-cis_level2_server.html
    
Offset 14284, 15 lines modifiedOffset 14284, 15 lines modified
00037cb0:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C00037cb0:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C
00037cc0:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·00037cc0:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·
00037cd0:·3c73·7472·6f6e·673e·302e·312e·3635·3c2f··<strong>0.1.65</00037cd0:·3c73·7472·6f6e·673e·302e·312e·3635·3c2f··<strong>0.1.65</
00037ce0:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><00037ce0:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><
00037cf0:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft00037cf0:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft
00037d00:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······00037d00:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······
00037d10:·2020·2020·2020·2020·2020·2020·2020·2861················(a00037d10:·2020·2020·2020·2020·2020·2020·2020·2861················(a
00037d20:·7320·6f66·2032·3032·342d·3031·2d31·3429··s·of·2024-01-14)00037d20:·7320·6f66·2032·3032·352d·3032·2d31·3529··s·of·2025-02-15)
00037d30:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00037d30:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00037d40:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div00037d40:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div
00037d50:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co00037d50:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co
00037d60:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><00037d60:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><
00037d70:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc00037d70:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc
00037d80:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec00037d80:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec
00037d90:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_00037d90:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_
659 B
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *****·Profile·Information·*****37 *****·Profile·Information·*****
38 Profile·Title·CIS·Ubuntu·20.04·Level·2·Server·Benchmark38 Profile·Title·CIS·Ubuntu·20.04·Level·2·Server·Benchmark
39 Profile·ID····xccdf_org.ssgproject.content_profile_cis_level2_server39 Profile·ID····xccdf_org.ssgproject.content_profile_cis_level2_server
40 ***·CPE·Platforms·***40 ***·CPE·Platforms·***
41 ····*·cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~41 ····*·cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~
42 *****·Revision·History·*****42 *****·Revision·History·*****
43 Current·version:·0.1.6543 Current·version:·0.1.65
44 ····*·draft·(as·of·2024-01-14)44 ····*·draft·(as·of·2025-02-15)
45 *****·Table·of·Contents·*****45 *****·Table·of·Contents·*****
46 ···1.·System_Settings46 ···1.·System_Settings
47 ·········1.·Installing_and_Maintaining_Software47 ·········1.·Installing_and_Maintaining_Software
48 ·········2.·Account_and_Access_Control48 ·········2.·Account_and_Access_Control
49 ·········3.·System_Accounting_with_auditd49 ·········3.·System_Accounting_with_auditd
50 ·········4.·GRUB2_bootloader_configuration50 ·········4.·GRUB2_bootloader_configuration
51 ·········5.·Configure_Syslog51 ·········5.·Configure_Syslog
1.91 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2004-guide-cis_level2_workstation.html
    
Offset 14285, 15 lines modifiedOffset 14285, 15 lines modified
00037cc0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu00037cc0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu
00037cd0:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<00037cd0:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<
00037ce0:·7374·726f·6e67·3e30·2e31·2e36·353c·2f73··strong>0.1.65</s00037ce0:·7374·726f·6e67·3e30·2e31·2e36·353c·2f73··strong>0.1.65</s
00037cf0:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l00037cf0:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l
00037d00:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<00037d00:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<
00037d10:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······00037d10:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······
00037d20:·2020·2020·2020·2020·2020·2020·2028·6173···············(as00037d20:·2020·2020·2020·2020·2020·2020·2028·6173···············(as
00037d30:·206f·6620·3230·3234·2d30·312d·3134·290a···of·2024-01-14).00037d30:·206f·6620·3230·3235·2d30·322d·3135·290a···of·2025-02-15).
00037d40:·2020·2020·2020·2020·2020·2020·2020·2020··················00037d40:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037d50:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>00037d50:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>
00037d60:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con00037d60:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con
00037d70:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l00037d70:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l
00037d80:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd00037d80:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd
00037d90:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject00037d90:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject
00037da0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s00037da0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s
669 B
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *****·Profile·Information·*****37 *****·Profile·Information·*****
38 Profile·Title·CIS·Ubuntu·20.04·Level·2·Workstation·Benchmark38 Profile·Title·CIS·Ubuntu·20.04·Level·2·Workstation·Benchmark
39 Profile·ID····xccdf_org.ssgproject.content_profile_cis_level2_workstation39 Profile·ID····xccdf_org.ssgproject.content_profile_cis_level2_workstation
40 ***·CPE·Platforms·***40 ***·CPE·Platforms·***
41 ····*·cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~41 ····*·cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~
42 *****·Revision·History·*****42 *****·Revision·History·*****
43 Current·version:·0.1.6543 Current·version:·0.1.65
44 ····*·draft·(as·of·2024-01-14)44 ····*·draft·(as·of·2025-02-15)
45 *****·Table·of·Contents·*****45 *****·Table·of·Contents·*****
46 ···1.·System_Settings46 ···1.·System_Settings
47 ·········1.·Installing_and_Maintaining_Software47 ·········1.·Installing_and_Maintaining_Software
48 ·········2.·Account_and_Access_Control48 ·········2.·Account_and_Access_Control
49 ·········3.·System_Accounting_with_auditd49 ·········3.·System_Accounting_with_auditd
50 ·········4.·GRUB2_bootloader_configuration50 ·········4.·GRUB2_bootloader_configuration
51 ·········5.·Configure_Syslog51 ·········5.·Configure_Syslog
2.0 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2004-guide-standard.html
    
Offset 14287, 16 lines modifiedOffset 14287, 16 lines modified
00037ce0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</00037ce0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</
00037cf0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve00037cf0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve
00037d00:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>000037d00:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>0
00037d10:·2e31·2e36·353c·2f73·7472·6f6e·673e·3c2f··.1.65</strong></00037d10:·2e31·2e36·353c·2f73·7472·6f6e·673e·3c2f··.1.65</strong></
00037d20:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron00037d20:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron
00037d30:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>00037d30:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>
00037d40:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00037d40:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00037d50:·2020·2020·2028·6173·206f·6620·3230·3234·······(as·of·202400037d50:·2020·2020·2028·6173·206f·6620·3230·3235·······(as·of·2025
00037d60:·2d30·312d·3134·290a·2020·2020·2020·2020··-01-14).········00037d60:·2d30·322d·3135·290a·2020·2020·2020·2020··-02-15).········
00037d70:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u00037d70:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u
00037d80:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl00037d80:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl
00037d90:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h00037d90:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h
00037da0:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre00037da0:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre
00037db0:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss00037db0:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss
00037dc0:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content00037dc0:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content
00037dd0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S00037dd0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S
654 B
html2text {}
    
Offset 38, 15 lines modifiedOffset 38, 15 lines modified
38 *****·Profile·Information·*****38 *****·Profile·Information·*****
39 Profile·Title·Standard·System·Security·Profile·for·Ubuntu·20.0439 Profile·Title·Standard·System·Security·Profile·for·Ubuntu·20.04
40 Profile·ID····xccdf_org.ssgproject.content_profile_standard40 Profile·ID····xccdf_org.ssgproject.content_profile_standard
41 ***·CPE·Platforms·***41 ***·CPE·Platforms·***
42 ····*·cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~42 ····*·cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~
43 *****·Revision·History·*****43 *****·Revision·History·*****
44 Current·version:·0.1.6544 Current·version:·0.1.65
45 ····*·draft·(as·of·2024-01-14)45 ····*·draft·(as·of·2025-02-15)
46 *****·Table·of·Contents·*****46 *****·Table·of·Contents·*****
47 ···1.·System_Settings47 ···1.·System_Settings
48 ·········1.·Installing_and_Maintaining_Software48 ·········1.·Installing_and_Maintaining_Software
49 ·········2.·Account_and_Access_Control49 ·········2.·Account_and_Access_Control
50 ·········3.·System_Accounting_with_auditd50 ·········3.·System_Accounting_with_auditd
51 ·········4.·Configure_Syslog51 ·········4.·Configure_Syslog
52 ·········5.·File_Permissions_and_Masks52 ·········5.·File_Permissions_and_Masks
2.0 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2004-guide-stig.html
    
Offset 14297, 16 lines modifiedOffset 14297, 16 lines modified
00037d80:·7369·6f6e·2048·6973·746f·7279·3c2f·6832··sion·History</h200037d80:·7369·6f6e·2048·6973·746f·7279·3c2f·6832··sion·History</h2
00037d90:·3e3c·703e·4375·7272·656e·7420·7665·7273··><p>Current·vers00037d90:·3e3c·703e·4375·7272·656e·7420·7665·7273··><p>Current·vers
00037da0:·696f·6e3a·203c·7374·726f·6e67·3e30·2e31··ion:·<strong>0.100037da0:·696f·6e3a·203c·7374·726f·6e67·3e30·2e31··ion:·<strong>0.1
00037db0:·2e36·353c·2f73·7472·6f6e·673e·3c2f·703e··.65</strong></p>00037db0:·2e36·353c·2f73·7472·6f6e·673e·3c2f·703e··.65</strong></p>
00037dc0:·3c75·6c3e·3c6c·693e·3c73·7472·6f6e·673e··<ul><li><strong>00037dc0:·3c75·6c3e·3c6c·693e·3c73·7472·6f6e·673e··<ul><li><strong>
00037dd0:·6472·6166·743c·2f73·7472·6f6e·673e·0a20··draft</strong>.·00037dd0:·6472·6166·743c·2f73·7472·6f6e·673e·0a20··draft</strong>.·
00037de0:·2020·2020·2020·2020·2020·2020·2020·2020··················00037de0:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037df0:·2020·2028·6173·206f·6620·3230·3234·2d30·····(as·of·2024-000037df0:·2020·2028·6173·206f·6620·3230·3235·2d30·····(as·of·2025-0
00037e00:·312d·3134·290a·2020·2020·2020·2020·2020··1-14).··········00037e00:·322d·3135·290a·2020·2020·2020·2020·2020··2-15).··········
00037e10:·2020·2020·2020·3c2f·6c69·3e3c·2f75·6c3e········</li></ul>00037e10:·2020·2020·2020·3c2f·6c69·3e3c·2f75·6c3e········</li></ul>
00037e20:·3c2f·6469·763e·3c68·323e·5461·626c·6520··</div><h2>Table·00037e20:·3c2f·6469·763e·3c68·323e·5461·626c·6520··</div><h2>Table·
00037e30:·6f66·2043·6f6e·7465·6e74·733c·2f68·323e··of·Contents</h2>00037e30:·6f66·2043·6f6e·7465·6e74·733c·2f68·323e··of·Contents</h2>
00037e40:·3c6f·6c3e·3c6c·693e·3c61·2068·7265·663d··<ol><li><a·href=00037e40:·3c6f·6c3e·3c6c·693e·3c61·2068·7265·663d··<ol><li><a·href=
00037e50:·2223·7863·6364·665f·6f72·672e·7373·6770··"#xccdf_org.ssgp00037e50:·2223·7863·6364·665f·6f72·672e·7373·6770··"#xccdf_org.ssgp
00037e60:·726f·6a65·6374·2e63·6f6e·7465·6e74·5f67··roject.content_g00037e60:·726f·6a65·6374·2e63·6f6e·7465·6e74·5f67··roject.content_g
00037e70:·726f·7570·5f73·7973·7465·6d22·3e53·7973··roup_system">Sys00037e70:·726f·7570·5f73·7973·7465·6d22·3e53·7973··roup_system">Sys
657 B
html2text {}
    
Offset 41, 15 lines modifiedOffset 41, 15 lines modified
41 Profile·Title·Canonical·Ubuntu·20.04·LTS·Security·Technical·Implementation41 Profile·Title·Canonical·Ubuntu·20.04·LTS·Security·Technical·Implementation
42 ··············Guide·(STIG)·V1R142 ··············Guide·(STIG)·V1R1
43 Profile·ID····xccdf_org.ssgproject.content_profile_stig43 Profile·ID····xccdf_org.ssgproject.content_profile_stig
44 ***·CPE·Platforms·***44 ***·CPE·Platforms·***
45 ····*·cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~45 ····*·cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~
46 *****·Revision·History·*****46 *****·Revision·History·*****
47 Current·version:·0.1.6547 Current·version:·0.1.65
48 ····*·draft·(as·of·2024-01-14)48 ····*·draft·(as·of·2025-02-15)
49 *****·Table·of·Contents·*****49 *****·Table·of·Contents·*****
50 ···1.·System_Settings50 ···1.·System_Settings
51 ·········1.·Installing_and_Maintaining_Software51 ·········1.·Installing_and_Maintaining_Software
52 ·········2.·Account_and_Access_Control52 ·········2.·Account_and_Access_Control
53 ·········3.·System_Accounting_with_auditd53 ·········3.·System_Accounting_with_auditd
54 ·········4.·AppArmor54 ·········4.·AppArmor
55 ·········5.·GRUB2_bootloader_configuration55 ·········5.·GRUB2_bootloader_configuration
1.9 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2204-guide-cis_level1_server.html
    
Offset 14284, 15 lines modifiedOffset 14284, 15 lines modified
00037cb0:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C00037cb0:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C
00037cc0:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·00037cc0:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·
00037cd0:·3c73·7472·6f6e·673e·302e·312e·3635·3c2f··<strong>0.1.65</00037cd0:·3c73·7472·6f6e·673e·302e·312e·3635·3c2f··<strong>0.1.65</
00037ce0:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><00037ce0:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><
00037cf0:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft00037cf0:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft
00037d00:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······00037d00:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······
00037d10:·2020·2020·2020·2020·2020·2020·2020·2861················(a00037d10:·2020·2020·2020·2020·2020·2020·2020·2861················(a
00037d20:·7320·6f66·2032·3032·342d·3031·2d31·3429··s·of·2024-01-14)00037d20:·7320·6f66·2032·3032·352d·3032·2d31·3529··s·of·2025-02-15)
00037d30:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00037d30:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00037d40:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div00037d40:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div
00037d50:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co00037d50:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co
00037d60:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><00037d60:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><
00037d70:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc00037d70:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc
00037d80:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec00037d80:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec
00037d90:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_00037d90:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_
665 B
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *****·Profile·Information·*****37 *****·Profile·Information·*****
38 Profile·Title·CIS·Ubuntu·22.04·Level·1·Server·Benchmark38 Profile·Title·CIS·Ubuntu·22.04·Level·1·Server·Benchmark
39 Profile·ID····xccdf_org.ssgproject.content_profile_cis_level1_server39 Profile·ID····xccdf_org.ssgproject.content_profile_cis_level1_server
40 ***·CPE·Platforms·***40 ***·CPE·Platforms·***
41 ····*·cpe:/o:canonical:ubuntu_linux:22.04::~~lts~~~41 ····*·cpe:/o:canonical:ubuntu_linux:22.04::~~lts~~~
42 *****·Revision·History·*****42 *****·Revision·History·*****
43 Current·version:·0.1.6543 Current·version:·0.1.65
44 ····*·draft·(as·of·2024-01-14)44 ····*·draft·(as·of·2025-02-15)
45 *****·Table·of·Contents·*****45 *****·Table·of·Contents·*****
46 ···1.·System_Settings46 ···1.·System_Settings
47 ·········1.·Installing_and_Maintaining_Software47 ·········1.·Installing_and_Maintaining_Software
48 ·········2.·Account_and_Access_Control48 ·········2.·Account_and_Access_Control
49 ·········3.·GRUB2_bootloader_configuration49 ·········3.·GRUB2_bootloader_configuration
50 ·········4.·Configure_Syslog50 ·········4.·Configure_Syslog
51 ·········5.·Network_Configuration_and_Firewalls51 ·········5.·Network_Configuration_and_Firewalls
1.92 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2204-guide-cis_level1_workstation.html
    
Offset 14285, 15 lines modifiedOffset 14285, 15 lines modified
00037cc0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu00037cc0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu
00037cd0:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<00037cd0:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<
00037ce0:·7374·726f·6e67·3e30·2e31·2e36·353c·2f73··strong>0.1.65</s00037ce0:·7374·726f·6e67·3e30·2e31·2e36·353c·2f73··strong>0.1.65</s
00037cf0:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l00037cf0:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l
00037d00:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<00037d00:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<
00037d10:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······00037d10:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······
00037d20:·2020·2020·2020·2020·2020·2020·2028·6173···············(as00037d20:·2020·2020·2020·2020·2020·2020·2028·6173···············(as
00037d30:·206f·6620·3230·3234·2d30·312d·3134·290a···of·2024-01-14).00037d30:·206f·6620·3230·3235·2d30·322d·3135·290a···of·2025-02-15).
00037d40:·2020·2020·2020·2020·2020·2020·2020·2020··················00037d40:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037d50:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>00037d50:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>
00037d60:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con00037d60:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con
00037d70:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l00037d70:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l
00037d80:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd00037d80:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd
00037d90:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject00037d90:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject
00037da0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s00037da0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s
675 B
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *****·Profile·Information·*****37 *****·Profile·Information·*****
38 Profile·Title·CIS·Ubuntu·22.04·Level·1·Workstation·Benchmark38 Profile·Title·CIS·Ubuntu·22.04·Level·1·Workstation·Benchmark
39 Profile·ID····xccdf_org.ssgproject.content_profile_cis_level1_workstation39 Profile·ID····xccdf_org.ssgproject.content_profile_cis_level1_workstation
40 ***·CPE·Platforms·***40 ***·CPE·Platforms·***
41 ····*·cpe:/o:canonical:ubuntu_linux:22.04::~~lts~~~41 ····*·cpe:/o:canonical:ubuntu_linux:22.04::~~lts~~~
42 *****·Revision·History·*****42 *****·Revision·History·*****
43 Current·version:·0.1.6543 Current·version:·0.1.65
44 ····*·draft·(as·of·2024-01-14)44 ····*·draft·(as·of·2025-02-15)
45 *****·Table·of·Contents·*****45 *****·Table·of·Contents·*****
46 ···1.·System_Settings46 ···1.·System_Settings
47 ·········1.·Installing_and_Maintaining_Software47 ·········1.·Installing_and_Maintaining_Software
48 ·········2.·Account_and_Access_Control48 ·········2.·Account_and_Access_Control
49 ·········3.·GRUB2_bootloader_configuration49 ·········3.·GRUB2_bootloader_configuration
50 ·········4.·Configure_Syslog50 ·········4.·Configure_Syslog
51 ·········5.·Network_Configuration_and_Firewalls51 ·········5.·Network_Configuration_and_Firewalls
701 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2204-guide-cis_level2_server.html
    
Offset 14284, 15 lines modifiedOffset 14284, 15 lines modified
00037cb0:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C00037cb0:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C
00037cc0:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·00037cc0:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·
00037cd0:·3c73·7472·6f6e·673e·302e·312e·3635·3c2f··<strong>0.1.65</00037cd0:·3c73·7472·6f6e·673e·302e·312e·3635·3c2f··<strong>0.1.65</
00037ce0:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><00037ce0:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><
00037cf0:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft00037cf0:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft
00037d00:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······00037d00:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······
00037d10:·2020·2020·2020·2020·2020·2020·2020·2861················(a00037d10:·2020·2020·2020·2020·2020·2020·2020·2861················(a
00037d20:·7320·6f66·2032·3032·342d·3031·2d31·3429··s·of·2024-01-14)00037d20:·7320·6f66·2032·3032·352d·3032·2d31·3529··s·of·2025-02-15)
00037d30:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00037d30:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00037d40:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div00037d40:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div
00037d50:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co00037d50:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co
00037d60:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><00037d60:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><
00037d70:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc00037d70:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc
00037d80:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec00037d80:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec
00037d90:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_00037d90:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_
Offset 40731, 23 lines modifiedOffset 40731, 23 lines modified
0009f1a0:·7265·640a·2020·2d20·7265·7374·7269·6374··red.··-·restrict0009f1a0:·7265·640a·2020·2d20·7265·7374·7269·6374··red.··-·restrict
0009f1b0:·5f73·7472·6174·6567·790a·0a2d·206e·616d··_strategy..-·nam0009f1b0:·5f73·7472·6174·6567·790a·0a2d·206e·616d··_strategy..-·nam
0009f1c0:·653a·2053·6574·2061·7263·6869·7465·6374··e:·Set·architect0009f1c0:·653a·2053·6574·2061·7263·6869·7465·6374··e:·Set·architect
0009f1d0:·7572·6520·666f·7220·6175·6469·7420·6368··ure·for·audit·ch0009f1d0:·7572·6520·666f·7220·6175·6469·7420·6368··ure·for·audit·ch
0009f1e0:·6d6f·6420·7461·736b·730a·2020·7365·745f··mod·tasks.··set_0009f1e0:·6d6f·6420·7461·736b·730a·2020·7365·745f··mod·tasks.··set_
0009f1f0:·6661·6374·3a0a·2020·2020·6175·6469·745f··fact:.····audit_0009f1f0:·6661·6374·3a0a·2020·2020·6175·6469·745f··fact:.····audit_
0009f200:·6172·6368·3a20·6236·340a·2020·7768·656e··arch:·b64.··when0009f200:·6172·6368·3a20·6236·340a·2020·7768·656e··arch:·b64.··when
0009f210:·3a0a·2020·2d20·616e·7369·626c·655f·7669··:.··-·ansible_vi 
0009f220:·7274·7561·6c69·7a61·7469·6f6e·5f74·7970··rtualization_typ 
0009f230:·6520·6e6f·7420·696e·205b·2264·6f63·6b65··e·not·in·["docke 
0009f240:·7222·2c20·226c·7863·222c·2022·6f70·656e··r",·"lxc",·"open 
0009f250:·767a·222c·2022·706f·646d·616e·222c·2022··vz",·"podman",·" 
0009f260:·636f·6e74·6169·6e65·7222·5d0a·2020·2d20··container"].··-· 
0009f270:·2722·6175·6469·7464·2220·696e·2061·6e73··'"auditd"·in·ans 
0009f280:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa0009f210:·3a0a·2020·2d20·2722·6175·6469·7464·2220··:.··-·'"auditd"·
 0009f220:·696e·2061·6e73·6962·6c65·5f66·6163·7473··in·ansible_facts
 0009f230:·2e70·6163·6b61·6765·7327·0a20·202d·2061··.packages'.··-·a
 0009f240:·6e73·6962·6c65·5f76·6972·7475·616c·697a··nsible_virtualiz
 0009f250:·6174·696f·6e5f·7479·7065·206e·6f74·2069··ation_type·not·i
 0009f260:·6e20·5b22·646f·636b·6572·222c·2022·6c78··n·["docker",·"lx
 0009f270:·6322·2c20·226f·7065·6e76·7a22·2c20·2270··c",·"openvz",·"p
 0009f280:·6f64·6d61·6e22·2c20·2263·6f6e·7461·696e··odman",·"contain
0009f290:·6765·7327·0a20·202d·2061·6e73·6962·6c65··ges'.··-·ansible0009f290:·6572·225d·0a20·202d·2061·6e73·6962·6c65··er"].··-·ansible
0009f2a0:·5f61·7263·6869·7465·6374·7572·6520·3d3d··_architecture·==0009f2a0:·5f61·7263·6869·7465·6374·7572·6520·3d3d··_architecture·==
0009f2b0:·2022·6161·7263·6836·3422·206f·7220·616e···"aarch64"·or·an0009f2b0:·2022·6161·7263·6836·3422·206f·7220·616e···"aarch64"·or·an
0009f2c0:·7369·626c·655f·6172·6368·6974·6563·7475··sible_architectu0009f2c0:·7369·626c·655f·6172·6368·6974·6563·7475··sible_architectu
0009f2d0:·7265·203d·3d20·2270·7063·3634·2220·6f72··re·==·"ppc64"·or0009f2d0:·7265·203d·3d20·2270·7063·3634·2220·6f72··re·==·"ppc64"·or
0009f2e0:·2061·6e73·6962·6c65·5f61·7263·6869·7465···ansible_archite0009f2e0:·2061·6e73·6962·6c65·5f61·7263·6869·7465···ansible_archite
0009f2f0:·6374·7572·650a·2020·2020·3d3d·2022·7070··cture.····==·"pp0009f2f0:·6374·7572·650a·2020·2020·3d3d·2022·7070··cture.····==·"pp
0009f300:·6336·346c·6522·206f·7220·616e·7369·626c··c64le"·or·ansibl0009f300:·6336·346c·6522·206f·7220·616e·7369·626c··c64le"·or·ansibl
Offset 41052, 23 lines modifiedOffset 41052, 23 lines modified
000a05b0:·2d46·206b·6579·3d70·6572·6d5f·6d6f·640a··-F·key=perm_mod.000a05b0:·2d46·206b·6579·3d70·6572·6d5f·6d6f·640a··-F·key=perm_mod.
000a05c0:·2020·2020·2020·6372·6561·7465·3a20·7472········create:·tr000a05c0:·2020·2020·2020·6372·6561·7465·3a20·7472········create:·tr
000a05d0:·7565·0a20·2020·2020·206d·6f64·653a·206f··ue.······mode:·o000a05d0:·7565·0a20·2020·2020·206d·6f64·653a·206f··ue.······mode:·o
000a05e0:·2d72·7778·0a20·2020·2020·2073·7461·7465··-rwx.······state000a05e0:·2d72·7778·0a20·2020·2020·2073·7461·7465··-rwx.······state
000a05f0:·3a20·7072·6573·656e·740a·2020·2020·7768··:·present.····wh000a05f0:·3a20·7072·6573·656e·740a·2020·2020·7768··:·present.····wh
000a0600:·656e·3a20·7379·7363·616c·6c73·5f66·6f75··en:·syscalls_fou000a0600:·656e·3a20·7379·7363·616c·6c73·5f66·6f75··en:·syscalls_fou
000a0610:·6e64·207c·206c·656e·6774·6820·3d3d·2030··nd·|·length·==·0000a0610:·6e64·207c·206c·656e·6774·6820·3d3d·2030··nd·|·length·==·0
000a0620:·0a20·2077·6865·6e3a·0a20·202d·2061·6e73··.··when:.··-·ans000a0620:·0a20·2077·6865·6e3a·0a20·202d·2027·2261··.··when:.··-·'"a
000a0630:·6962·6c65·5f76·6972·7475·616c·697a·6174··ible_virtualizat 
000a0640:·696f·6e5f·7479·7065·206e·6f74·2069·6e20··ion_type·not·in· 
000a0650:·5b22·646f·636b·6572·222c·2022·6c78·6322··["docker",·"lxc" 
000a0660:·2c20·226f·7065·6e76·7a22·2c20·2270·6f64··,·"openvz",·"pod 
000a0670:·6d61·6e22·2c20·2263·6f6e·7461·696e·6572··man",·"container 
000a0680:·225d·0a20·202d·2027·2261·7564·6974·6422··"].··-·'"auditd" 
000a0690:·2069·6e20·616e·7369·626c·655f·6661·6374···in·ansible_fact 
000a06a0:·732e·7061·636b·6167·6573·270a·2020·7461··s.packages'.··ta000a0630:·7564·6974·6422·2069·6e20·616e·7369·626c··uditd"·in·ansibl
 000a0640:·655f·6661·6374·732e·7061·636b·6167·6573··e_facts.packages
 000a0650:·270a·2020·2d20·616e·7369·626c·655f·7669··'.··-·ansible_vi
 000a0660:·7274·7561·6c69·7a61·7469·6f6e·5f74·7970··rtualization_typ
 000a0670:·6520·6e6f·7420·696e·205b·2264·6f63·6b65··e·not·in·["docke
 000a0680:·7222·2c20·226c·7863·222c·2022·6f70·656e··r",·"lxc",·"open
 000a0690:·767a·222c·2022·706f·646d·616e·222c·2022··vz",·"podman",·"
 000a06a0:·636f·6e74·6169·6e65·7222·5d0a·2020·7461··container"].··ta
000a06b0:·6773·3a0a·2020·2d20·434a·4953·2d35·2e34··gs:.··-·CJIS-5.4000a06b0:·6773·3a0a·2020·2d20·434a·4953·2d35·2e34··gs:.··-·CJIS-5.4
000a06c0:·2e31·2e31·0a20·202d·204e·4953·542d·3830··.1.1.··-·NIST-80000a06c0:·2e31·2e31·0a20·202d·204e·4953·542d·3830··.1.1.··-·NIST-80
000a06d0:·302d·3137·312d·332e·312e·370a·2020·2d20··0-171-3.1.7.··-·000a06d0:·302d·3137·312d·332e·312e·370a·2020·2d20··0-171-3.1.7.··-·
000a06e0:·4e49·5354·2d38·3030·2d35·332d·4155·2d31··NIST-800-53-AU-1000a06e0:·4e49·5354·2d38·3030·2d35·332d·4155·2d31··NIST-800-53-AU-1
000a06f0:·3228·6329·0a20·202d·204e·4953·542d·3830··2(c).··-·NIST-80000a06f0:·3228·6329·0a20·202d·204e·4953·542d·3830··2(c).··-·NIST-80
000a0700:·302d·3533·2d41·552d·3228·6429·0a20·202d··0-53-AU-2(d).··-000a0700:·302d·3533·2d41·552d·3228·6429·0a20·202d··0-53-AU-2(d).··-
000a0710:·204e·4953·542d·3830·302d·3533·2d43·4d2d···NIST-800-53-CM-000a0710:·204e·4953·542d·3830·302d·3533·2d43·4d2d···NIST-800-53-CM-
Offset 41362, 23 lines modifiedOffset 41362, 23 lines modified
000a1910:·206b·6579·3d70·6572·6d5f·6d6f·640a·2020···key=perm_mod.··000a1910:·206b·6579·3d70·6572·6d5f·6d6f·640a·2020···key=perm_mod.··
000a1920:·2020·2020·6372·6561·7465·3a20·7472·7565······create:·true000a1920:·2020·2020·6372·6561·7465·3a20·7472·7565······create:·true
000a1930:·0a20·2020·2020·206d·6f64·653a·206f·2d72··.······mode:·o-r000a1930:·0a20·2020·2020·206d·6f64·653a·206f·2d72··.······mode:·o-r
000a1940:·7778·0a20·2020·2020·2073·7461·7465·3a20··wx.······state:·000a1940:·7778·0a20·2020·2020·2073·7461·7465·3a20··wx.······state:·
000a1950:·7072·6573·656e·740a·2020·2020·7768·656e··present.····when000a1950:·7072·6573·656e·740a·2020·2020·7768·656e··present.····when
000a1960:·3a20·7379·7363·616c·6c73·5f66·6f75·6e64··:·syscalls_found000a1960:·3a20·7379·7363·616c·6c73·5f66·6f75·6e64··:·syscalls_found
000a1970:·207c·206c·656e·6774·6820·3d3d·2030·0a20···|·length·==·0.·000a1970:·207c·206c·656e·6774·6820·3d3d·2030·0a20···|·length·==·0.·
000a1980:·2077·6865·6e3a·0a20·202d·2061·6e73·6962···when:.··-·ansib000a1980:·2077·6865·6e3a·0a20·202d·2027·2261·7564···when:.··-·'"aud
000a1990:·6c65·5f76·6972·7475·616c·697a·6174·696f··le_virtualizatio 
000a19a0:·6e5f·7479·7065·206e·6f74·2069·6e20·5b22··n_type·not·in·[" 
000a19b0:·646f·636b·6572·222c·2022·6c78·6322·2c20··docker",·"lxc",· 
000a19c0:·226f·7065·6e76·7a22·2c20·2270·6f64·6d61··"openvz",·"podma 
000a19d0:·6e22·2c20·2263·6f6e·7461·696e·6572·225d··n",·"container"] 
000a19e0:·0a20·202d·2027·2261·7564·6974·6422·2069··.··-·'"auditd"·i 
000a19f0:·6e20·616e·7369·626c·655f·6661·6374·732e··n·ansible_facts. 
000a1a00:·7061·636b·6167·6573·270a·2020·2d20·6175··packages'.··-·au000a1990:·6974·6422·2069·6e20·616e·7369·626c·655f··itd"·in·ansible_
 000a19a0:·6661·6374·732e·7061·636b·6167·6573·270a··facts.packages'.
 000a19b0:·2020·2d20·616e·7369·626c·655f·7669·7274····-·ansible_virt
 000a19c0:·7561·6c69·7a61·7469·6f6e·5f74·7970·6520··ualization_type·
 000a19d0:·6e6f·7420·696e·205b·2264·6f63·6b65·7222··not·in·["docker"
 000a19e0:·2c20·226c·7863·222c·2022·6f70·656e·767a··,·"lxc",·"openvz
 000a19f0:·222c·2022·706f·646d·616e·222c·2022·636f··",·"podman",·"co
 000a1a00:·6e74·6169·6e65·7222·5d0a·2020·2d20·6175··ntainer"].··-·au
000a1a10:·6469·745f·6172·6368·203d·3d20·2262·3634··dit_arch·==·"b64000a1a10:·6469·745f·6172·6368·203d·3d20·2262·3634··dit_arch·==·"b64
000a1a20:·220a·2020·7461·6773·3a0a·2020·2d20·434a··".··tags:.··-·CJ000a1a20:·220a·2020·7461·6773·3a0a·2020·2d20·434a··".··tags:.··-·CJ
000a1a30:·4953·2d35·2e34·2e31·2e31·0a20·202d·204e··IS-5.4.1.1.··-·N000a1a30:·4953·2d35·2e34·2e31·2e31·0a20·202d·204e··IS-5.4.1.1.··-·N
000a1a40:·4953·542d·3830·302d·3137·312d·332e·312e··IST-800-171-3.1.000a1a40:·4953·542d·3830·302d·3137·312d·332e·312e··IST-800-171-3.1.
000a1a50:·370a·2020·2d20·4e49·5354·2d38·3030·2d35··7.··-·NIST-800-5000a1a50:·370a·2020·2d20·4e49·5354·2d38·3030·2d35··7.··-·NIST-800-5
000a1a60:·332d·4155·2d31·3228·6329·0a20·202d·204e··3-AU-12(c).··-·N000a1a60:·332d·4155·2d31·3228·6329·0a20·202d·204e··3-AU-12(c).··-·N
000a1a70:·4953·542d·3830·302d·3533·2d41·552d·3228··IST-800-53-AU-2(000a1a70:·4953·542d·3830·302d·3533·2d41·552d·3228··IST-800-53-AU-2(
Offset 41410, 26 lines modifiedOffset 41410, 26 lines modified
000a1c10:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="000a1c10:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
000a1c20:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c000a1c20:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
000a1c30:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm000a1c30:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
000a1c40:·3132·3231·3422·3e3c·7072·653e·3c63·6f64··12214"><pre><cod000a1c40:·3132·3231·3422·3e3c·7072·653e·3c63·6f64··12214"><pre><cod
000a1c50:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation·000a1c50:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation·
000a1c60:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on000a1c60:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on
000a1c70:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl000a1c70:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl
000a1c80:·6174·666f·726d·730a·6966·205b·2021·202d··atforms.if·[·!·-000a1c80:·6174·666f·726d·730a·6966·2064·706b·672d··atforms.if·dpkg-
000a1c90:·6620·2f2e·646f·636b·6572·656e·7620·5d20··f·/.dockerenv·]·000a1c90:·7175·6572·7920·2d2d·7368·6f77·202d·2d73··query·--show·--s
 000a1ca0:·686f·7766·6f72·6d61·743d·2724·7b64·623a··howformat='${db:
 000a1cb0:·5374·6174·7573·2d53·7461·7475·737d·5c6e··Status-Status}\n
 000a1cc0:·2720·2761·7564·6974·6427·2032·2667·743b··'·'auditd'·2&gt;
 000a1cd0:·2f64·6576·2f6e·756c·6c20·7c20·6772·6570··/dev/null·|·grep
 000a1ce0:·202d·7120·696e·7374·616c·6c65·6420·2661···-q·installed·&a
000a1ca0:·2661·6d70·3b26·616d·703b·205b·2021·202d··&amp;&amp;·[·!·-000a1cf0:·6d70·3b26·616d·703b·205b·2021·202d·6620··mp;&amp;·[·!·-f·
 000a1d00:·2f2e·646f·636b·6572·656e·7620·5d20·2661··/.dockerenv·]·&a
 000a1d10:·6d70·3b26·616d·703b·205b·2021·202d·6620··mp;&amp;·[·!·-f·
000a1cb0:·6620·2f72·756e·2f2e·636f·6e74·6169·6e65··f·/run/.containe000a1d20:·2f72·756e·2f2e·636f·6e74·6169·6e65·7265··/run/.containere
Max diff block lines reached; 540184/550250 bytes (98.17%) of diff not shown.
163 KB
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *****·Profile·Information·*****37 *****·Profile·Information·*****
38 Profile·Title·CIS·Ubuntu·22.04·Level·2·Server·Benchmark38 Profile·Title·CIS·Ubuntu·22.04·Level·2·Server·Benchmark
39 Profile·ID····xccdf_org.ssgproject.content_profile_cis_level2_server39 Profile·ID····xccdf_org.ssgproject.content_profile_cis_level2_server
40 ***·CPE·Platforms·***40 ***·CPE·Platforms·***
41 ····*·cpe:/o:canonical:ubuntu_linux:22.04::~~lts~~~41 ····*·cpe:/o:canonical:ubuntu_linux:22.04::~~lts~~~
42 *****·Revision·History·*****42 *****·Revision·History·*****
43 Current·version:·0.1.6543 Current·version:·0.1.65
44 ····*·draft·(as·of·2024-01-14)44 ····*·draft·(as·of·2025-02-15)
45 *****·Table·of·Contents·*****45 *****·Table·of·Contents·*****
46 ···1.·System_Settings46 ···1.·System_Settings
47 ·········1.·Installing_and_Maintaining_Software47 ·········1.·Installing_and_Maintaining_Software
48 ·········2.·Account_and_Access_Control48 ·········2.·Account_and_Access_Control
49 ·········3.·System_Accounting_with_auditd49 ·········3.·System_Accounting_with_auditd
50 ·········4.·GRUB2_bootloader_configuration50 ·········4.·GRUB2_bootloader_configuration
51 ·········5.·Configure_Syslog51 ·········5.·Configure_Syslog
Offset 3343, 16 lines modifiedOffset 3343, 16 lines modified
3343 ··-·reboot_required3343 ··-·reboot_required
3344 ··-·restrict_strategy3344 ··-·restrict_strategy
  
3345 -·name:·Set·architecture·for·audit·chmod·tasks3345 -·name:·Set·architecture·for·audit·chmod·tasks
3346 ··set_fact:3346 ··set_fact:
3347 ····audit_arch:·b643347 ····audit_arch:·b64
3348 ··when:3348 ··when:
3349 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3350 ··-·'"auditd"·in·ansible_facts.packages'3349 ··-·'"auditd"·in·ansible_facts.packages'
 3350 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3351 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture3351 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
3352 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"3352 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
3353 ··tags:3353 ··tags:
3354 ··-·CJIS-5.4.1.13354 ··-·CJIS-5.4.1.1
3355 ··-·NIST-800-171-3.1.73355 ··-·NIST-800-171-3.1.7
3356 ··-·NIST-800-53-AU-12(c)3356 ··-·NIST-800-53-AU-12(c)
3357 ··-·NIST-800-53-AU-2(d)3357 ··-·NIST-800-53-AU-2(d)
Offset 3488, 16 lines modifiedOffset 3488, 16 lines modified
3488 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10003488 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
3489 ········-F·auid!=unset·-F·key=perm_mod3489 ········-F·auid!=unset·-F·key=perm_mod
3490 ······create:·true3490 ······create:·true
3491 ······mode:·o-rwx3491 ······mode:·o-rwx
3492 ······state:·present3492 ······state:·present
3493 ····when:·syscalls_found·|·length·==·03493 ····when:·syscalls_found·|·length·==·0
3494 ··when:3494 ··when:
3495 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3496 ··-·'"auditd"·in·ansible_facts.packages'3495 ··-·'"auditd"·in·ansible_facts.packages'
 3496 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3497 ··tags:3497 ··tags:
3498 ··-·CJIS-5.4.1.13498 ··-·CJIS-5.4.1.1
3499 ··-·NIST-800-171-3.1.73499 ··-·NIST-800-171-3.1.7
3500 ··-·NIST-800-53-AU-12(c)3500 ··-·NIST-800-53-AU-12(c)
3501 ··-·NIST-800-53-AU-2(d)3501 ··-·NIST-800-53-AU-2(d)
3502 ··-·NIST-800-53-CM-6(a)3502 ··-·NIST-800-53-CM-6(a)
3503 ··-·PCI-DSS-Req-10.5.53503 ··-·PCI-DSS-Req-10.5.5
Offset 3631, 16 lines modifiedOffset 3631, 16 lines modified
3631 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10003631 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
3632 ········-F·auid!=unset·-F·key=perm_mod3632 ········-F·auid!=unset·-F·key=perm_mod
3633 ······create:·true3633 ······create:·true
3634 ······mode:·o-rwx3634 ······mode:·o-rwx
3635 ······state:·present3635 ······state:·present
3636 ····when:·syscalls_found·|·length·==·03636 ····when:·syscalls_found·|·length·==·0
3637 ··when:3637 ··when:
3638 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3639 ··-·'"auditd"·in·ansible_facts.packages'3638 ··-·'"auditd"·in·ansible_facts.packages'
 3639 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3640 ··-·audit_arch·==·"b64"3640 ··-·audit_arch·==·"b64"
3641 ··tags:3641 ··tags:
3642 ··-·CJIS-5.4.1.13642 ··-·CJIS-5.4.1.1
3643 ··-·NIST-800-171-3.1.73643 ··-·NIST-800-171-3.1.7
3644 ··-·NIST-800-53-AU-12(c)3644 ··-·NIST-800-53-AU-12(c)
3645 ··-·NIST-800-53-AU-2(d)3645 ··-·NIST-800-53-AU-2(d)
3646 ··-·NIST-800-53-CM-6(a)3646 ··-·NIST-800-53-CM-6(a)
Offset 3649, 16 lines modifiedOffset 3649, 16 lines modified
3649 ··-·low_complexity3649 ··-·low_complexity
3650 ··-·low_disruption3650 ··-·low_disruption
3651 ··-·medium_severity3651 ··-·medium_severity
3652 ··-·reboot_required3652 ··-·reboot_required
3653 ··-·restrict_strategy3653 ··-·restrict_strategy
3654 Remediation_Shell_script_⇲3654 Remediation_Shell_script_⇲
3655 #·Remediation·is·applicable·only·in·certain·platforms3655 #·Remediation·is·applicable·only·in·certain·platforms
3656 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·dpkg-query·--show·--showformat='${db:Status- 
3657 Status}\n'·'auditd'·2>/dev/null·|·grep·-q·installed;·then3656 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'auditd'·2>/dev/null·|·grep·-q·installed·&&·[·!·-
 3657 f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
3658 #·First·perform·the·remediation·of·the·syscall·rule3658 #·First·perform·the·remediation·of·the·syscall·rule
3659 #·Retrieve·hardware·architecture·of·the·underlying·system3659 #·Retrieve·hardware·architecture·of·the·underlying·system
3660 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")3660 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
3661 for·ARCH·in·"${RULE_ARCHS[@]}"3661 for·ARCH·in·"${RULE_ARCHS[@]}"
3662 do3662 do
Offset 4049, 16 lines modifiedOffset 4049, 16 lines modified
4049 ··-·reboot_required4049 ··-·reboot_required
4050 ··-·restrict_strategy4050 ··-·restrict_strategy
  
4051 -·name:·Set·architecture·for·audit·chown·tasks4051 -·name:·Set·architecture·for·audit·chown·tasks
4052 ··set_fact:4052 ··set_fact:
4053 ····audit_arch:·b644053 ····audit_arch:·b64
4054 ··when:4054 ··when:
4055 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4056 ··-·'"auditd"·in·ansible_facts.packages'4055 ··-·'"auditd"·in·ansible_facts.packages'
 4056 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4057 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture4057 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
4058 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"4058 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
4059 ··tags:4059 ··tags:
4060 ··-·CJIS-5.4.1.14060 ··-·CJIS-5.4.1.1
4061 ··-·NIST-800-171-3.1.74061 ··-·NIST-800-171-3.1.7
4062 ··-·NIST-800-53-AU-12(c)4062 ··-·NIST-800-53-AU-12(c)
4063 ··-·NIST-800-53-AU-2(d)4063 ··-·NIST-800-53-AU-2(d)
Offset 4196, 16 lines modifiedOffset 4196, 16 lines modified
4196 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10004196 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
4197 ········-F·auid!=unset·-F·key=perm_mod4197 ········-F·auid!=unset·-F·key=perm_mod
4198 ······create:·true4198 ······create:·true
4199 ······mode:·o-rwx4199 ······mode:·o-rwx
4200 ······state:·present4200 ······state:·present
4201 ····when:·syscalls_found·|·length·==·04201 ····when:·syscalls_found·|·length·==·0
4202 ··when:4202 ··when:
4203 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4204 ··-·'"auditd"·in·ansible_facts.packages'4203 ··-·'"auditd"·in·ansible_facts.packages'
 4204 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4205 ··tags:4205 ··tags:
4206 ··-·CJIS-5.4.1.14206 ··-·CJIS-5.4.1.1
4207 ··-·NIST-800-171-3.1.74207 ··-·NIST-800-171-3.1.7
4208 ··-·NIST-800-53-AU-12(c)4208 ··-·NIST-800-53-AU-12(c)
4209 ··-·NIST-800-53-AU-2(d)4209 ··-·NIST-800-53-AU-2(d)
4210 ··-·NIST-800-53-CM-6(a)4210 ··-·NIST-800-53-CM-6(a)
4211 ··-·PCI-DSS-Req-10.5.54211 ··-·PCI-DSS-Req-10.5.5
Offset 4341, 16 lines modifiedOffset 4341, 16 lines modified
4341 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10004341 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
4342 ········-F·auid!=unset·-F·key=perm_mod4342 ········-F·auid!=unset·-F·key=perm_mod
4343 ······create:·true4343 ······create:·true
Max diff block lines reached; 162554/167398 bytes (97.11%) of diff not shown.
701 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2204-guide-cis_level2_workstation.html
    
Offset 14285, 15 lines modifiedOffset 14285, 15 lines modified
00037cc0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu00037cc0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu
00037cd0:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<00037cd0:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<
00037ce0:·7374·726f·6e67·3e30·2e31·2e36·353c·2f73··strong>0.1.65</s00037ce0:·7374·726f·6e67·3e30·2e31·2e36·353c·2f73··strong>0.1.65</s
00037cf0:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l00037cf0:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l
00037d00:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<00037d00:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<
00037d10:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······00037d10:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······
00037d20:·2020·2020·2020·2020·2020·2020·2028·6173···············(as00037d20:·2020·2020·2020·2020·2020·2020·2028·6173···············(as
00037d30:·206f·6620·3230·3234·2d30·312d·3134·290a···of·2024-01-14).00037d30:·206f·6620·3230·3235·2d30·322d·3135·290a···of·2025-02-15).
00037d40:·2020·2020·2020·2020·2020·2020·2020·2020··················00037d40:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037d50:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>00037d50:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>
00037d60:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con00037d60:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con
00037d70:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l00037d70:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l
00037d80:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd00037d80:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd
00037d90:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject00037d90:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject
00037da0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s00037da0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s
Offset 42285, 23 lines modifiedOffset 42285, 23 lines modified
000a52c0:·6972·6564·0a20·202d·2072·6573·7472·6963··ired.··-·restric000a52c0:·6972·6564·0a20·202d·2072·6573·7472·6963··ired.··-·restric
000a52d0:·745f·7374·7261·7465·6779·0a0a·2d20·6e61··t_strategy..-·na000a52d0:·745f·7374·7261·7465·6779·0a0a·2d20·6e61··t_strategy..-·na
000a52e0:·6d65·3a20·5365·7420·6172·6368·6974·6563··me:·Set·architec000a52e0:·6d65·3a20·5365·7420·6172·6368·6974·6563··me:·Set·architec
000a52f0:·7475·7265·2066·6f72·2061·7564·6974·2063··ture·for·audit·c000a52f0:·7475·7265·2066·6f72·2061·7564·6974·2063··ture·for·audit·c
000a5300:·686d·6f64·2074·6173·6b73·0a20·2073·6574··hmod·tasks.··set000a5300:·686d·6f64·2074·6173·6b73·0a20·2073·6574··hmod·tasks.··set
000a5310:·5f66·6163·743a·0a20·2020·2061·7564·6974··_fact:.····audit000a5310:·5f66·6163·743a·0a20·2020·2061·7564·6974··_fact:.····audit
000a5320:·5f61·7263·683a·2062·3634·0a20·2077·6865··_arch:·b64.··whe000a5320:·5f61·7263·683a·2062·3634·0a20·2077·6865··_arch:·b64.··whe
000a5330:·6e3a·0a20·202d·2061·6e73·6962·6c65·5f76··n:.··-·ansible_v 
000a5340:·6972·7475·616c·697a·6174·696f·6e5f·7479··irtualization_ty 
000a5350:·7065·206e·6f74·2069·6e20·5b22·646f·636b··pe·not·in·["dock 
000a5360:·6572·222c·2022·6c78·6322·2c20·226f·7065··er",·"lxc",·"ope 
000a5370:·6e76·7a22·2c20·2270·6f64·6d61·6e22·2c20··nvz",·"podman",· 
000a5380:·2263·6f6e·7461·696e·6572·225d·0a20·202d··"container"].··- 
000a5390:·2027·2261·7564·6974·6422·2069·6e20·616e···'"auditd"·in·an 
000a53a0:·7369·626c·655f·6661·6374·732e·7061·636b··sible_facts.pack000a5330:·6e3a·0a20·202d·2027·2261·7564·6974·6422··n:.··-·'"auditd"
 000a5340:·2069·6e20·616e·7369·626c·655f·6661·6374···in·ansible_fact
 000a5350:·732e·7061·636b·6167·6573·270a·2020·2d20··s.packages'.··-·
 000a5360:·616e·7369·626c·655f·7669·7274·7561·6c69··ansible_virtuali
 000a5370:·7a61·7469·6f6e·5f74·7970·6520·6e6f·7420··zation_type·not·
 000a5380:·696e·205b·2264·6f63·6b65·7222·2c20·226c··in·["docker",·"l
 000a5390:·7863·222c·2022·6f70·656e·767a·222c·2022··xc",·"openvz",·"
 000a53a0:·706f·646d·616e·222c·2022·636f·6e74·6169··podman",·"contai
000a53b0:·6167·6573·270a·2020·2d20·616e·7369·626c··ages'.··-·ansibl000a53b0:·6e65·7222·5d0a·2020·2d20·616e·7369·626c··ner"].··-·ansibl
000a53c0:·655f·6172·6368·6974·6563·7475·7265·203d··e_architecture·=000a53c0:·655f·6172·6368·6974·6563·7475·7265·203d··e_architecture·=
000a53d0:·3d20·2261·6172·6368·3634·2220·6f72·2061··=·"aarch64"·or·a000a53d0:·3d20·2261·6172·6368·3634·2220·6f72·2061··=·"aarch64"·or·a
000a53e0:·6e73·6962·6c65·5f61·7263·6869·7465·6374··nsible_architect000a53e0:·6e73·6962·6c65·5f61·7263·6869·7465·6374··nsible_architect
000a53f0:·7572·6520·3d3d·2022·7070·6336·3422·206f··ure·==·"ppc64"·o000a53f0:·7572·6520·3d3d·2022·7070·6336·3422·206f··ure·==·"ppc64"·o
000a5400:·7220·616e·7369·626c·655f·6172·6368·6974··r·ansible_archit000a5400:·7220·616e·7369·626c·655f·6172·6368·6974··r·ansible_archit
000a5410:·6563·7475·7265·0a20·2020·203d·3d20·2270··ecture.····==·"p000a5410:·6563·7475·7265·0a20·2020·203d·3d20·2270··ecture.····==·"p
000a5420:·7063·3634·6c65·2220·6f72·2061·6e73·6962··pc64le"·or·ansib000a5420:·7063·3634·6c65·2220·6f72·2061·6e73·6962··pc64le"·or·ansib
Offset 42606, 23 lines modifiedOffset 42606, 23 lines modified
000a66d0:·202d·4620·6b65·793d·7065·726d·5f6d·6f64···-F·key=perm_mod000a66d0:·202d·4620·6b65·793d·7065·726d·5f6d·6f64···-F·key=perm_mod
000a66e0:·0a20·2020·2020·2063·7265·6174·653a·2074··.······create:·t000a66e0:·0a20·2020·2020·2063·7265·6174·653a·2074··.······create:·t
000a66f0:·7275·650a·2020·2020·2020·6d6f·6465·3a20··rue.······mode:·000a66f0:·7275·650a·2020·2020·2020·6d6f·6465·3a20··rue.······mode:·
000a6700:·6f2d·7277·780a·2020·2020·2020·7374·6174··o-rwx.······stat000a6700:·6f2d·7277·780a·2020·2020·2020·7374·6174··o-rwx.······stat
000a6710:·653a·2070·7265·7365·6e74·0a20·2020·2077··e:·present.····w000a6710:·653a·2070·7265·7365·6e74·0a20·2020·2077··e:·present.····w
000a6720:·6865·6e3a·2073·7973·6361·6c6c·735f·666f··hen:·syscalls_fo000a6720:·6865·6e3a·2073·7973·6361·6c6c·735f·666f··hen:·syscalls_fo
000a6730:·756e·6420·7c20·6c65·6e67·7468·203d·3d20··und·|·length·==·000a6730:·756e·6420·7c20·6c65·6e67·7468·203d·3d20··und·|·length·==·
000a6740:·300a·2020·7768·656e·3a0a·2020·2d20·616e··0.··when:.··-·an000a6740:·300a·2020·7768·656e·3a0a·2020·2d20·2722··0.··when:.··-·'"
000a6750:·7369·626c·655f·7669·7274·7561·6c69·7a61··sible_virtualiza 
000a6760:·7469·6f6e·5f74·7970·6520·6e6f·7420·696e··tion_type·not·in 
000a6770:·205b·2264·6f63·6b65·7222·2c20·226c·7863···["docker",·"lxc 
000a6780:·222c·2022·6f70·656e·767a·222c·2022·706f··",·"openvz",·"po 
000a6790:·646d·616e·222c·2022·636f·6e74·6169·6e65··dman",·"containe 
000a67a0:·7222·5d0a·2020·2d20·2722·6175·6469·7464··r"].··-·'"auditd 
000a67b0:·2220·696e·2061·6e73·6962·6c65·5f66·6163··"·in·ansible_fac 
000a67c0:·7473·2e70·6163·6b61·6765·7327·0a20·2074··ts.packages'.··t000a6750:·6175·6469·7464·2220·696e·2061·6e73·6962··auditd"·in·ansib
 000a6760:·6c65·5f66·6163·7473·2e70·6163·6b61·6765··le_facts.package
 000a6770:·7327·0a20·202d·2061·6e73·6962·6c65·5f76··s'.··-·ansible_v
 000a6780:·6972·7475·616c·697a·6174·696f·6e5f·7479··irtualization_ty
 000a6790:·7065·206e·6f74·2069·6e20·5b22·646f·636b··pe·not·in·["dock
 000a67a0:·6572·222c·2022·6c78·6322·2c20·226f·7065··er",·"lxc",·"ope
 000a67b0:·6e76·7a22·2c20·2270·6f64·6d61·6e22·2c20··nvz",·"podman",·
 000a67c0:·2263·6f6e·7461·696e·6572·225d·0a20·2074··"container"].··t
000a67d0:·6167·733a·0a20·202d·2043·4a49·532d·352e··ags:.··-·CJIS-5.000a67d0:·6167·733a·0a20·202d·2043·4a49·532d·352e··ags:.··-·CJIS-5.
000a67e0:·342e·312e·310a·2020·2d20·4e49·5354·2d38··4.1.1.··-·NIST-8000a67e0:·342e·312e·310a·2020·2d20·4e49·5354·2d38··4.1.1.··-·NIST-8
000a67f0:·3030·2d31·3731·2d33·2e31·2e37·0a20·202d··00-171-3.1.7.··-000a67f0:·3030·2d31·3731·2d33·2e31·2e37·0a20·202d··00-171-3.1.7.··-
000a6800:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-000a6800:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-
000a6810:·3132·2863·290a·2020·2d20·4e49·5354·2d38··12(c).··-·NIST-8000a6810:·3132·2863·290a·2020·2d20·4e49·5354·2d38··12(c).··-·NIST-8
000a6820:·3030·2d35·332d·4155·2d32·2864·290a·2020··00-53-AU-2(d).··000a6820:·3030·2d35·332d·4155·2d32·2864·290a·2020··00-53-AU-2(d).··
000a6830:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM000a6830:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM
Offset 42916, 23 lines modifiedOffset 42916, 23 lines modified
000a7a30:·4620·6b65·793d·7065·726d·5f6d·6f64·0a20··F·key=perm_mod.·000a7a30:·4620·6b65·793d·7065·726d·5f6d·6f64·0a20··F·key=perm_mod.·
000a7a40:·2020·2020·2063·7265·6174·653a·2074·7275·······create:·tru000a7a40:·2020·2020·2063·7265·6174·653a·2074·7275·······create:·tru
000a7a50:·650a·2020·2020·2020·6d6f·6465·3a20·6f2d··e.······mode:·o-000a7a50:·650a·2020·2020·2020·6d6f·6465·3a20·6f2d··e.······mode:·o-
000a7a60:·7277·780a·2020·2020·2020·7374·6174·653a··rwx.······state:000a7a60:·7277·780a·2020·2020·2020·7374·6174·653a··rwx.······state:
000a7a70:·2070·7265·7365·6e74·0a20·2020·2077·6865···present.····whe000a7a70:·2070·7265·7365·6e74·0a20·2020·2077·6865···present.····whe
000a7a80:·6e3a·2073·7973·6361·6c6c·735f·666f·756e··n:·syscalls_foun000a7a80:·6e3a·2073·7973·6361·6c6c·735f·666f·756e··n:·syscalls_foun
000a7a90:·6420·7c20·6c65·6e67·7468·203d·3d20·300a··d·|·length·==·0.000a7a90:·6420·7c20·6c65·6e67·7468·203d·3d20·300a··d·|·length·==·0.
000a7aa0:·2020·7768·656e·3a0a·2020·2d20·616e·7369····when:.··-·ansi000a7aa0:·2020·7768·656e·3a0a·2020·2d20·2722·6175····when:.··-·'"au
000a7ab0:·626c·655f·7669·7274·7561·6c69·7a61·7469··ble_virtualizati 
000a7ac0:·6f6e·5f74·7970·6520·6e6f·7420·696e·205b··on_type·not·in·[ 
000a7ad0:·2264·6f63·6b65·7222·2c20·226c·7863·222c··"docker",·"lxc", 
000a7ae0:·2022·6f70·656e·767a·222c·2022·706f·646d···"openvz",·"podm 
000a7af0:·616e·222c·2022·636f·6e74·6169·6e65·7222··an",·"container" 
000a7b00:·5d0a·2020·2d20·2722·6175·6469·7464·2220··].··-·'"auditd"· 
000a7b10:·696e·2061·6e73·6962·6c65·5f66·6163·7473··in·ansible_facts 
000a7b20:·2e70·6163·6b61·6765·7327·0a20·202d·2061··.packages'.··-·a000a7ab0:·6469·7464·2220·696e·2061·6e73·6962·6c65··ditd"·in·ansible
 000a7ac0:·5f66·6163·7473·2e70·6163·6b61·6765·7327··_facts.packages'
 000a7ad0:·0a20·202d·2061·6e73·6962·6c65·5f76·6972··.··-·ansible_vir
 000a7ae0:·7475·616c·697a·6174·696f·6e5f·7479·7065··tualization_type
 000a7af0:·206e·6f74·2069·6e20·5b22·646f·636b·6572···not·in·["docker
 000a7b00:·222c·2022·6c78·6322·2c20·226f·7065·6e76··",·"lxc",·"openv
 000a7b10:·7a22·2c20·2270·6f64·6d61·6e22·2c20·2263··z",·"podman",·"c
 000a7b20:·6f6e·7461·696e·6572·225d·0a20·202d·2061··ontainer"].··-·a
000a7b30:·7564·6974·5f61·7263·6820·3d3d·2022·6236··udit_arch·==·"b6000a7b30:·7564·6974·5f61·7263·6820·3d3d·2022·6236··udit_arch·==·"b6
000a7b40:·3422·0a20·2074·6167·733a·0a20·202d·2043··4".··tags:.··-·C000a7b40:·3422·0a20·2074·6167·733a·0a20·202d·2043··4".··tags:.··-·C
000a7b50:·4a49·532d·352e·342e·312e·310a·2020·2d20··JIS-5.4.1.1.··-·000a7b50:·4a49·532d·352e·342e·312e·310a·2020·2d20··JIS-5.4.1.1.··-·
000a7b60:·4e49·5354·2d38·3030·2d31·3731·2d33·2e31··NIST-800-171-3.1000a7b60:·4e49·5354·2d38·3030·2d31·3731·2d33·2e31··NIST-800-171-3.1
000a7b70:·2e37·0a20·202d·204e·4953·542d·3830·302d··.7.··-·NIST-800-000a7b70:·2e37·0a20·202d·204e·4953·542d·3830·302d··.7.··-·NIST-800-
000a7b80:·3533·2d41·552d·3132·2863·290a·2020·2d20··53-AU-12(c).··-·000a7b80:·3533·2d41·552d·3132·2863·290a·2020·2d20··53-AU-12(c).··-·
000a7b90:·4e49·5354·2d38·3030·2d35·332d·4155·2d32··NIST-800-53-AU-2000a7b90:·4e49·5354·2d38·3030·2d35·332d·4155·2d32··NIST-800-53-AU-2
Offset 42964, 26 lines modifiedOffset 42964, 26 lines modified
000a7d30:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=000a7d30:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
000a7d40:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·000a7d40:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
000a7d50:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id000a7d50:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
000a7d60:·6d31·3232·3134·223e·3c70·7265·3e3c·636f··m12214"><pre><co000a7d60:·6d31·3232·3134·223e·3c70·7265·3e3c·636f··m12214"><pre><co
000a7d70:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation000a7d70:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation
000a7d80:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o000a7d80:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o
000a7d90:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p000a7d90:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p
000a7da0:·6c61·7466·6f72·6d73·0a69·6620·5b20·2120··latforms.if·[·!·000a7da0:·6c61·7466·6f72·6d73·0a69·6620·6470·6b67··latforms.if·dpkg
000a7db0:·2d66·202f·2e64·6f63·6b65·7265·6e76·205d··-f·/.dockerenv·]000a7db0:·2d71·7565·7279·202d·2d73·686f·7720·2d2d··-query·--show·--
 000a7dc0:·7368·6f77·666f·726d·6174·3d27·247b·6462··showformat='${db
 000a7dd0:·3a53·7461·7475·732d·5374·6174·7573·7d5c··:Status-Status}\
 000a7de0:·6e27·2027·6175·6469·7464·2720·3226·6774··n'·'auditd'·2&gt
 000a7df0:·3b2f·6465·762f·6e75·6c6c·207c·2067·7265··;/dev/null·|·gre
 000a7e00:·7020·2d71·2069·6e73·7461·6c6c·6564·2026··p·-q·installed·&
000a7dc0:·2026·616d·703b·2661·6d70·3b20·5b20·2120···&amp;&amp;·[·!·000a7e10:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f
 000a7e20:·202f·2e64·6f63·6b65·7265·6e76·205d·2026···/.dockerenv·]·&
 000a7e30:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f
000a7dd0:·2d66·202f·7275·6e2f·2e63·6f6e·7461·696e··-f·/run/.contain000a7e40:·202f·7275·6e2f·2e63·6f6e·7461·696e·6572···/run/.container
Max diff block lines reached; 540602/550668 bytes (98.17%) of diff not shown.
164 KB
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *****·Profile·Information·*****37 *****·Profile·Information·*****
38 Profile·Title·CIS·Ubuntu·22.04·Level·2·Workstation·Benchmark38 Profile·Title·CIS·Ubuntu·22.04·Level·2·Workstation·Benchmark
39 Profile·ID····xccdf_org.ssgproject.content_profile_cis_level2_workstation39 Profile·ID····xccdf_org.ssgproject.content_profile_cis_level2_workstation
40 ***·CPE·Platforms·***40 ***·CPE·Platforms·***
41 ····*·cpe:/o:canonical:ubuntu_linux:22.04::~~lts~~~41 ····*·cpe:/o:canonical:ubuntu_linux:22.04::~~lts~~~
42 *****·Revision·History·*****42 *****·Revision·History·*****
43 Current·version:·0.1.6543 Current·version:·0.1.65
44 ····*·draft·(as·of·2024-01-14)44 ····*·draft·(as·of·2025-02-15)
45 *****·Table·of·Contents·*****45 *****·Table·of·Contents·*****
46 ···1.·System_Settings46 ···1.·System_Settings
47 ·········1.·Installing_and_Maintaining_Software47 ·········1.·Installing_and_Maintaining_Software
48 ·········2.·Account_and_Access_Control48 ·········2.·Account_and_Access_Control
49 ·········3.·System_Accounting_with_auditd49 ·········3.·System_Accounting_with_auditd
50 ·········4.·GRUB2_bootloader_configuration50 ·········4.·GRUB2_bootloader_configuration
51 ·········5.·Configure_Syslog51 ·········5.·Configure_Syslog
Offset 3580, 16 lines modifiedOffset 3580, 16 lines modified
3580 ··-·reboot_required3580 ··-·reboot_required
3581 ··-·restrict_strategy3581 ··-·restrict_strategy
  
3582 -·name:·Set·architecture·for·audit·chmod·tasks3582 -·name:·Set·architecture·for·audit·chmod·tasks
3583 ··set_fact:3583 ··set_fact:
3584 ····audit_arch:·b643584 ····audit_arch:·b64
3585 ··when:3585 ··when:
3586 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3587 ··-·'"auditd"·in·ansible_facts.packages'3586 ··-·'"auditd"·in·ansible_facts.packages'
 3587 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3588 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture3588 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
3589 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"3589 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
3590 ··tags:3590 ··tags:
3591 ··-·CJIS-5.4.1.13591 ··-·CJIS-5.4.1.1
3592 ··-·NIST-800-171-3.1.73592 ··-·NIST-800-171-3.1.7
3593 ··-·NIST-800-53-AU-12(c)3593 ··-·NIST-800-53-AU-12(c)
3594 ··-·NIST-800-53-AU-2(d)3594 ··-·NIST-800-53-AU-2(d)
Offset 3725, 16 lines modifiedOffset 3725, 16 lines modified
3725 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10003725 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
3726 ········-F·auid!=unset·-F·key=perm_mod3726 ········-F·auid!=unset·-F·key=perm_mod
3727 ······create:·true3727 ······create:·true
3728 ······mode:·o-rwx3728 ······mode:·o-rwx
3729 ······state:·present3729 ······state:·present
3730 ····when:·syscalls_found·|·length·==·03730 ····when:·syscalls_found·|·length·==·0
3731 ··when:3731 ··when:
3732 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3733 ··-·'"auditd"·in·ansible_facts.packages'3732 ··-·'"auditd"·in·ansible_facts.packages'
 3733 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3734 ··tags:3734 ··tags:
3735 ··-·CJIS-5.4.1.13735 ··-·CJIS-5.4.1.1
3736 ··-·NIST-800-171-3.1.73736 ··-·NIST-800-171-3.1.7
3737 ··-·NIST-800-53-AU-12(c)3737 ··-·NIST-800-53-AU-12(c)
3738 ··-·NIST-800-53-AU-2(d)3738 ··-·NIST-800-53-AU-2(d)
3739 ··-·NIST-800-53-CM-6(a)3739 ··-·NIST-800-53-CM-6(a)
3740 ··-·PCI-DSS-Req-10.5.53740 ··-·PCI-DSS-Req-10.5.5
Offset 3868, 16 lines modifiedOffset 3868, 16 lines modified
3868 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10003868 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
3869 ········-F·auid!=unset·-F·key=perm_mod3869 ········-F·auid!=unset·-F·key=perm_mod
3870 ······create:·true3870 ······create:·true
3871 ······mode:·o-rwx3871 ······mode:·o-rwx
3872 ······state:·present3872 ······state:·present
3873 ····when:·syscalls_found·|·length·==·03873 ····when:·syscalls_found·|·length·==·0
3874 ··when:3874 ··when:
3875 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3876 ··-·'"auditd"·in·ansible_facts.packages'3875 ··-·'"auditd"·in·ansible_facts.packages'
 3876 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3877 ··-·audit_arch·==·"b64"3877 ··-·audit_arch·==·"b64"
3878 ··tags:3878 ··tags:
3879 ··-·CJIS-5.4.1.13879 ··-·CJIS-5.4.1.1
3880 ··-·NIST-800-171-3.1.73880 ··-·NIST-800-171-3.1.7
3881 ··-·NIST-800-53-AU-12(c)3881 ··-·NIST-800-53-AU-12(c)
3882 ··-·NIST-800-53-AU-2(d)3882 ··-·NIST-800-53-AU-2(d)
3883 ··-·NIST-800-53-CM-6(a)3883 ··-·NIST-800-53-CM-6(a)
Offset 3886, 16 lines modifiedOffset 3886, 16 lines modified
3886 ··-·low_complexity3886 ··-·low_complexity
3887 ··-·low_disruption3887 ··-·low_disruption
3888 ··-·medium_severity3888 ··-·medium_severity
3889 ··-·reboot_required3889 ··-·reboot_required
3890 ··-·restrict_strategy3890 ··-·restrict_strategy
3891 Remediation_Shell_script_⇲3891 Remediation_Shell_script_⇲
3892 #·Remediation·is·applicable·only·in·certain·platforms3892 #·Remediation·is·applicable·only·in·certain·platforms
3893 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·dpkg-query·--show·--showformat='${db:Status- 
3894 Status}\n'·'auditd'·2>/dev/null·|·grep·-q·installed;·then3893 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'auditd'·2>/dev/null·|·grep·-q·installed·&&·[·!·-
 3894 f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
3895 #·First·perform·the·remediation·of·the·syscall·rule3895 #·First·perform·the·remediation·of·the·syscall·rule
3896 #·Retrieve·hardware·architecture·of·the·underlying·system3896 #·Retrieve·hardware·architecture·of·the·underlying·system
3897 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")3897 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
3898 for·ARCH·in·"${RULE_ARCHS[@]}"3898 for·ARCH·in·"${RULE_ARCHS[@]}"
3899 do3899 do
Offset 4286, 16 lines modifiedOffset 4286, 16 lines modified
4286 ··-·reboot_required4286 ··-·reboot_required
4287 ··-·restrict_strategy4287 ··-·restrict_strategy
  
4288 -·name:·Set·architecture·for·audit·chown·tasks4288 -·name:·Set·architecture·for·audit·chown·tasks
4289 ··set_fact:4289 ··set_fact:
4290 ····audit_arch:·b644290 ····audit_arch:·b64
4291 ··when:4291 ··when:
4292 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4293 ··-·'"auditd"·in·ansible_facts.packages'4292 ··-·'"auditd"·in·ansible_facts.packages'
 4293 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4294 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture4294 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
4295 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"4295 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
4296 ··tags:4296 ··tags:
4297 ··-·CJIS-5.4.1.14297 ··-·CJIS-5.4.1.1
4298 ··-·NIST-800-171-3.1.74298 ··-·NIST-800-171-3.1.7
4299 ··-·NIST-800-53-AU-12(c)4299 ··-·NIST-800-53-AU-12(c)
4300 ··-·NIST-800-53-AU-2(d)4300 ··-·NIST-800-53-AU-2(d)
Offset 4433, 16 lines modifiedOffset 4433, 16 lines modified
4433 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10004433 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
4434 ········-F·auid!=unset·-F·key=perm_mod4434 ········-F·auid!=unset·-F·key=perm_mod
4435 ······create:·true4435 ······create:·true
4436 ······mode:·o-rwx4436 ······mode:·o-rwx
4437 ······state:·present4437 ······state:·present
4438 ····when:·syscalls_found·|·length·==·04438 ····when:·syscalls_found·|·length·==·0
4439 ··when:4439 ··when:
4440 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4441 ··-·'"auditd"·in·ansible_facts.packages'4440 ··-·'"auditd"·in·ansible_facts.packages'
 4441 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4442 ··tags:4442 ··tags:
4443 ··-·CJIS-5.4.1.14443 ··-·CJIS-5.4.1.1
4444 ··-·NIST-800-171-3.1.74444 ··-·NIST-800-171-3.1.7
4445 ··-·NIST-800-53-AU-12(c)4445 ··-·NIST-800-53-AU-12(c)
4446 ··-·NIST-800-53-AU-2(d)4446 ··-·NIST-800-53-AU-2(d)
4447 ··-·NIST-800-53-CM-6(a)4447 ··-·NIST-800-53-CM-6(a)
4448 ··-·PCI-DSS-Req-10.5.54448 ··-·PCI-DSS-Req-10.5.5
Offset 4578, 16 lines modifiedOffset 4578, 16 lines modified
4578 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10004578 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
4579 ········-F·auid!=unset·-F·key=perm_mod4579 ········-F·auid!=unset·-F·key=perm_mod
4580 ······create:·true4580 ······create:·true
Max diff block lines reached; 162556/167410 bytes (97.10%) of diff not shown.
2.0 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2204-guide-standard.html
    
Offset 14287, 16 lines modifiedOffset 14287, 16 lines modified
00037ce0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</00037ce0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</
00037cf0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve00037cf0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve
00037d00:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>000037d00:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>0
00037d10:·2e31·2e36·353c·2f73·7472·6f6e·673e·3c2f··.1.65</strong></00037d10:·2e31·2e36·353c·2f73·7472·6f6e·673e·3c2f··.1.65</strong></
00037d20:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron00037d20:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron
00037d30:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>00037d30:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>
00037d40:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00037d40:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00037d50:·2020·2020·2028·6173·206f·6620·3230·3234·······(as·of·202400037d50:·2020·2020·2028·6173·206f·6620·3230·3235·······(as·of·2025
00037d60:·2d30·312d·3134·290a·2020·2020·2020·2020··-01-14).········00037d60:·2d30·322d·3135·290a·2020·2020·2020·2020··-02-15).········
00037d70:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u00037d70:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u
00037d80:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl00037d80:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl
00037d90:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h00037d90:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h
00037da0:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre00037da0:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre
00037db0:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss00037db0:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss
00037dc0:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content00037dc0:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content
00037dd0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S00037dd0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S
654 B
html2text {}
    
Offset 38, 15 lines modifiedOffset 38, 15 lines modified
38 *****·Profile·Information·*****38 *****·Profile·Information·*****
39 Profile·Title·Standard·System·Security·Profile·for·Ubuntu·22.0439 Profile·Title·Standard·System·Security·Profile·for·Ubuntu·22.04
40 Profile·ID····xccdf_org.ssgproject.content_profile_standard40 Profile·ID····xccdf_org.ssgproject.content_profile_standard
41 ***·CPE·Platforms·***41 ***·CPE·Platforms·***
42 ····*·cpe:/o:canonical:ubuntu_linux:22.04::~~lts~~~42 ····*·cpe:/o:canonical:ubuntu_linux:22.04::~~lts~~~
43 *****·Revision·History·*****43 *****·Revision·History·*****
44 Current·version:·0.1.6544 Current·version:·0.1.65
45 ····*·draft·(as·of·2024-01-14)45 ····*·draft·(as·of·2025-02-15)
46 *****·Table·of·Contents·*****46 *****·Table·of·Contents·*****
47 ···1.·System_Settings47 ···1.·System_Settings
48 ·········1.·Installing_and_Maintaining_Software48 ·········1.·Installing_and_Maintaining_Software
49 ·········2.·Account_and_Access_Control49 ·········2.·Account_and_Access_Control
50 ·········3.·System_Accounting_with_auditd50 ·········3.·System_Accounting_with_auditd
51 ·········4.·Configure_Syslog51 ·········4.·Configure_Syslog
52 ·········5.·File_Permissions_and_Masks52 ·········5.·File_Permissions_and_Masks
133 KB
./usr/share/scap-security-guide/ansible/ubuntu2204-playbook-cis_level2_server.yml
Ordering differences only
    
Offset 1152, 16 lines modifiedOffset 1152, 16 lines modified
  
1152 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension1152 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
1153 ······find:1153 ······find:
1154 ········paths:·/etc/audit/rules.d/1154 ········paths:·/etc/audit/rules.d/
1155 ········patterns:·'*.rules'1155 ········patterns:·'*.rules'
1156 ······register:·find_rules_d1156 ······register:·find_rules_d
1157 ······when:1157 ······when:
1158 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1159 ······-·'"auditd"·in·ansible_facts.packages'1158 ······-·'"auditd"·in·ansible_facts.packages'
 1159 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1160 ······tags:1160 ······tags:
1161 ······-·CJIS-5.4.1.11161 ······-·CJIS-5.4.1.1
1162 ······-·NIST-800-171-3.3.11162 ······-·NIST-800-171-3.3.1
1163 ······-·NIST-800-171-3.4.31163 ······-·NIST-800-171-3.4.3
1164 ······-·NIST-800-53-AC-6(9)1164 ······-·NIST-800-53-AC-6(9)
1165 ······-·NIST-800-53-CM-6(a)1165 ······-·NIST-800-53-CM-6(a)
1166 ······-·PCI-DSS-Req-10.5.21166 ······-·PCI-DSS-Req-10.5.2
Offset 1176, 16 lines modifiedOffset 1176, 16 lines modified
1176 ······lineinfile:1176 ······lineinfile:
1177 ········path:·'{{·item·}}'1177 ········path:·'{{·item·}}'
1178 ········regexp:·^\s*(?:-e)\s+.*$1178 ········regexp:·^\s*(?:-e)\s+.*$
1179 ········state:·absent1179 ········state:·absent
1180 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']1180 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
1181 ········}}'1181 ········}}'
1182 ······when:1182 ······when:
1183 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1184 ······-·'"auditd"·in·ansible_facts.packages'1183 ······-·'"auditd"·in·ansible_facts.packages'
 1184 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1185 ······tags:1185 ······tags:
1186 ······-·CJIS-5.4.1.11186 ······-·CJIS-5.4.1.1
1187 ······-·NIST-800-171-3.3.11187 ······-·NIST-800-171-3.3.1
1188 ······-·NIST-800-171-3.4.31188 ······-·NIST-800-171-3.4.3
1189 ······-·NIST-800-53-AC-6(9)1189 ······-·NIST-800-53-AC-6(9)
1190 ······-·NIST-800-53-CM-6(a)1190 ······-·NIST-800-53-CM-6(a)
1191 ······-·PCI-DSS-Req-10.5.21191 ······-·PCI-DSS-Req-10.5.2
Offset 1202, 16 lines modifiedOffset 1202, 16 lines modified
1202 ········create:·true1202 ········create:·true
1203 ········line:·-e·21203 ········line:·-e·2
1204 ········mode:·o-rwx1204 ········mode:·o-rwx
1205 ······loop:1205 ······loop:
1206 ······-·/etc/audit/audit.rules1206 ······-·/etc/audit/audit.rules
1207 ······-·/etc/audit/rules.d/immutable.rules1207 ······-·/etc/audit/rules.d/immutable.rules
1208 ······when:1208 ······when:
1209 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1210 ······-·'"auditd"·in·ansible_facts.packages'1209 ······-·'"auditd"·in·ansible_facts.packages'
 1210 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1211 ······tags:1211 ······tags:
1212 ······-·CJIS-5.4.1.11212 ······-·CJIS-5.4.1.1
1213 ······-·NIST-800-171-3.3.11213 ······-·NIST-800-171-3.3.1
1214 ······-·NIST-800-171-3.4.31214 ······-·NIST-800-171-3.4.3
1215 ······-·NIST-800-53-AC-6(9)1215 ······-·NIST-800-53-AC-6(9)
1216 ······-·NIST-800-53-CM-6(a)1216 ······-·NIST-800-53-CM-6(a)
1217 ······-·PCI-DSS-Req-10.5.21217 ······-·PCI-DSS-Req-10.5.2
Offset 1246, 16 lines modifiedOffset 1246, 16 lines modified
1246 ····-·name:·Check·if·watch·rule·for·/etc/sudoers·already·exists·in·/etc/audit/rules.d/1246 ····-·name:·Check·if·watch·rule·for·/etc/sudoers·already·exists·in·/etc/audit/rules.d/
1247 ······find:1247 ······find:
1248 ········paths:·/etc/audit/rules.d1248 ········paths:·/etc/audit/rules.d
1249 ········contains:·^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+1249 ········contains:·^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+
1250 ········patterns:·'*.rules'1250 ········patterns:·'*.rules'
1251 ······register:·find_existing_watch_rules_d1251 ······register:·find_existing_watch_rules_d
1252 ······when:1252 ······when:
1253 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1254 ······-·'"auditd"·in·ansible_facts.packages'1253 ······-·'"auditd"·in·ansible_facts.packages'
 1254 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1255 ······tags:1255 ······tags:
1256 ······-·CJIS-5.4.1.11256 ······-·CJIS-5.4.1.1
1257 ······-·NIST-800-171-3.1.71257 ······-·NIST-800-171-3.1.7
1258 ······-·NIST-800-53-AC-2(7)(b)1258 ······-·NIST-800-53-AC-2(7)(b)
1259 ······-·NIST-800-53-AC-6(9)1259 ······-·NIST-800-53-AC-6(9)
1260 ······-·NIST-800-53-AU-12(c)1260 ······-·NIST-800-53-AU-12(c)
1261 ······-·NIST-800-53-AU-2(d)1261 ······-·NIST-800-53-AU-2(d)
Offset 1272, 16 lines modifiedOffset 1272, 16 lines modified
1272 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·actions1272 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·actions
1273 ······find:1273 ······find:
1274 ········paths:·/etc/audit/rules.d1274 ········paths:·/etc/audit/rules.d
1275 ········contains:·^.*(?:-F·key=|-k\s+)actions$1275 ········contains:·^.*(?:-F·key=|-k\s+)actions$
1276 ········patterns:·'*.rules'1276 ········patterns:·'*.rules'
1277 ······register:·find_watch_key1277 ······register:·find_watch_key
1278 ······when:1278 ······when:
1279 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1280 ······-·'"auditd"·in·ansible_facts.packages'1279 ······-·'"auditd"·in·ansible_facts.packages'
 1280 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1281 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched1281 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
1282 ········==·01282 ········==·0
1283 ······tags:1283 ······tags:
1284 ······-·CJIS-5.4.1.11284 ······-·CJIS-5.4.1.1
1285 ······-·NIST-800-171-3.1.71285 ······-·NIST-800-171-3.1.7
1286 ······-·NIST-800-53-AC-2(7)(b)1286 ······-·NIST-800-53-AC-2(7)(b)
1287 ······-·NIST-800-53-AC-6(9)1287 ······-·NIST-800-53-AC-6(9)
Offset 1298, 16 lines modifiedOffset 1298, 16 lines modified
1298 ······-·restrict_strategy1298 ······-·restrict_strategy
  
1299 ····-·name:·Use·/etc/audit/rules.d/actions.rules·as·the·recipient·for·the·rule1299 ····-·name:·Use·/etc/audit/rules.d/actions.rules·as·the·recipient·for·the·rule
1300 ······set_fact:1300 ······set_fact:
1301 ········all_files:1301 ········all_files:
1302 ········-·/etc/audit/rules.d/actions.rules1302 ········-·/etc/audit/rules.d/actions.rules
1303 ······when:1303 ······when:
1304 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1305 ······-·'"auditd"·in·ansible_facts.packages'1304 ······-·'"auditd"·in·ansible_facts.packages'
 1305 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1306 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched1306 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
1307 ········is·defined·and·find_existing_watch_rules_d.matched·==·01307 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1308 ······tags:1308 ······tags:
1309 ······-·CJIS-5.4.1.11309 ······-·CJIS-5.4.1.1
1310 ······-·NIST-800-171-3.1.71310 ······-·NIST-800-171-3.1.7
1311 ······-·NIST-800-53-AC-2(7)(b)1311 ······-·NIST-800-53-AC-2(7)(b)
1312 ······-·NIST-800-53-AC-6(9)1312 ······-·NIST-800-53-AC-6(9)
Offset 1324, 16 lines modifiedOffset 1324, 16 lines modified
1324 ······-·restrict_strategy1324 ······-·restrict_strategy
  
1325 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule1325 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
1326 ······set_fact:1326 ······set_fact:
1327 ········all_files:1327 ········all_files:
1328 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'1328 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
1329 ······when:1329 ······when:
1330 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1331 ······-·'"auditd"·in·ansible_facts.packages'1330 ······-·'"auditd"·in·ansible_facts.packages'
 1331 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1332 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched1332 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
1333 ········is·defined·and·find_existing_watch_rules_d.matched·==·01333 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1334 ······tags:1334 ······tags:
1335 ······-·CJIS-5.4.1.11335 ······-·CJIS-5.4.1.1
1336 ······-·NIST-800-171-3.1.71336 ······-·NIST-800-171-3.1.7
1337 ······-·NIST-800-53-AC-2(7)(b)1337 ······-·NIST-800-53-AC-2(7)(b)
1338 ······-·NIST-800-53-AC-6(9)1338 ······-·NIST-800-53-AC-6(9)
Offset 1352, 16 lines modifiedOffset 1352, 16 lines modified
1352 ····-·name:·Add·watch·rule·for·/etc/sudoers·in·/etc/audit/rules.d/1352 ····-·name:·Add·watch·rule·for·/etc/sudoers·in·/etc/audit/rules.d/
Max diff block lines reached; 130561/135598 bytes (96.29%) of diff not shown.
133 KB
./usr/share/scap-security-guide/ansible/ubuntu2204-playbook-cis_level2_workstation.yml
Ordering differences only
    
Offset 1121, 16 lines modifiedOffset 1121, 16 lines modified
  
1121 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension1121 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
1122 ······find:1122 ······find:
1123 ········paths:·/etc/audit/rules.d/1123 ········paths:·/etc/audit/rules.d/
1124 ········patterns:·'*.rules'1124 ········patterns:·'*.rules'
1125 ······register:·find_rules_d1125 ······register:·find_rules_d
1126 ······when:1126 ······when:
1127 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1128 ······-·'"auditd"·in·ansible_facts.packages'1127 ······-·'"auditd"·in·ansible_facts.packages'
 1128 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1129 ······tags:1129 ······tags:
1130 ······-·CJIS-5.4.1.11130 ······-·CJIS-5.4.1.1
1131 ······-·NIST-800-171-3.3.11131 ······-·NIST-800-171-3.3.1
1132 ······-·NIST-800-171-3.4.31132 ······-·NIST-800-171-3.4.3
1133 ······-·NIST-800-53-AC-6(9)1133 ······-·NIST-800-53-AC-6(9)
1134 ······-·NIST-800-53-CM-6(a)1134 ······-·NIST-800-53-CM-6(a)
1135 ······-·PCI-DSS-Req-10.5.21135 ······-·PCI-DSS-Req-10.5.2
Offset 1145, 16 lines modifiedOffset 1145, 16 lines modified
1145 ······lineinfile:1145 ······lineinfile:
1146 ········path:·'{{·item·}}'1146 ········path:·'{{·item·}}'
1147 ········regexp:·^\s*(?:-e)\s+.*$1147 ········regexp:·^\s*(?:-e)\s+.*$
1148 ········state:·absent1148 ········state:·absent
1149 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']1149 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
1150 ········}}'1150 ········}}'
1151 ······when:1151 ······when:
1152 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1153 ······-·'"auditd"·in·ansible_facts.packages'1152 ······-·'"auditd"·in·ansible_facts.packages'
 1153 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1154 ······tags:1154 ······tags:
1155 ······-·CJIS-5.4.1.11155 ······-·CJIS-5.4.1.1
1156 ······-·NIST-800-171-3.3.11156 ······-·NIST-800-171-3.3.1
1157 ······-·NIST-800-171-3.4.31157 ······-·NIST-800-171-3.4.3
1158 ······-·NIST-800-53-AC-6(9)1158 ······-·NIST-800-53-AC-6(9)
1159 ······-·NIST-800-53-CM-6(a)1159 ······-·NIST-800-53-CM-6(a)
1160 ······-·PCI-DSS-Req-10.5.21160 ······-·PCI-DSS-Req-10.5.2
Offset 1171, 16 lines modifiedOffset 1171, 16 lines modified
1171 ········create:·true1171 ········create:·true
1172 ········line:·-e·21172 ········line:·-e·2
1173 ········mode:·o-rwx1173 ········mode:·o-rwx
1174 ······loop:1174 ······loop:
1175 ······-·/etc/audit/audit.rules1175 ······-·/etc/audit/audit.rules
1176 ······-·/etc/audit/rules.d/immutable.rules1176 ······-·/etc/audit/rules.d/immutable.rules
1177 ······when:1177 ······when:
1178 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1179 ······-·'"auditd"·in·ansible_facts.packages'1178 ······-·'"auditd"·in·ansible_facts.packages'
 1179 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1180 ······tags:1180 ······tags:
1181 ······-·CJIS-5.4.1.11181 ······-·CJIS-5.4.1.1
1182 ······-·NIST-800-171-3.3.11182 ······-·NIST-800-171-3.3.1
1183 ······-·NIST-800-171-3.4.31183 ······-·NIST-800-171-3.4.3
1184 ······-·NIST-800-53-AC-6(9)1184 ······-·NIST-800-53-AC-6(9)
1185 ······-·NIST-800-53-CM-6(a)1185 ······-·NIST-800-53-CM-6(a)
1186 ······-·PCI-DSS-Req-10.5.21186 ······-·PCI-DSS-Req-10.5.2
Offset 1215, 16 lines modifiedOffset 1215, 16 lines modified
1215 ····-·name:·Check·if·watch·rule·for·/etc/sudoers·already·exists·in·/etc/audit/rules.d/1215 ····-·name:·Check·if·watch·rule·for·/etc/sudoers·already·exists·in·/etc/audit/rules.d/
1216 ······find:1216 ······find:
1217 ········paths:·/etc/audit/rules.d1217 ········paths:·/etc/audit/rules.d
1218 ········contains:·^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+1218 ········contains:·^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+
1219 ········patterns:·'*.rules'1219 ········patterns:·'*.rules'
1220 ······register:·find_existing_watch_rules_d1220 ······register:·find_existing_watch_rules_d
1221 ······when:1221 ······when:
1222 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1223 ······-·'"auditd"·in·ansible_facts.packages'1222 ······-·'"auditd"·in·ansible_facts.packages'
 1223 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1224 ······tags:1224 ······tags:
1225 ······-·CJIS-5.4.1.11225 ······-·CJIS-5.4.1.1
1226 ······-·NIST-800-171-3.1.71226 ······-·NIST-800-171-3.1.7
1227 ······-·NIST-800-53-AC-2(7)(b)1227 ······-·NIST-800-53-AC-2(7)(b)
1228 ······-·NIST-800-53-AC-6(9)1228 ······-·NIST-800-53-AC-6(9)
1229 ······-·NIST-800-53-AU-12(c)1229 ······-·NIST-800-53-AU-12(c)
1230 ······-·NIST-800-53-AU-2(d)1230 ······-·NIST-800-53-AU-2(d)
Offset 1241, 16 lines modifiedOffset 1241, 16 lines modified
1241 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·actions1241 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·actions
1242 ······find:1242 ······find:
1243 ········paths:·/etc/audit/rules.d1243 ········paths:·/etc/audit/rules.d
1244 ········contains:·^.*(?:-F·key=|-k\s+)actions$1244 ········contains:·^.*(?:-F·key=|-k\s+)actions$
1245 ········patterns:·'*.rules'1245 ········patterns:·'*.rules'
1246 ······register:·find_watch_key1246 ······register:·find_watch_key
1247 ······when:1247 ······when:
1248 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1249 ······-·'"auditd"·in·ansible_facts.packages'1248 ······-·'"auditd"·in·ansible_facts.packages'
 1249 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1250 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched1250 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
1251 ········==·01251 ········==·0
1252 ······tags:1252 ······tags:
1253 ······-·CJIS-5.4.1.11253 ······-·CJIS-5.4.1.1
1254 ······-·NIST-800-171-3.1.71254 ······-·NIST-800-171-3.1.7
1255 ······-·NIST-800-53-AC-2(7)(b)1255 ······-·NIST-800-53-AC-2(7)(b)
1256 ······-·NIST-800-53-AC-6(9)1256 ······-·NIST-800-53-AC-6(9)
Offset 1267, 16 lines modifiedOffset 1267, 16 lines modified
1267 ······-·restrict_strategy1267 ······-·restrict_strategy
  
1268 ····-·name:·Use·/etc/audit/rules.d/actions.rules·as·the·recipient·for·the·rule1268 ····-·name:·Use·/etc/audit/rules.d/actions.rules·as·the·recipient·for·the·rule
1269 ······set_fact:1269 ······set_fact:
1270 ········all_files:1270 ········all_files:
1271 ········-·/etc/audit/rules.d/actions.rules1271 ········-·/etc/audit/rules.d/actions.rules
1272 ······when:1272 ······when:
1273 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1274 ······-·'"auditd"·in·ansible_facts.packages'1273 ······-·'"auditd"·in·ansible_facts.packages'
 1274 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1275 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched1275 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
1276 ········is·defined·and·find_existing_watch_rules_d.matched·==·01276 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1277 ······tags:1277 ······tags:
1278 ······-·CJIS-5.4.1.11278 ······-·CJIS-5.4.1.1
1279 ······-·NIST-800-171-3.1.71279 ······-·NIST-800-171-3.1.7
1280 ······-·NIST-800-53-AC-2(7)(b)1280 ······-·NIST-800-53-AC-2(7)(b)
1281 ······-·NIST-800-53-AC-6(9)1281 ······-·NIST-800-53-AC-6(9)
Offset 1293, 16 lines modifiedOffset 1293, 16 lines modified
1293 ······-·restrict_strategy1293 ······-·restrict_strategy
  
1294 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule1294 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
1295 ······set_fact:1295 ······set_fact:
1296 ········all_files:1296 ········all_files:
1297 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'1297 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
1298 ······when:1298 ······when:
1299 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1300 ······-·'"auditd"·in·ansible_facts.packages'1299 ······-·'"auditd"·in·ansible_facts.packages'
 1300 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1301 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched1301 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
1302 ········is·defined·and·find_existing_watch_rules_d.matched·==·01302 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1303 ······tags:1303 ······tags:
1304 ······-·CJIS-5.4.1.11304 ······-·CJIS-5.4.1.1
1305 ······-·NIST-800-171-3.1.71305 ······-·NIST-800-171-3.1.7
1306 ······-·NIST-800-53-AC-2(7)(b)1306 ······-·NIST-800-53-AC-2(7)(b)
1307 ······-·NIST-800-53-AC-6(9)1307 ······-·NIST-800-53-AC-6(9)
Offset 1321, 16 lines modifiedOffset 1321, 16 lines modified
1321 ····-·name:·Add·watch·rule·for·/etc/sudoers·in·/etc/audit/rules.d/1321 ····-·name:·Add·watch·rule·for·/etc/sudoers·in·/etc/audit/rules.d/
Max diff block lines reached; 130561/135598 bytes (96.29%) of diff not shown.
1.43 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-ds-1.2.xml
1.31 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-ds-1.2.xml
    
Offset 92, 15 lines modifiedOffset 92, 15 lines modified
92 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·16.04·(Xenial)</cpe-dict:title>92 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·16.04·(Xenial)</cpe-dict:title>
93 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu1604:def:1</cpe-dict:check>93 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu1604:def:1</cpe-dict:check>
94 ······</cpe-dict:cpe-item>94 ······</cpe-dict:cpe-item>
95 ····</cpe-dict:cpe-list>95 ····</cpe-dict:cpe-list>
96 ··</ds:component>96 ··</ds:component>
97 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-xccdf.xml"·timestamp="2022-12-20T09:54:05">97 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-xccdf.xml"·timestamp="2022-12-20T09:54:05">
98 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-XENIAL"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">98 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-XENIAL"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
99 ······<xccdf-1.2:status·date="2024-01-14">draft</xccdf-1.2:status>99 ······<xccdf-1.2:status·date="2025-02-15">draft</xccdf-1.2:status>
100 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·16.04</xccdf-1.2:title>100 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·16.04</xccdf-1.2:title>
101 ······<xccdf-1.2:description>101 ······<xccdf-1.2:description>
102 ········This·guide·presents·a·catalog·of·security-relevant102 ········This·guide·presents·a·catalog·of·security-relevant
103 configuration·settings·for·Ubuntu·16.04.·It·is·a·rendering·of103 configuration·settings·for·Ubuntu·16.04.·It·is·a·rendering·of
104 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)104 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
105 in·order·to·support·security·automation.··The·SCAP·content·is105 in·order·to·support·security·automation.··The·SCAP·content·is
106 is·available·in·the106 is·available·in·the
1.41 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-ds.xml
1.31 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-ds.xml
    
Offset 94, 15 lines modifiedOffset 94, 15 lines modified
94 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·16.04·(Xenial)</cpe-dict:title>94 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·16.04·(Xenial)</cpe-dict:title>
95 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu1604:def:1</cpe-dict:check>95 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu1604:def:1</cpe-dict:check>
96 ······</cpe-dict:cpe-item>96 ······</cpe-dict:cpe-item>
97 ····</cpe-dict:cpe-list>97 ····</cpe-dict:cpe-list>
98 ··</ds:component>98 ··</ds:component>
99 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-xccdf.xml"·timestamp="2022-12-20T09:54:05">99 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-xccdf.xml"·timestamp="2022-12-20T09:54:05">
100 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-XENIAL"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">100 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-XENIAL"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
101 ······<xccdf-1.2:status·date="2024-01-14">draft</xccdf-1.2:status>101 ······<xccdf-1.2:status·date="2025-02-15">draft</xccdf-1.2:status>
102 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·16.04</xccdf-1.2:title>102 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·16.04</xccdf-1.2:title>
103 ······<xccdf-1.2:description>103 ······<xccdf-1.2:description>
104 ········This·guide·presents·a·catalog·of·security-relevant104 ········This·guide·presents·a·catalog·of·security-relevant
105 configuration·settings·for·Ubuntu·16.04.·It·is·a·rendering·of105 configuration·settings·for·Ubuntu·16.04.·It·is·a·rendering·of
106 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)106 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
107 in·order·to·support·security·automation.··The·SCAP·content·is107 in·order·to·support·security·automation.··The·SCAP·content·is
108 is·available·in·the108 is·available·in·the
1.24 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-xccdf.xml
1.13 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-xccdf.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-XENIAL"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-XENIAL"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
3 ··<xccdf-1.2:status·date="2024-01-14">draft</xccdf-1.2:status>3 ··<xccdf-1.2:status·date="2025-02-15">draft</xccdf-1.2:status>
4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·16.04</xccdf-1.2:title>4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·16.04</xccdf-1.2:title>
5 ··<xccdf-1.2:description>5 ··<xccdf-1.2:description>
6 ····This·guide·presents·a·catalog·of·security-relevant6 ····This·guide·presents·a·catalog·of·security-relevant
7 configuration·settings·for·Ubuntu·16.04.·It·is·a·rendering·of7 configuration·settings·for·Ubuntu·16.04.·It·is·a·rendering·of
8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
9 in·order·to·support·security·automation.··The·SCAP·content·is9 in·order·to·support·security·automation.··The·SCAP·content·is
10 is·available·in·the10 is·available·in·the
1.44 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-ds-1.2.xml
1.32 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-ds-1.2.xml
    
Offset 100, 15 lines modifiedOffset 100, 15 lines modified
100 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·18.04·(Bionic·Beaver)</cpe-dict:title>100 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·18.04·(Bionic·Beaver)</cpe-dict:title>
101 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu1804:def:1</cpe-dict:check>101 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu1804:def:1</cpe-dict:check>
102 ······</cpe-dict:cpe-item>102 ······</cpe-dict:cpe-item>
103 ····</cpe-dict:cpe-list>103 ····</cpe-dict:cpe-list>
104 ··</ds:component>104 ··</ds:component>
105 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-xccdf.xml"·timestamp="2022-12-20T09:54:05">105 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-xccdf.xml"·timestamp="2022-12-20T09:54:05">
106 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-BIONIC"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">106 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-BIONIC"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
107 ······<xccdf-1.2:status·date="2024-01-14">draft</xccdf-1.2:status>107 ······<xccdf-1.2:status·date="2025-02-15">draft</xccdf-1.2:status>
108 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·18.04</xccdf-1.2:title>108 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·18.04</xccdf-1.2:title>
109 ······<xccdf-1.2:description>109 ······<xccdf-1.2:description>
110 ········This·guide·presents·a·catalog·of·security-relevant110 ········This·guide·presents·a·catalog·of·security-relevant
111 configuration·settings·for·Ubuntu·18.04.·It·is·a·rendering·of111 configuration·settings·for·Ubuntu·18.04.·It·is·a·rendering·of
112 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)112 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
113 in·order·to·support·security·automation.··The·SCAP·content·is113 in·order·to·support·security·automation.··The·SCAP·content·is
114 is·available·in·the114 is·available·in·the
1.42 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-ds.xml
1.31 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-ds.xml
    
Offset 100, 15 lines modifiedOffset 100, 15 lines modified
100 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·18.04·(Bionic·Beaver)</cpe-dict:title>100 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·18.04·(Bionic·Beaver)</cpe-dict:title>
101 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu1804:def:1</cpe-dict:check>101 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu1804:def:1</cpe-dict:check>
102 ······</cpe-dict:cpe-item>102 ······</cpe-dict:cpe-item>
103 ····</cpe-dict:cpe-list>103 ····</cpe-dict:cpe-list>
104 ··</ds:component>104 ··</ds:component>
105 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-xccdf.xml"·timestamp="2022-12-20T09:54:05">105 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-xccdf.xml"·timestamp="2022-12-20T09:54:05">
106 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-BIONIC"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">106 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-BIONIC"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
107 ······<xccdf-1.2:status·date="2024-01-14">draft</xccdf-1.2:status>107 ······<xccdf-1.2:status·date="2025-02-15">draft</xccdf-1.2:status>
108 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·18.04</xccdf-1.2:title>108 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·18.04</xccdf-1.2:title>
109 ······<xccdf-1.2:description>109 ······<xccdf-1.2:description>
110 ········This·guide·presents·a·catalog·of·security-relevant110 ········This·guide·presents·a·catalog·of·security-relevant
111 configuration·settings·for·Ubuntu·18.04.·It·is·a·rendering·of111 configuration·settings·for·Ubuntu·18.04.·It·is·a·rendering·of
112 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)112 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
113 in·order·to·support·security·automation.··The·SCAP·content·is113 in·order·to·support·security·automation.··The·SCAP·content·is
114 is·available·in·the114 is·available·in·the
1.24 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-xccdf.xml
1.13 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-xccdf.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-BIONIC"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-BIONIC"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
3 ··<xccdf-1.2:status·date="2024-01-14">draft</xccdf-1.2:status>3 ··<xccdf-1.2:status·date="2025-02-15">draft</xccdf-1.2:status>
4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·18.04</xccdf-1.2:title>4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·18.04</xccdf-1.2:title>
5 ··<xccdf-1.2:description>5 ··<xccdf-1.2:description>
6 ····This·guide·presents·a·catalog·of·security-relevant6 ····This·guide·presents·a·catalog·of·security-relevant
7 configuration·settings·for·Ubuntu·18.04.·It·is·a·rendering·of7 configuration·settings·for·Ubuntu·18.04.·It·is·a·rendering·of
8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
9 in·order·to·support·security·automation.··The·SCAP·content·is9 in·order·to·support·security·automation.··The·SCAP·content·is
10 is·available·in·the10 is·available·in·the
1.43 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ds-1.2.xml
1.32 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ds-1.2.xml
    
Offset 100, 15 lines modifiedOffset 100, 15 lines modified
100 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·20.04·(Focal·Fossa)</cpe-dict:title>100 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·20.04·(Focal·Fossa)</cpe-dict:title>
101 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2004:def:1</cpe-dict:check>101 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2004:def:1</cpe-dict:check>
102 ······</cpe-dict:cpe-item>102 ······</cpe-dict:cpe-item>
103 ····</cpe-dict:cpe-list>103 ····</cpe-dict:cpe-list>
104 ··</ds:component>104 ··</ds:component>
105 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-xccdf.xml"·timestamp="2022-12-20T09:54:05">105 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-xccdf.xml"·timestamp="2022-12-20T09:54:05">
106 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_20-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">106 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_20-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
107 ······<xccdf-1.2:status·date="2024-01-14">draft</xccdf-1.2:status>107 ······<xccdf-1.2:status·date="2025-02-15">draft</xccdf-1.2:status>
108 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·20.04</xccdf-1.2:title>108 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·20.04</xccdf-1.2:title>
109 ······<xccdf-1.2:description>109 ······<xccdf-1.2:description>
110 ········This·guide·presents·a·catalog·of·security-relevant110 ········This·guide·presents·a·catalog·of·security-relevant
111 configuration·settings·for·Ubuntu·20.04.·It·is·a·rendering·of111 configuration·settings·for·Ubuntu·20.04.·It·is·a·rendering·of
112 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)112 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
113 in·order·to·support·security·automation.··The·SCAP·content·is113 in·order·to·support·security·automation.··The·SCAP·content·is
114 is·available·in·the114 is·available·in·the
1.42 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ds.xml
1.31 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ds.xml
    
Offset 100, 15 lines modifiedOffset 100, 15 lines modified
100 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·20.04·(Focal·Fossa)</cpe-dict:title>100 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·20.04·(Focal·Fossa)</cpe-dict:title>
101 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2004:def:1</cpe-dict:check>101 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2004:def:1</cpe-dict:check>
102 ······</cpe-dict:cpe-item>102 ······</cpe-dict:cpe-item>
103 ····</cpe-dict:cpe-list>103 ····</cpe-dict:cpe-list>
104 ··</ds:component>104 ··</ds:component>
105 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-xccdf.xml"·timestamp="2022-12-20T09:54:05">105 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-xccdf.xml"·timestamp="2022-12-20T09:54:05">
106 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_20-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">106 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_20-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
107 ······<xccdf-1.2:status·date="2024-01-14">draft</xccdf-1.2:status>107 ······<xccdf-1.2:status·date="2025-02-15">draft</xccdf-1.2:status>
108 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·20.04</xccdf-1.2:title>108 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·20.04</xccdf-1.2:title>
109 ······<xccdf-1.2:description>109 ······<xccdf-1.2:description>
110 ········This·guide·presents·a·catalog·of·security-relevant110 ········This·guide·presents·a·catalog·of·security-relevant
111 configuration·settings·for·Ubuntu·20.04.·It·is·a·rendering·of111 configuration·settings·for·Ubuntu·20.04.·It·is·a·rendering·of
112 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)112 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
113 in·order·to·support·security·automation.··The·SCAP·content·is113 in·order·to·support·security·automation.··The·SCAP·content·is
114 is·available·in·the114 is·available·in·the
1.24 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-xccdf.xml
1.13 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-xccdf.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_20-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_20-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
3 ··<xccdf-1.2:status·date="2024-01-14">draft</xccdf-1.2:status>3 ··<xccdf-1.2:status·date="2025-02-15">draft</xccdf-1.2:status>
4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·20.04</xccdf-1.2:title>4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·20.04</xccdf-1.2:title>
5 ··<xccdf-1.2:description>5 ··<xccdf-1.2:description>
6 ····This·guide·presents·a·catalog·of·security-relevant6 ····This·guide·presents·a·catalog·of·security-relevant
7 configuration·settings·for·Ubuntu·20.04.·It·is·a·rendering·of7 configuration·settings·for·Ubuntu·20.04.·It·is·a·rendering·of
8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
9 in·order·to·support·security·automation.··The·SCAP·content·is9 in·order·to·support·security·automation.··The·SCAP·content·is
10 is·available·in·the10 is·available·in·the
282 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ds-1.2.xml
281 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ds-1.2.xml
    
Offset 100, 15 lines modifiedOffset 100, 15 lines modified
100 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·22.04·(Focal·Fossa)</cpe-dict:title>100 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·22.04·(Focal·Fossa)</cpe-dict:title>
101 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2204:def:1</cpe-dict:check>101 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2204:def:1</cpe-dict:check>
102 ······</cpe-dict:cpe-item>102 ······</cpe-dict:cpe-item>
103 ····</cpe-dict:cpe-list>103 ····</cpe-dict:cpe-list>
104 ··</ds:component>104 ··</ds:component>
105 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-xccdf.xml"·timestamp="2022-12-20T09:54:05">105 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-xccdf.xml"·timestamp="2022-12-20T09:54:05">
106 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_22-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">106 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_22-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
107 ······<xccdf-1.2:status·date="2024-01-14">draft</xccdf-1.2:status>107 ······<xccdf-1.2:status·date="2025-02-15">draft</xccdf-1.2:status>
108 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·22.04</xccdf-1.2:title>108 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·22.04</xccdf-1.2:title>
109 ······<xccdf-1.2:description>109 ······<xccdf-1.2:description>
110 ········This·guide·presents·a·catalog·of·security-relevant110 ········This·guide·presents·a·catalog·of·security-relevant
111 configuration·settings·for·Ubuntu·22.04.·It·is·a·rendering·of111 configuration·settings·for·Ubuntu·22.04.·It·is·a·rendering·of
112 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)112 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
113 in·order·to·support·security·automation.··The·SCAP·content·is113 in·order·to·support·security·automation.··The·SCAP·content·is
114 is·available·in·the114 is·available·in·the
Offset 15798, 16 lines modifiedOffset 15798, 16 lines modified
  
15798 -·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension15798 -·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
15799 ··find:15799 ··find:
15800 ····paths:·/etc/audit/rules.d/15800 ····paths:·/etc/audit/rules.d/
15801 ····patterns:·'*.rules'15801 ····patterns:·'*.rules'
15802 ··register:·find_rules_d15802 ··register:·find_rules_d
15803 ··when:15803 ··when:
15804 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;] 
15805 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'15804 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'
 15805 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;]
15806 ··tags:15806 ··tags:
15807 ··-·CJIS-5.4.1.115807 ··-·CJIS-5.4.1.1
15808 ··-·NIST-800-171-3.3.115808 ··-·NIST-800-171-3.3.1
15809 ··-·NIST-800-171-3.4.315809 ··-·NIST-800-171-3.4.3
15810 ··-·NIST-800-53-AC-6(9)15810 ··-·NIST-800-53-AC-6(9)
15811 ··-·NIST-800-53-CM-6(a)15811 ··-·NIST-800-53-CM-6(a)
15812 ··-·PCI-DSS-Req-10.5.215812 ··-·PCI-DSS-Req-10.5.2
Offset 15822, 16 lines modifiedOffset 15822, 16 lines modified
15822 ··lineinfile:15822 ··lineinfile:
15823 ····path:·'{{·item·}}'15823 ····path:·'{{·item·}}'
15824 ····regexp:·^\s*(?:-e)\s+.*$15824 ····regexp:·^\s*(?:-e)\s+.*$
15825 ····state:·absent15825 ····state:·absent
15826 ··loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']15826 ··loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
15827 ····}}'15827 ····}}'
15828 ··when:15828 ··when:
15829 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;] 
15830 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'15829 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'
 15830 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;]
15831 ··tags:15831 ··tags:
15832 ··-·CJIS-5.4.1.115832 ··-·CJIS-5.4.1.1
15833 ··-·NIST-800-171-3.3.115833 ··-·NIST-800-171-3.3.1
15834 ··-·NIST-800-171-3.4.315834 ··-·NIST-800-171-3.4.3
15835 ··-·NIST-800-53-AC-6(9)15835 ··-·NIST-800-53-AC-6(9)
15836 ··-·NIST-800-53-CM-6(a)15836 ··-·NIST-800-53-CM-6(a)
15837 ··-·PCI-DSS-Req-10.5.215837 ··-·PCI-DSS-Req-10.5.2
Offset 15848, 16 lines modifiedOffset 15848, 16 lines modified
15848 ····create:·true15848 ····create:·true
15849 ····line:·-e·215849 ····line:·-e·2
15850 ····mode:·o-rwx15850 ····mode:·o-rwx
15851 ··loop:15851 ··loop:
15852 ··-·/etc/audit/audit.rules15852 ··-·/etc/audit/audit.rules
15853 ··-·/etc/audit/rules.d/immutable.rules15853 ··-·/etc/audit/rules.d/immutable.rules
15854 ··when:15854 ··when:
15855 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;] 
15856 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'15855 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'
 15856 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;]
15857 ··tags:15857 ··tags:
15858 ··-·CJIS-5.4.1.115858 ··-·CJIS-5.4.1.1
15859 ··-·NIST-800-171-3.3.115859 ··-·NIST-800-171-3.3.1
15860 ··-·NIST-800-171-3.4.315860 ··-·NIST-800-171-3.4.3
15861 ··-·NIST-800-53-AC-6(9)15861 ··-·NIST-800-53-AC-6(9)
15862 ··-·NIST-800-53-CM-6(a)15862 ··-·NIST-800-53-CM-6(a)
15863 ··-·PCI-DSS-Req-10.5.215863 ··-·PCI-DSS-Req-10.5.2
Offset 16201, 16 lines modifiedOffset 16201, 16 lines modified
16201 ··-·reboot_required16201 ··-·reboot_required
16202 ··-·restrict_strategy16202 ··-·restrict_strategy
  
16203 -·name:·Set·architecture·for·audit·mount·tasks16203 -·name:·Set·architecture·for·audit·mount·tasks
16204 ··set_fact:16204 ··set_fact:
16205 ····audit_arch:·b6416205 ····audit_arch:·b64
16206 ··when:16206 ··when:
16207 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;] 
16208 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'16207 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'
 16208 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;]
16209 ··-·ansible_architecture·==·&quot;aarch64&quot;·or·ansible_architecture·==·&quot;ppc64&quot;·or·ansible_architecture16209 ··-·ansible_architecture·==·&quot;aarch64&quot;·or·ansible_architecture·==·&quot;ppc64&quot;·or·ansible_architecture
16210 ····==·&quot;ppc64le&quot;·or·ansible_architecture·==·&quot;s390x&quot;·or·ansible_architecture·==·&quot;x86_64&quot;16210 ····==·&quot;ppc64le&quot;·or·ansible_architecture·==·&quot;s390x&quot;·or·ansible_architecture·==·&quot;x86_64&quot;
16211 ··tags:16211 ··tags:
16212 ··-·CJIS-5.4.1.116212 ··-·CJIS-5.4.1.1
16213 ··-·NIST-800-171-3.1.716213 ··-·NIST-800-171-3.1.7
16214 ··-·NIST-800-53-AC-6(9)16214 ··-·NIST-800-53-AC-6(9)
16215 ··-·NIST-800-53-AU-12(c)16215 ··-·NIST-800-53-AU-12(c)
Offset 16341, 16 lines modifiedOffset 16341, 16 lines modified
16341 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid&gt;=100016341 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid&gt;=1000
16342 ········-F·auid!=unset·-F·key=perm_mod16342 ········-F·auid!=unset·-F·key=perm_mod
16343 ······create:·true16343 ······create:·true
16344 ······mode:·o-rwx16344 ······mode:·o-rwx
16345 ······state:·present16345 ······state:·present
16346 ····when:·syscalls_found·|·length·==·016346 ····when:·syscalls_found·|·length·==·0
16347 ··when:16347 ··when:
16348 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;] 
16349 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'16348 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'
 16349 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;]
16350 ··tags:16350 ··tags:
16351 ··-·CJIS-5.4.1.116351 ··-·CJIS-5.4.1.1
16352 ··-·NIST-800-171-3.1.716352 ··-·NIST-800-171-3.1.7
16353 ··-·NIST-800-53-AC-6(9)16353 ··-·NIST-800-53-AC-6(9)
16354 ··-·NIST-800-53-AU-12(c)16354 ··-·NIST-800-53-AU-12(c)
16355 ··-·NIST-800-53-AU-2(d)16355 ··-·NIST-800-53-AU-2(d)
16356 ··-·NIST-800-53-CM-6(a)16356 ··-·NIST-800-53-CM-6(a)
Offset 16479, 16 lines modifiedOffset 16479, 16 lines modified
16479 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid&gt;=100016479 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid&gt;=1000
16480 ········-F·auid!=unset·-F·key=perm_mod16480 ········-F·auid!=unset·-F·key=perm_mod
16481 ······create:·true16481 ······create:·true
16482 ······mode:·o-rwx16482 ······mode:·o-rwx
16483 ······state:·present16483 ······state:·present
16484 ····when:·syscalls_found·|·length·==·016484 ····when:·syscalls_found·|·length·==·0
16485 ··when:16485 ··when:
16486 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;] 
16487 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'16486 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'
 16487 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;]
16488 ··-·audit_arch·==·&quot;b64&quot;16488 ··-·audit_arch·==·&quot;b64&quot;
16489 ··tags:16489 ··tags:
16490 ··-·CJIS-5.4.1.116490 ··-·CJIS-5.4.1.1
16491 ··-·NIST-800-171-3.1.716491 ··-·NIST-800-171-3.1.7
16492 ··-·NIST-800-53-AC-6(9)16492 ··-·NIST-800-53-AC-6(9)
16493 ··-·NIST-800-53-AU-12(c)16493 ··-·NIST-800-53-AU-12(c)
16494 ··-·NIST-800-53-AU-2(d)16494 ··-·NIST-800-53-AU-2(d)
Offset 16497, 15 lines modifiedOffset 16497, 15 lines modified
16497 ··-·audit_rules_media_export16497 ··-·audit_rules_media_export
16498 ··-·low_complexity16498 ··-·low_complexity
16499 ··-·low_disruption16499 ··-·low_disruption
Max diff block lines reached; 282396/288134 bytes (98.01%) of diff not shown.
282 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ds.xml
281 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ds.xml
    
Offset 100, 15 lines modifiedOffset 100, 15 lines modified
100 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·22.04·(Focal·Fossa)</cpe-dict:title>100 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·22.04·(Focal·Fossa)</cpe-dict:title>
101 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2204:def:1</cpe-dict:check>101 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2204:def:1</cpe-dict:check>
102 ······</cpe-dict:cpe-item>102 ······</cpe-dict:cpe-item>
103 ····</cpe-dict:cpe-list>103 ····</cpe-dict:cpe-list>
104 ··</ds:component>104 ··</ds:component>
105 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-xccdf.xml"·timestamp="2022-12-20T09:54:05">105 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-xccdf.xml"·timestamp="2022-12-20T09:54:05">
106 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_22-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">106 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_22-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
107 ······<xccdf-1.2:status·date="2024-01-14">draft</xccdf-1.2:status>107 ······<xccdf-1.2:status·date="2025-02-15">draft</xccdf-1.2:status>
108 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·22.04</xccdf-1.2:title>108 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·22.04</xccdf-1.2:title>
109 ······<xccdf-1.2:description>109 ······<xccdf-1.2:description>
110 ········This·guide·presents·a·catalog·of·security-relevant110 ········This·guide·presents·a·catalog·of·security-relevant
111 configuration·settings·for·Ubuntu·22.04.·It·is·a·rendering·of111 configuration·settings·for·Ubuntu·22.04.·It·is·a·rendering·of
112 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)112 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
113 in·order·to·support·security·automation.··The·SCAP·content·is113 in·order·to·support·security·automation.··The·SCAP·content·is
114 is·available·in·the114 is·available·in·the
Offset 15798, 16 lines modifiedOffset 15798, 16 lines modified
  
15798 -·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension15798 -·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
15799 ··find:15799 ··find:
15800 ····paths:·/etc/audit/rules.d/15800 ····paths:·/etc/audit/rules.d/
15801 ····patterns:·'*.rules'15801 ····patterns:·'*.rules'
15802 ··register:·find_rules_d15802 ··register:·find_rules_d
15803 ··when:15803 ··when:
15804 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;] 
15805 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'15804 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'
 15805 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;]
15806 ··tags:15806 ··tags:
15807 ··-·CJIS-5.4.1.115807 ··-·CJIS-5.4.1.1
15808 ··-·NIST-800-171-3.3.115808 ··-·NIST-800-171-3.3.1
15809 ··-·NIST-800-171-3.4.315809 ··-·NIST-800-171-3.4.3
15810 ··-·NIST-800-53-AC-6(9)15810 ··-·NIST-800-53-AC-6(9)
15811 ··-·NIST-800-53-CM-6(a)15811 ··-·NIST-800-53-CM-6(a)
15812 ··-·PCI-DSS-Req-10.5.215812 ··-·PCI-DSS-Req-10.5.2
Offset 15822, 16 lines modifiedOffset 15822, 16 lines modified
15822 ··lineinfile:15822 ··lineinfile:
15823 ····path:·'{{·item·}}'15823 ····path:·'{{·item·}}'
15824 ····regexp:·^\s*(?:-e)\s+.*$15824 ····regexp:·^\s*(?:-e)\s+.*$
15825 ····state:·absent15825 ····state:·absent
15826 ··loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']15826 ··loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
15827 ····}}'15827 ····}}'
15828 ··when:15828 ··when:
15829 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;] 
15830 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'15829 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'
 15830 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;]
15831 ··tags:15831 ··tags:
15832 ··-·CJIS-5.4.1.115832 ··-·CJIS-5.4.1.1
15833 ··-·NIST-800-171-3.3.115833 ··-·NIST-800-171-3.3.1
15834 ··-·NIST-800-171-3.4.315834 ··-·NIST-800-171-3.4.3
15835 ··-·NIST-800-53-AC-6(9)15835 ··-·NIST-800-53-AC-6(9)
15836 ··-·NIST-800-53-CM-6(a)15836 ··-·NIST-800-53-CM-6(a)
15837 ··-·PCI-DSS-Req-10.5.215837 ··-·PCI-DSS-Req-10.5.2
Offset 15848, 16 lines modifiedOffset 15848, 16 lines modified
15848 ····create:·true15848 ····create:·true
15849 ····line:·-e·215849 ····line:·-e·2
15850 ····mode:·o-rwx15850 ····mode:·o-rwx
15851 ··loop:15851 ··loop:
15852 ··-·/etc/audit/audit.rules15852 ··-·/etc/audit/audit.rules
15853 ··-·/etc/audit/rules.d/immutable.rules15853 ··-·/etc/audit/rules.d/immutable.rules
15854 ··when:15854 ··when:
15855 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;] 
15856 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'15855 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'
 15856 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;]
15857 ··tags:15857 ··tags:
15858 ··-·CJIS-5.4.1.115858 ··-·CJIS-5.4.1.1
15859 ··-·NIST-800-171-3.3.115859 ··-·NIST-800-171-3.3.1
15860 ··-·NIST-800-171-3.4.315860 ··-·NIST-800-171-3.4.3
15861 ··-·NIST-800-53-AC-6(9)15861 ··-·NIST-800-53-AC-6(9)
15862 ··-·NIST-800-53-CM-6(a)15862 ··-·NIST-800-53-CM-6(a)
15863 ··-·PCI-DSS-Req-10.5.215863 ··-·PCI-DSS-Req-10.5.2
Offset 16201, 16 lines modifiedOffset 16201, 16 lines modified
16201 ··-·reboot_required16201 ··-·reboot_required
16202 ··-·restrict_strategy16202 ··-·restrict_strategy
  
16203 -·name:·Set·architecture·for·audit·mount·tasks16203 -·name:·Set·architecture·for·audit·mount·tasks
16204 ··set_fact:16204 ··set_fact:
16205 ····audit_arch:·b6416205 ····audit_arch:·b64
16206 ··when:16206 ··when:
16207 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;] 
16208 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'16207 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'
 16208 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;]
16209 ··-·ansible_architecture·==·&quot;aarch64&quot;·or·ansible_architecture·==·&quot;ppc64&quot;·or·ansible_architecture16209 ··-·ansible_architecture·==·&quot;aarch64&quot;·or·ansible_architecture·==·&quot;ppc64&quot;·or·ansible_architecture
16210 ····==·&quot;ppc64le&quot;·or·ansible_architecture·==·&quot;s390x&quot;·or·ansible_architecture·==·&quot;x86_64&quot;16210 ····==·&quot;ppc64le&quot;·or·ansible_architecture·==·&quot;s390x&quot;·or·ansible_architecture·==·&quot;x86_64&quot;
16211 ··tags:16211 ··tags:
16212 ··-·CJIS-5.4.1.116212 ··-·CJIS-5.4.1.1
16213 ··-·NIST-800-171-3.1.716213 ··-·NIST-800-171-3.1.7
16214 ··-·NIST-800-53-AC-6(9)16214 ··-·NIST-800-53-AC-6(9)
16215 ··-·NIST-800-53-AU-12(c)16215 ··-·NIST-800-53-AU-12(c)
Offset 16341, 16 lines modifiedOffset 16341, 16 lines modified
16341 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid&gt;=100016341 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid&gt;=1000
16342 ········-F·auid!=unset·-F·key=perm_mod16342 ········-F·auid!=unset·-F·key=perm_mod
16343 ······create:·true16343 ······create:·true
16344 ······mode:·o-rwx16344 ······mode:·o-rwx
16345 ······state:·present16345 ······state:·present
16346 ····when:·syscalls_found·|·length·==·016346 ····when:·syscalls_found·|·length·==·0
16347 ··when:16347 ··when:
16348 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;] 
16349 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'16348 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'
 16349 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;]
16350 ··tags:16350 ··tags:
16351 ··-·CJIS-5.4.1.116351 ··-·CJIS-5.4.1.1
16352 ··-·NIST-800-171-3.1.716352 ··-·NIST-800-171-3.1.7
16353 ··-·NIST-800-53-AC-6(9)16353 ··-·NIST-800-53-AC-6(9)
16354 ··-·NIST-800-53-AU-12(c)16354 ··-·NIST-800-53-AU-12(c)
16355 ··-·NIST-800-53-AU-2(d)16355 ··-·NIST-800-53-AU-2(d)
16356 ··-·NIST-800-53-CM-6(a)16356 ··-·NIST-800-53-CM-6(a)
Offset 16479, 16 lines modifiedOffset 16479, 16 lines modified
16479 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid&gt;=100016479 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid&gt;=1000
16480 ········-F·auid!=unset·-F·key=perm_mod16480 ········-F·auid!=unset·-F·key=perm_mod
16481 ······create:·true16481 ······create:·true
16482 ······mode:·o-rwx16482 ······mode:·o-rwx
16483 ······state:·present16483 ······state:·present
16484 ····when:·syscalls_found·|·length·==·016484 ····when:·syscalls_found·|·length·==·0
16485 ··when:16485 ··when:
16486 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;] 
16487 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'16486 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'
 16487 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;]
16488 ··-·audit_arch·==·&quot;b64&quot;16488 ··-·audit_arch·==·&quot;b64&quot;
16489 ··tags:16489 ··tags:
16490 ··-·CJIS-5.4.1.116490 ··-·CJIS-5.4.1.1
16491 ··-·NIST-800-171-3.1.716491 ··-·NIST-800-171-3.1.7
16492 ··-·NIST-800-53-AC-6(9)16492 ··-·NIST-800-53-AC-6(9)
16493 ··-·NIST-800-53-AU-12(c)16493 ··-·NIST-800-53-AU-12(c)
16494 ··-·NIST-800-53-AU-2(d)16494 ··-·NIST-800-53-AU-2(d)
Offset 16497, 15 lines modifiedOffset 16497, 15 lines modified
16497 ··-·audit_rules_media_export16497 ··-·audit_rules_media_export
16498 ··-·low_complexity16498 ··-·low_complexity
16499 ··-·low_disruption16499 ··-·low_disruption
Max diff block lines reached; 282396/288134 bytes (98.01%) of diff not shown.
281 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-xccdf.xml
281 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-xccdf.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_22-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_22-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
3 ··<xccdf-1.2:status·date="2024-01-14">draft</xccdf-1.2:status>3 ··<xccdf-1.2:status·date="2025-02-15">draft</xccdf-1.2:status>
4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·22.04</xccdf-1.2:title>4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·22.04</xccdf-1.2:title>
5 ··<xccdf-1.2:description>5 ··<xccdf-1.2:description>
6 ····This·guide·presents·a·catalog·of·security-relevant6 ····This·guide·presents·a·catalog·of·security-relevant
7 configuration·settings·for·Ubuntu·22.04.·It·is·a·rendering·of7 configuration·settings·for·Ubuntu·22.04.·It·is·a·rendering·of
8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
9 in·order·to·support·security·automation.··The·SCAP·content·is9 in·order·to·support·security·automation.··The·SCAP·content·is
10 is·available·in·the10 is·available·in·the
Offset 15694, 16 lines modifiedOffset 15694, 16 lines modified
  
15694 -·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension15694 -·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
15695 ··find:15695 ··find:
15696 ····paths:·/etc/audit/rules.d/15696 ····paths:·/etc/audit/rules.d/
15697 ····patterns:·'*.rules'15697 ····patterns:·'*.rules'
15698 ··register:·find_rules_d15698 ··register:·find_rules_d
15699 ··when:15699 ··when:
15700 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;] 
15701 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'15700 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'
 15701 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;]
15702 ··tags:15702 ··tags:
15703 ··-·CJIS-5.4.1.115703 ··-·CJIS-5.4.1.1
15704 ··-·NIST-800-171-3.3.115704 ··-·NIST-800-171-3.3.1
15705 ··-·NIST-800-171-3.4.315705 ··-·NIST-800-171-3.4.3
15706 ··-·NIST-800-53-AC-6(9)15706 ··-·NIST-800-53-AC-6(9)
15707 ··-·NIST-800-53-CM-6(a)15707 ··-·NIST-800-53-CM-6(a)
15708 ··-·PCI-DSS-Req-10.5.215708 ··-·PCI-DSS-Req-10.5.2
Offset 15718, 16 lines modifiedOffset 15718, 16 lines modified
15718 ··lineinfile:15718 ··lineinfile:
15719 ····path:·'{{·item·}}'15719 ····path:·'{{·item·}}'
15720 ····regexp:·^\s*(?:-e)\s+.*$15720 ····regexp:·^\s*(?:-e)\s+.*$
15721 ····state:·absent15721 ····state:·absent
15722 ··loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']15722 ··loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
15723 ····}}'15723 ····}}'
15724 ··when:15724 ··when:
15725 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;] 
15726 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'15725 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'
 15726 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;]
15727 ··tags:15727 ··tags:
15728 ··-·CJIS-5.4.1.115728 ··-·CJIS-5.4.1.1
15729 ··-·NIST-800-171-3.3.115729 ··-·NIST-800-171-3.3.1
15730 ··-·NIST-800-171-3.4.315730 ··-·NIST-800-171-3.4.3
15731 ··-·NIST-800-53-AC-6(9)15731 ··-·NIST-800-53-AC-6(9)
15732 ··-·NIST-800-53-CM-6(a)15732 ··-·NIST-800-53-CM-6(a)
15733 ··-·PCI-DSS-Req-10.5.215733 ··-·PCI-DSS-Req-10.5.2
Offset 15744, 16 lines modifiedOffset 15744, 16 lines modified
15744 ····create:·true15744 ····create:·true
15745 ····line:·-e·215745 ····line:·-e·2
15746 ····mode:·o-rwx15746 ····mode:·o-rwx
15747 ··loop:15747 ··loop:
15748 ··-·/etc/audit/audit.rules15748 ··-·/etc/audit/audit.rules
15749 ··-·/etc/audit/rules.d/immutable.rules15749 ··-·/etc/audit/rules.d/immutable.rules
15750 ··when:15750 ··when:
15751 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;] 
15752 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'15751 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'
 15752 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;]
15753 ··tags:15753 ··tags:
15754 ··-·CJIS-5.4.1.115754 ··-·CJIS-5.4.1.1
15755 ··-·NIST-800-171-3.3.115755 ··-·NIST-800-171-3.3.1
15756 ··-·NIST-800-171-3.4.315756 ··-·NIST-800-171-3.4.3
15757 ··-·NIST-800-53-AC-6(9)15757 ··-·NIST-800-53-AC-6(9)
15758 ··-·NIST-800-53-CM-6(a)15758 ··-·NIST-800-53-CM-6(a)
15759 ··-·PCI-DSS-Req-10.5.215759 ··-·PCI-DSS-Req-10.5.2
Offset 16097, 16 lines modifiedOffset 16097, 16 lines modified
16097 ··-·reboot_required16097 ··-·reboot_required
16098 ··-·restrict_strategy16098 ··-·restrict_strategy
  
16099 -·name:·Set·architecture·for·audit·mount·tasks16099 -·name:·Set·architecture·for·audit·mount·tasks
16100 ··set_fact:16100 ··set_fact:
16101 ····audit_arch:·b6416101 ····audit_arch:·b64
16102 ··when:16102 ··when:
16103 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;] 
16104 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'16103 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'
 16104 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;]
16105 ··-·ansible_architecture·==·&quot;aarch64&quot;·or·ansible_architecture·==·&quot;ppc64&quot;·or·ansible_architecture16105 ··-·ansible_architecture·==·&quot;aarch64&quot;·or·ansible_architecture·==·&quot;ppc64&quot;·or·ansible_architecture
16106 ····==·&quot;ppc64le&quot;·or·ansible_architecture·==·&quot;s390x&quot;·or·ansible_architecture·==·&quot;x86_64&quot;16106 ····==·&quot;ppc64le&quot;·or·ansible_architecture·==·&quot;s390x&quot;·or·ansible_architecture·==·&quot;x86_64&quot;
16107 ··tags:16107 ··tags:
16108 ··-·CJIS-5.4.1.116108 ··-·CJIS-5.4.1.1
16109 ··-·NIST-800-171-3.1.716109 ··-·NIST-800-171-3.1.7
16110 ··-·NIST-800-53-AC-6(9)16110 ··-·NIST-800-53-AC-6(9)
16111 ··-·NIST-800-53-AU-12(c)16111 ··-·NIST-800-53-AU-12(c)
Offset 16237, 16 lines modifiedOffset 16237, 16 lines modified
16237 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid&gt;=100016237 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid&gt;=1000
16238 ········-F·auid!=unset·-F·key=perm_mod16238 ········-F·auid!=unset·-F·key=perm_mod
16239 ······create:·true16239 ······create:·true
16240 ······mode:·o-rwx16240 ······mode:·o-rwx
16241 ······state:·present16241 ······state:·present
16242 ····when:·syscalls_found·|·length·==·016242 ····when:·syscalls_found·|·length·==·0
16243 ··when:16243 ··when:
16244 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;] 
16245 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'16244 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'
 16245 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;]
16246 ··tags:16246 ··tags:
16247 ··-·CJIS-5.4.1.116247 ··-·CJIS-5.4.1.1
16248 ··-·NIST-800-171-3.1.716248 ··-·NIST-800-171-3.1.7
16249 ··-·NIST-800-53-AC-6(9)16249 ··-·NIST-800-53-AC-6(9)
16250 ··-·NIST-800-53-AU-12(c)16250 ··-·NIST-800-53-AU-12(c)
16251 ··-·NIST-800-53-AU-2(d)16251 ··-·NIST-800-53-AU-2(d)
16252 ··-·NIST-800-53-CM-6(a)16252 ··-·NIST-800-53-CM-6(a)
Offset 16375, 16 lines modifiedOffset 16375, 16 lines modified
16375 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid&gt;=100016375 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid&gt;=1000
16376 ········-F·auid!=unset·-F·key=perm_mod16376 ········-F·auid!=unset·-F·key=perm_mod
16377 ······create:·true16377 ······create:·true
16378 ······mode:·o-rwx16378 ······mode:·o-rwx
16379 ······state:·present16379 ······state:·present
16380 ····when:·syscalls_found·|·length·==·016380 ····when:·syscalls_found·|·length·==·0
16381 ··when:16381 ··when:
16382 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;] 
16383 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'16382 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'
 16383 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;]
16384 ··-·audit_arch·==·&quot;b64&quot;16384 ··-·audit_arch·==·&quot;b64&quot;
16385 ··tags:16385 ··tags:
16386 ··-·CJIS-5.4.1.116386 ··-·CJIS-5.4.1.1
16387 ··-·NIST-800-171-3.1.716387 ··-·NIST-800-171-3.1.7
16388 ··-·NIST-800-53-AC-6(9)16388 ··-·NIST-800-53-AC-6(9)
16389 ··-·NIST-800-53-AU-12(c)16389 ··-·NIST-800-53-AU-12(c)
16390 ··-·NIST-800-53-AU-2(d)16390 ··-·NIST-800-53-AU-2(d)
Offset 16393, 15 lines modifiedOffset 16393, 15 lines modified
16393 ··-·audit_rules_media_export16393 ··-·audit_rules_media_export
16394 ··-·low_complexity16394 ··-·low_complexity
16395 ··-·low_disruption16395 ··-·low_disruption
16396 ··-·medium_severity16396 ··-·medium_severity
16397 ··-·reboot_required16397 ··-·reboot_required
16398 ··-·restrict_strategy</xccdf-1.2:fix>16398 ··-·restrict_strategy</xccdf-1.2:fix>
16399 ··········<xccdf-1.2:fix·system="urn:xccdf:fix:script:sh"·id="audit_rules_media_export">#·Remediation·is·applicable·only·in·certain·platforms16399 ··········<xccdf-1.2:fix·system="urn:xccdf:fix:script:sh"·id="audit_rules_media_export">#·Remediation·is·applicable·only·in·certain·platforms
16400 if·[·!·-f·/.dockerenv·]·&amp;&amp;·[·!·-f·/run/.containerenv·]·&amp;&amp;·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'auditd'·2&gt;/dev/null·|·grep·-q·installed;·then16400 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'auditd'·2&gt;/dev/null·|·grep·-q·installed·&amp;&amp;·[·!·-f·/.dockerenv·]·&amp;&amp;·[·!·-f·/run/.containerenv·];·then
Max diff block lines reached; 281023/287134 bytes (97.87%) of diff not shown.
27.4 KB
ssg-debian_0.1.65-1_all.deb
452 B
file list
    
Offset 1, 3 lines modifiedOffset 1, 3 lines modified
1 -rw-r--r--···0········0········0········4·2022-12-20·09:54:05.000000·debian-binary1 -rw-r--r--···0········0········0········4·2022-12-20·09:54:05.000000·debian-binary
2 -rw-r--r--···0········0········0·····1820·2022-12-20·09:54:05.000000·control.tar.xz2 -rw-r--r--···0········0········0·····1824·2022-12-20·09:54:05.000000·control.tar.xz
3 -rw-r--r--···0········0········0···826668·2022-12-20·09:54:05.000000·data.tar.xz3 -rw-r--r--···0········0········0···826676·2022-12-20·09:54:05.000000·data.tar.xz
98.0 B
control.tar.xz
70.0 B
control.tar
48.0 B
./md5sums
30.0 B
./md5sums
Files differ
26.8 KB
data.tar.xz
26.8 KB
data.tar
1.86 KB
./usr/share/doc/ssg-debian/ssg-debian10-guide-anssi_np_nt28_average.html
    
Offset 14284, 15 lines modifiedOffset 14284, 15 lines modified
00037cb0:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·00037cb0:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·
00037cc0:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong00037cc0:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong
00037cd0:·3e30·2e31·2e36·353c·2f73·7472·6f6e·673e··>0.1.65</strong>00037cd0:·3e30·2e31·2e36·353c·2f73·7472·6f6e·673e··>0.1.65</strong>
00037ce0:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str00037ce0:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str
00037cf0:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron00037cf0:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron
00037d00:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············00037d00:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············
00037d10:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·2000037d10:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·20
00037d20:·3234·2d30·312d·3134·290a·2020·2020·2020··24-01-14).······00037d20:·3235·2d30·322d·3135·290a·2020·2020·2020··25-02-15).······
00037d30:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><00037d30:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><
00037d40:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta00037d40:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta
00037d50:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<00037d50:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<
00037d60:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h00037d60:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h
00037d70:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.00037d70:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.
00037d80:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte00037d80:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte
00037d90:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"00037d90:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"
629 B
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *****·Profile·Information·*****37 *****·Profile·Information·*****
38 Profile·Title·Profile·for·ANSSI·DAT-NT28·Average·(Intermediate)·Level38 Profile·Title·Profile·for·ANSSI·DAT-NT28·Average·(Intermediate)·Level
39 Profile·ID····xccdf_org.ssgproject.content_profile_anssi_np_nt28_average39 Profile·ID····xccdf_org.ssgproject.content_profile_anssi_np_nt28_average
40 ***·CPE·Platforms·***40 ***·CPE·Platforms·***
41 ····*·cpe:/o:debian:debian_linux:1041 ····*·cpe:/o:debian:debian_linux:10
42 *****·Revision·History·*****42 *****·Revision·History·*****
43 Current·version:·0.1.6543 Current·version:·0.1.65
44 ····*·draft·(as·of·2024-01-14)44 ····*·draft·(as·of·2025-02-15)
45 *****·Table·of·Contents·*****45 *****·Table·of·Contents·*****
46 ···1.·System_Settings46 ···1.·System_Settings
47 ·········1.·Installing_and_Maintaining_Software47 ·········1.·Installing_and_Maintaining_Software
48 ·········2.·Configure_Syslog48 ·········2.·Configure_Syslog
49 ·········3.·File_Permissions_and_Masks49 ·········3.·File_Permissions_and_Masks
50 ···2.·Services50 ···2.·Services
51 ·········1.·APT_service_configuration51 ·········1.·APT_service_configuration
1.87 KB
./usr/share/doc/ssg-debian/ssg-debian10-guide-anssi_np_nt28_high.html
    
Offset 14285, 15 lines modifiedOffset 14285, 15 lines modified
00037cc0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu00037cc0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu
00037cd0:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<00037cd0:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<
00037ce0:·7374·726f·6e67·3e30·2e31·2e36·353c·2f73··strong>0.1.65</s00037ce0:·7374·726f·6e67·3e30·2e31·2e36·353c·2f73··strong>0.1.65</s
00037cf0:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l00037cf0:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l
00037d00:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<00037d00:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<
00037d10:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······00037d10:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······
00037d20:·2020·2020·2020·2020·2020·2020·2028·6173···············(as00037d20:·2020·2020·2020·2020·2020·2020·2028·6173···············(as
00037d30:·206f·6620·3230·3234·2d30·312d·3134·290a···of·2024-01-14).00037d30:·206f·6620·3230·3235·2d30·322d·3135·290a···of·2025-02-15).
00037d40:·2020·2020·2020·2020·2020·2020·2020·2020··················00037d40:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037d50:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>00037d50:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>
00037d60:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con00037d60:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con
00037d70:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l00037d70:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l
00037d80:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd00037d80:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd
00037d90:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject00037d90:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject
00037da0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s00037da0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s
651 B
html2text {}
    
Offset 38, 15 lines modifiedOffset 38, 15 lines modified
38 *****·Profile·Information·*****38 *****·Profile·Information·*****
39 Profile·Title·Profile·for·ANSSI·DAT-NT28·High·(Enforced)·Level39 Profile·Title·Profile·for·ANSSI·DAT-NT28·High·(Enforced)·Level
40 Profile·ID····xccdf_org.ssgproject.content_profile_anssi_np_nt28_high40 Profile·ID····xccdf_org.ssgproject.content_profile_anssi_np_nt28_high
41 ***·CPE·Platforms·***41 ***·CPE·Platforms·***
42 ····*·cpe:/o:debian:debian_linux:1042 ····*·cpe:/o:debian:debian_linux:10
43 *****·Revision·History·*****43 *****·Revision·History·*****
44 Current·version:·0.1.6544 Current·version:·0.1.65
45 ····*·draft·(as·of·2024-01-14)45 ····*·draft·(as·of·2025-02-15)
46 *****·Table·of·Contents·*****46 *****·Table·of·Contents·*****
47 ···1.·System_Settings47 ···1.·System_Settings
48 ·········1.·Installing_and_Maintaining_Software48 ·········1.·Installing_and_Maintaining_Software
49 ·········2.·System_Accounting_with_auditd49 ·········2.·System_Accounting_with_auditd
50 ·········3.·GRUB2_bootloader_configuration50 ·········3.·GRUB2_bootloader_configuration
51 ·········4.·Configure_Syslog51 ·········4.·Configure_Syslog
52 ·········5.·File_Permissions_and_Masks52 ·········5.·File_Permissions_and_Masks
1.84 KB
./usr/share/doc/ssg-debian/ssg-debian10-guide-anssi_np_nt28_minimal.html
    
Offset 14278, 15 lines modifiedOffset 14278, 15 lines modified
00037c50:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>00037c50:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>
00037c60:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:00037c60:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:
00037c70:·203c·7374·726f·6e67·3e30·2e31·2e36·353c···<strong>0.1.65<00037c70:·203c·7374·726f·6e67·3e30·2e31·2e36·353c···<strong>0.1.65<
00037c80:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>00037c80:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>
00037c90:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf00037c90:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf
00037ca0:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····00037ca0:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····
00037cb0:·2020·2020·2020·2020·2020·2020·2020·2028·················(00037cb0:·2020·2020·2020·2020·2020·2020·2020·2028·················(
00037cc0:·6173·206f·6620·3230·3234·2d30·312d·3134··as·of·2024-01-1400037cc0:·6173·206f·6620·3230·3235·2d30·322d·3135··as·of·2025-02-15
00037cd0:·290a·2020·2020·2020·2020·2020·2020·2020··).··············00037cd0:·290a·2020·2020·2020·2020·2020·2020·2020··).··············
00037ce0:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di00037ce0:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di
00037cf0:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C00037cf0:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C
00037d00:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>00037d00:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>
00037d10:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc00037d10:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc
00037d20:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje00037d20:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje
00037d30:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group00037d30:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group
614 B
html2text {}
    
Offset 36, 15 lines modifiedOffset 36, 15 lines modified
36 *****·Profile·Information·*****36 *****·Profile·Information·*****
37 Profile·Title·Profile·for·ANSSI·DAT-NT28·Minimal·Level37 Profile·Title·Profile·for·ANSSI·DAT-NT28·Minimal·Level
38 Profile·ID····xccdf_org.ssgproject.content_profile_anssi_np_nt28_minimal38 Profile·ID····xccdf_org.ssgproject.content_profile_anssi_np_nt28_minimal
39 ***·CPE·Platforms·***39 ***·CPE·Platforms·***
40 ····*·cpe:/o:debian:debian_linux:1040 ····*·cpe:/o:debian:debian_linux:10
41 *****·Revision·History·*****41 *****·Revision·History·*****
42 Current·version:·0.1.6542 Current·version:·0.1.65
43 ····*·draft·(as·of·2024-01-14)43 ····*·draft·(as·of·2025-02-15)
44 *****·Table·of·Contents·*****44 *****·Table·of·Contents·*****
45 ···1.·System_Settings45 ···1.·System_Settings
46 ·········1.·Installing_and_Maintaining_Software46 ·········1.·Installing_and_Maintaining_Software
47 ·········2.·Configure_Syslog47 ·········2.·Configure_Syslog
48 ·········3.·File_Permissions_and_Masks48 ·········3.·File_Permissions_and_Masks
49 ···2.·Services49 ···2.·Services
50 ·········1.·APT_service_configuration50 ·········1.·APT_service_configuration
1.86 KB
./usr/share/doc/ssg-debian/ssg-debian10-guide-anssi_np_nt28_restrictive.html
    
Offset 14282, 15 lines modifiedOffset 14282, 15 lines modified
00037c90:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>00037c90:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>
00037ca0:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:00037ca0:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:
00037cb0:·203c·7374·726f·6e67·3e30·2e31·2e36·353c···<strong>0.1.65<00037cb0:·203c·7374·726f·6e67·3e30·2e31·2e36·353c···<strong>0.1.65<
00037cc0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>00037cc0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>
00037cd0:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf00037cd0:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf
00037ce0:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····00037ce0:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····
00037cf0:·2020·2020·2020·2020·2020·2020·2020·2028·················(00037cf0:·2020·2020·2020·2020·2020·2020·2020·2028·················(
00037d00:·6173·206f·6620·3230·3234·2d30·312d·3134··as·of·2024-01-1400037d00:·6173·206f·6620·3230·3235·2d30·322d·3135··as·of·2025-02-15
00037d10:·290a·2020·2020·2020·2020·2020·2020·2020··).··············00037d10:·290a·2020·2020·2020·2020·2020·2020·2020··).··············
00037d20:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di00037d20:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di
00037d30:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C00037d30:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C
00037d40:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>00037d40:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>
00037d50:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc00037d50:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc
00037d60:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje00037d60:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje
00037d70:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group00037d70:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group
626 B
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *****·Profile·Information·*****37 *****·Profile·Information·*****
38 Profile·Title·Profile·for·ANSSI·DAT-NT28·Restrictive·Level38 Profile·Title·Profile·for·ANSSI·DAT-NT28·Restrictive·Level
39 Profile·ID····xccdf_org.ssgproject.content_profile_anssi_np_nt28_restrictive39 Profile·ID····xccdf_org.ssgproject.content_profile_anssi_np_nt28_restrictive
40 ***·CPE·Platforms·***40 ***·CPE·Platforms·***
41 ····*·cpe:/o:debian:debian_linux:1041 ····*·cpe:/o:debian:debian_linux:10
42 *****·Revision·History·*****42 *****·Revision·History·*****
43 Current·version:·0.1.6543 Current·version:·0.1.65
44 ····*·draft·(as·of·2024-01-14)44 ····*·draft·(as·of·2025-02-15)
45 *****·Table·of·Contents·*****45 *****·Table·of·Contents·*****
46 ···1.·System_Settings46 ···1.·System_Settings
47 ·········1.·Installing_and_Maintaining_Software47 ·········1.·Installing_and_Maintaining_Software
48 ·········2.·System_Accounting_with_auditd48 ·········2.·System_Accounting_with_auditd
49 ·········3.·Configure_Syslog49 ·········3.·Configure_Syslog
50 ·········4.·File_Permissions_and_Masks50 ·········4.·File_Permissions_and_Masks
51 ···2.·Services51 ···2.·Services
1.95 KB
./usr/share/doc/ssg-debian/ssg-debian10-guide-standard.html
    
Offset 14284, 16 lines modifiedOffset 14284, 16 lines modified
00037cb0:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>00037cb0:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>
00037cc0:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi00037cc0:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi
00037cd0:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.00037cd0:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.
00037ce0:·3635·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··65</strong></p><00037ce0:·3635·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··65</strong></p><
00037cf0:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d00037cf0:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d
00037d00:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··00037d00:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··
00037d10:·2020·2020·2020·2020·2020·2020·2020·2020··················00037d10:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037d20:·2020·2861·7320·6f66·2032·3032·342d·3031····(as·of·2024-0100037d20:·2020·2861·7320·6f66·2032·3032·352d·3032····(as·of·2025-02
00037d30:·2d31·3429·0a20·2020·2020·2020·2020·2020··-14).···········00037d30:·2d31·3529·0a20·2020·2020·2020·2020·2020··-15).···········
00037d40:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><00037d40:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><
00037d50:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o00037d50:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o
00037d60:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><00037d60:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><
00037d70:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="00037d70:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="
00037d80:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr00037d80:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr
00037d90:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr00037d90:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr
00037da0:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst00037da0:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst
611 B
html2text {}
    
Offset 38, 15 lines modifiedOffset 38, 15 lines modified
38 *****·Profile·Information·*****38 *****·Profile·Information·*****
39 Profile·Title·Standard·System·Security·Profile·for·Debian·1039 Profile·Title·Standard·System·Security·Profile·for·Debian·10
40 Profile·ID····xccdf_org.ssgproject.content_profile_standard40 Profile·ID····xccdf_org.ssgproject.content_profile_standard
41 ***·CPE·Platforms·***41 ***·CPE·Platforms·***
42 ····*·cpe:/o:debian:debian_linux:1042 ····*·cpe:/o:debian:debian_linux:10
43 *****·Revision·History·*****43 *****·Revision·History·*****
44 Current·version:·0.1.6544 Current·version:·0.1.65
45 ····*·draft·(as·of·2024-01-14)45 ····*·draft·(as·of·2025-02-15)
46 *****·Table·of·Contents·*****46 *****·Table·of·Contents·*****
47 ···1.·System_Settings47 ···1.·System_Settings
48 ·········1.·Installing_and_Maintaining_Software48 ·········1.·Installing_and_Maintaining_Software
49 ·········2.·System_Accounting_with_auditd49 ·········2.·System_Accounting_with_auditd
50 ·········3.·Configure_Syslog50 ·········3.·Configure_Syslog
51 ·········4.·File_Permissions_and_Masks51 ·········4.·File_Permissions_and_Masks
52 ···2.·Services52 ···2.·Services
1.86 KB
./usr/share/doc/ssg-debian/ssg-debian11-guide-anssi_np_nt28_average.html
    
Offset 14284, 15 lines modifiedOffset 14284, 15 lines modified
00037cb0:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·00037cb0:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·
00037cc0:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong00037cc0:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong
00037cd0:·3e30·2e31·2e36·353c·2f73·7472·6f6e·673e··>0.1.65</strong>00037cd0:·3e30·2e31·2e36·353c·2f73·7472·6f6e·673e··>0.1.65</strong>
00037ce0:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str00037ce0:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str
00037cf0:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron00037cf0:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron
00037d00:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············00037d00:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············
00037d10:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·2000037d10:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·20
00037d20:·3234·2d30·312d·3134·290a·2020·2020·2020··24-01-14).······00037d20:·3235·2d30·322d·3135·290a·2020·2020·2020··25-02-15).······
00037d30:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><00037d30:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><
00037d40:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta00037d40:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta
00037d50:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<00037d50:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<
00037d60:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h00037d60:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h
00037d70:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.00037d70:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.
00037d80:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte00037d80:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte
00037d90:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"00037d90:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"
629 B
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *****·Profile·Information·*****37 *****·Profile·Information·*****
38 Profile·Title·Profile·for·ANSSI·DAT-NT28·Average·(Intermediate)·Level38 Profile·Title·Profile·for·ANSSI·DAT-NT28·Average·(Intermediate)·Level
39 Profile·ID····xccdf_org.ssgproject.content_profile_anssi_np_nt28_average39 Profile·ID····xccdf_org.ssgproject.content_profile_anssi_np_nt28_average
40 ***·CPE·Platforms·***40 ***·CPE·Platforms·***
41 ····*·cpe:/o:debian:debian_linux:1141 ····*·cpe:/o:debian:debian_linux:11
42 *****·Revision·History·*****42 *****·Revision·History·*****
43 Current·version:·0.1.6543 Current·version:·0.1.65
44 ····*·draft·(as·of·2024-01-14)44 ····*·draft·(as·of·2025-02-15)
45 *****·Table·of·Contents·*****45 *****·Table·of·Contents·*****
46 ···1.·System_Settings46 ···1.·System_Settings
47 ·········1.·Installing_and_Maintaining_Software47 ·········1.·Installing_and_Maintaining_Software
48 ·········2.·Configure_Syslog48 ·········2.·Configure_Syslog
49 ·········3.·File_Permissions_and_Masks49 ·········3.·File_Permissions_and_Masks
50 ···2.·Services50 ···2.·Services
51 ·········1.·APT_service_configuration51 ·········1.·APT_service_configuration
1.87 KB
./usr/share/doc/ssg-debian/ssg-debian11-guide-anssi_np_nt28_high.html
    
Offset 14285, 15 lines modifiedOffset 14285, 15 lines modified
00037cc0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu00037cc0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu
00037cd0:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<00037cd0:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<
00037ce0:·7374·726f·6e67·3e30·2e31·2e36·353c·2f73··strong>0.1.65</s00037ce0:·7374·726f·6e67·3e30·2e31·2e36·353c·2f73··strong>0.1.65</s
00037cf0:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l00037cf0:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l
00037d00:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<00037d00:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<
00037d10:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······00037d10:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······
00037d20:·2020·2020·2020·2020·2020·2020·2028·6173···············(as00037d20:·2020·2020·2020·2020·2020·2020·2028·6173···············(as
00037d30:·206f·6620·3230·3234·2d30·312d·3134·290a···of·2024-01-14).00037d30:·206f·6620·3230·3235·2d30·322d·3135·290a···of·2025-02-15).
00037d40:·2020·2020·2020·2020·2020·2020·2020·2020··················00037d40:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037d50:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>00037d50:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>
00037d60:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con00037d60:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con
00037d70:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l00037d70:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l
00037d80:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd00037d80:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd
00037d90:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject00037d90:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject
00037da0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s00037da0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s
651 B
html2text {}
    
Offset 38, 15 lines modifiedOffset 38, 15 lines modified
38 *****·Profile·Information·*****38 *****·Profile·Information·*****
39 Profile·Title·Profile·for·ANSSI·DAT-NT28·High·(Enforced)·Level39 Profile·Title·Profile·for·ANSSI·DAT-NT28·High·(Enforced)·Level
40 Profile·ID····xccdf_org.ssgproject.content_profile_anssi_np_nt28_high40 Profile·ID····xccdf_org.ssgproject.content_profile_anssi_np_nt28_high
41 ***·CPE·Platforms·***41 ***·CPE·Platforms·***
42 ····*·cpe:/o:debian:debian_linux:1142 ····*·cpe:/o:debian:debian_linux:11
43 *****·Revision·History·*****43 *****·Revision·History·*****
44 Current·version:·0.1.6544 Current·version:·0.1.65
45 ····*·draft·(as·of·2024-01-14)45 ····*·draft·(as·of·2025-02-15)
46 *****·Table·of·Contents·*****46 *****·Table·of·Contents·*****
47 ···1.·System_Settings47 ···1.·System_Settings
48 ·········1.·Installing_and_Maintaining_Software48 ·········1.·Installing_and_Maintaining_Software
49 ·········2.·System_Accounting_with_auditd49 ·········2.·System_Accounting_with_auditd
50 ·········3.·GRUB2_bootloader_configuration50 ·········3.·GRUB2_bootloader_configuration
51 ·········4.·Configure_Syslog51 ·········4.·Configure_Syslog
52 ·········5.·File_Permissions_and_Masks52 ·········5.·File_Permissions_and_Masks
1.84 KB
./usr/share/doc/ssg-debian/ssg-debian11-guide-anssi_np_nt28_minimal.html
    
Offset 14278, 15 lines modifiedOffset 14278, 15 lines modified
00037c50:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>00037c50:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>
00037c60:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:00037c60:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:
00037c70:·203c·7374·726f·6e67·3e30·2e31·2e36·353c···<strong>0.1.65<00037c70:·203c·7374·726f·6e67·3e30·2e31·2e36·353c···<strong>0.1.65<
00037c80:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>00037c80:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>
00037c90:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf00037c90:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf
00037ca0:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····00037ca0:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····
00037cb0:·2020·2020·2020·2020·2020·2020·2020·2028·················(00037cb0:·2020·2020·2020·2020·2020·2020·2020·2028·················(
00037cc0:·6173·206f·6620·3230·3234·2d30·312d·3134··as·of·2024-01-1400037cc0:·6173·206f·6620·3230·3235·2d30·322d·3135··as·of·2025-02-15
00037cd0:·290a·2020·2020·2020·2020·2020·2020·2020··).··············00037cd0:·290a·2020·2020·2020·2020·2020·2020·2020··).··············
00037ce0:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di00037ce0:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di
00037cf0:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C00037cf0:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C
00037d00:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>00037d00:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>
00037d10:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc00037d10:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc
00037d20:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje00037d20:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje
00037d30:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group00037d30:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group
614 B
html2text {}
    
Offset 36, 15 lines modifiedOffset 36, 15 lines modified
36 *****·Profile·Information·*****36 *****·Profile·Information·*****
37 Profile·Title·Profile·for·ANSSI·DAT-NT28·Minimal·Level37 Profile·Title·Profile·for·ANSSI·DAT-NT28·Minimal·Level
38 Profile·ID····xccdf_org.ssgproject.content_profile_anssi_np_nt28_minimal38 Profile·ID····xccdf_org.ssgproject.content_profile_anssi_np_nt28_minimal
39 ***·CPE·Platforms·***39 ***·CPE·Platforms·***
40 ····*·cpe:/o:debian:debian_linux:1140 ····*·cpe:/o:debian:debian_linux:11
41 *****·Revision·History·*****41 *****·Revision·History·*****
42 Current·version:·0.1.6542 Current·version:·0.1.65
43 ····*·draft·(as·of·2024-01-14)43 ····*·draft·(as·of·2025-02-15)
44 *****·Table·of·Contents·*****44 *****·Table·of·Contents·*****
45 ···1.·System_Settings45 ···1.·System_Settings
46 ·········1.·Installing_and_Maintaining_Software46 ·········1.·Installing_and_Maintaining_Software
47 ·········2.·Configure_Syslog47 ·········2.·Configure_Syslog
48 ·········3.·File_Permissions_and_Masks48 ·········3.·File_Permissions_and_Masks
49 ···2.·Services49 ···2.·Services
50 ·········1.·APT_service_configuration50 ·········1.·APT_service_configuration
1.86 KB
./usr/share/doc/ssg-debian/ssg-debian11-guide-anssi_np_nt28_restrictive.html
    
Offset 14282, 15 lines modifiedOffset 14282, 15 lines modified
00037c90:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>00037c90:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>
00037ca0:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:00037ca0:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:
00037cb0:·203c·7374·726f·6e67·3e30·2e31·2e36·353c···<strong>0.1.65<00037cb0:·203c·7374·726f·6e67·3e30·2e31·2e36·353c···<strong>0.1.65<
00037cc0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>00037cc0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>
00037cd0:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf00037cd0:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf
00037ce0:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····00037ce0:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····
00037cf0:·2020·2020·2020·2020·2020·2020·2020·2028·················(00037cf0:·2020·2020·2020·2020·2020·2020·2020·2028·················(
00037d00:·6173·206f·6620·3230·3234·2d30·312d·3134··as·of·2024-01-1400037d00:·6173·206f·6620·3230·3235·2d30·322d·3135··as·of·2025-02-15
00037d10:·290a·2020·2020·2020·2020·2020·2020·2020··).··············00037d10:·290a·2020·2020·2020·2020·2020·2020·2020··).··············
00037d20:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di00037d20:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di
00037d30:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C00037d30:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C
00037d40:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>00037d40:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>
00037d50:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc00037d50:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc
00037d60:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje00037d60:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje
00037d70:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group00037d70:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group
626 B
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *****·Profile·Information·*****37 *****·Profile·Information·*****
38 Profile·Title·Profile·for·ANSSI·DAT-NT28·Restrictive·Level38 Profile·Title·Profile·for·ANSSI·DAT-NT28·Restrictive·Level
39 Profile·ID····xccdf_org.ssgproject.content_profile_anssi_np_nt28_restrictive39 Profile·ID····xccdf_org.ssgproject.content_profile_anssi_np_nt28_restrictive
40 ***·CPE·Platforms·***40 ***·CPE·Platforms·***
41 ····*·cpe:/o:debian:debian_linux:1141 ····*·cpe:/o:debian:debian_linux:11
42 *****·Revision·History·*****42 *****·Revision·History·*****
43 Current·version:·0.1.6543 Current·version:·0.1.65
44 ····*·draft·(as·of·2024-01-14)44 ····*·draft·(as·of·2025-02-15)
45 *****·Table·of·Contents·*****45 *****·Table·of·Contents·*****
46 ···1.·System_Settings46 ···1.·System_Settings
47 ·········1.·Installing_and_Maintaining_Software47 ·········1.·Installing_and_Maintaining_Software
48 ·········2.·System_Accounting_with_auditd48 ·········2.·System_Accounting_with_auditd
49 ·········3.·Configure_Syslog49 ·········3.·Configure_Syslog
50 ·········4.·File_Permissions_and_Masks50 ·········4.·File_Permissions_and_Masks
51 ···2.·Services51 ···2.·Services
1.95 KB
./usr/share/doc/ssg-debian/ssg-debian11-guide-standard.html
    
Offset 14284, 16 lines modifiedOffset 14284, 16 lines modified
00037cb0:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>00037cb0:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>
00037cc0:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi00037cc0:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi
00037cd0:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.00037cd0:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.
00037ce0:·3635·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··65</strong></p><00037ce0:·3635·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··65</strong></p><
00037cf0:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d00037cf0:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d
00037d00:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··00037d00:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··
00037d10:·2020·2020·2020·2020·2020·2020·2020·2020··················00037d10:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037d20:·2020·2861·7320·6f66·2032·3032·342d·3031····(as·of·2024-0100037d20:·2020·2861·7320·6f66·2032·3032·352d·3032····(as·of·2025-02
00037d30:·2d31·3429·0a20·2020·2020·2020·2020·2020··-14).···········00037d30:·2d31·3529·0a20·2020·2020·2020·2020·2020··-15).···········
00037d40:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><00037d40:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><
00037d50:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o00037d50:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o
00037d60:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><00037d60:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><
00037d70:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="00037d70:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="
00037d80:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr00037d80:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr
00037d90:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr00037d90:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr
00037da0:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst00037da0:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst
611 B
html2text {}
    
Offset 38, 15 lines modifiedOffset 38, 15 lines modified
38 *****·Profile·Information·*****38 *****·Profile·Information·*****
39 Profile·Title·Standard·System·Security·Profile·for·Debian·1139 Profile·Title·Standard·System·Security·Profile·for·Debian·11
40 Profile·ID····xccdf_org.ssgproject.content_profile_standard40 Profile·ID····xccdf_org.ssgproject.content_profile_standard
41 ***·CPE·Platforms·***41 ***·CPE·Platforms·***
42 ····*·cpe:/o:debian:debian_linux:1142 ····*·cpe:/o:debian:debian_linux:11
43 *****·Revision·History·*****43 *****·Revision·History·*****
44 Current·version:·0.1.6544 Current·version:·0.1.65
45 ····*·draft·(as·of·2024-01-14)45 ····*·draft·(as·of·2025-02-15)
46 *****·Table·of·Contents·*****46 *****·Table·of·Contents·*****
47 ···1.·System_Settings47 ···1.·System_Settings
48 ·········1.·Installing_and_Maintaining_Software48 ·········1.·Installing_and_Maintaining_Software
49 ·········2.·System_Accounting_with_auditd49 ·········2.·System_Accounting_with_auditd
50 ·········3.·Configure_Syslog50 ·········3.·Configure_Syslog
51 ·········4.·File_Permissions_and_Masks51 ·········4.·File_Permissions_and_Masks
52 ···2.·Services52 ···2.·Services
1.39 KB
./usr/share/xml/scap/ssg/content/ssg-debian10-ds-1.2.xml
1.28 KB
./usr/share/xml/scap/ssg/content/ssg-debian10-ds-1.2.xml
    
Offset 96, 15 lines modifiedOffset 96, 15 lines modified
96 ········<cpe-dict:title·xml:lang="en-us">Debian·Linux·10</cpe-dict:title>96 ········<cpe-dict:title·xml:lang="en-us">Debian·Linux·10</cpe-dict:title>
97 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian10-cpe-oval.xml">oval:ssg-installed_OS_is_debian10:def:1</cpe-dict:check>97 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian10-cpe-oval.xml">oval:ssg-installed_OS_is_debian10:def:1</cpe-dict:check>
98 ······</cpe-dict:cpe-item>98 ······</cpe-dict:cpe-item>
99 ····</cpe-dict:cpe-list>99 ····</cpe-dict:cpe-list>
100 ··</ds:component>100 ··</ds:component>
101 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian10-xccdf.xml"·timestamp="2022-12-20T09:54:05">101 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian10-xccdf.xml"·timestamp="2022-12-20T09:54:05">
102 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_DEBIAN-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">102 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_DEBIAN-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
103 ······<xccdf-1.2:status·date="2024-01-14">draft</xccdf-1.2:status>103 ······<xccdf-1.2:status·date="2025-02-15">draft</xccdf-1.2:status>
104 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Debian·10</xccdf-1.2:title>104 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Debian·10</xccdf-1.2:title>
105 ······<xccdf-1.2:description>105 ······<xccdf-1.2:description>
106 ········This·guide·presents·a·catalog·of·security-relevant106 ········This·guide·presents·a·catalog·of·security-relevant
107 configuration·settings·for·Debian·10.·It·is·a·rendering·of107 configuration·settings·for·Debian·10.·It·is·a·rendering·of
108 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)108 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
109 in·order·to·support·security·automation.··The·SCAP·content·is109 in·order·to·support·security·automation.··The·SCAP·content·is
110 is·available·in·the110 is·available·in·the
1.37 KB
./usr/share/xml/scap/ssg/content/ssg-debian10-ds.xml
1.27 KB
./usr/share/xml/scap/ssg/content/ssg-debian10-ds.xml
    
Offset 96, 15 lines modifiedOffset 96, 15 lines modified
96 ········<cpe-dict:title·xml:lang="en-us">Debian·Linux·10</cpe-dict:title>96 ········<cpe-dict:title·xml:lang="en-us">Debian·Linux·10</cpe-dict:title>
97 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian10-cpe-oval.xml">oval:ssg-installed_OS_is_debian10:def:1</cpe-dict:check>97 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian10-cpe-oval.xml">oval:ssg-installed_OS_is_debian10:def:1</cpe-dict:check>
98 ······</cpe-dict:cpe-item>98 ······</cpe-dict:cpe-item>
99 ····</cpe-dict:cpe-list>99 ····</cpe-dict:cpe-list>
100 ··</ds:component>100 ··</ds:component>
101 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian10-xccdf.xml"·timestamp="2022-12-20T09:54:05">101 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian10-xccdf.xml"·timestamp="2022-12-20T09:54:05">
102 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_DEBIAN-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">102 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_DEBIAN-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
103 ······<xccdf-1.2:status·date="2024-01-14">draft</xccdf-1.2:status>103 ······<xccdf-1.2:status·date="2025-02-15">draft</xccdf-1.2:status>
104 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Debian·10</xccdf-1.2:title>104 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Debian·10</xccdf-1.2:title>
105 ······<xccdf-1.2:description>105 ······<xccdf-1.2:description>
106 ········This·guide·presents·a·catalog·of·security-relevant106 ········This·guide·presents·a·catalog·of·security-relevant
107 configuration·settings·for·Debian·10.·It·is·a·rendering·of107 configuration·settings·for·Debian·10.·It·is·a·rendering·of
108 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)108 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
109 in·order·to·support·security·automation.··The·SCAP·content·is109 in·order·to·support·security·automation.··The·SCAP·content·is
110 is·available·in·the110 is·available·in·the
1.22 KB
./usr/share/xml/scap/ssg/content/ssg-debian10-xccdf.xml
1.12 KB
./usr/share/xml/scap/ssg/content/ssg-debian10-xccdf.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_DEBIAN-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_DEBIAN-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
3 ··<xccdf-1.2:status·date="2024-01-14">draft</xccdf-1.2:status>3 ··<xccdf-1.2:status·date="2025-02-15">draft</xccdf-1.2:status>
4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Debian·10</xccdf-1.2:title>4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Debian·10</xccdf-1.2:title>
5 ··<xccdf-1.2:description>5 ··<xccdf-1.2:description>
6 ····This·guide·presents·a·catalog·of·security-relevant6 ····This·guide·presents·a·catalog·of·security-relevant
7 configuration·settings·for·Debian·10.·It·is·a·rendering·of7 configuration·settings·for·Debian·10.·It·is·a·rendering·of
8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
9 in·order·to·support·security·automation.··The·SCAP·content·is9 in·order·to·support·security·automation.··The·SCAP·content·is
10 is·available·in·the10 is·available·in·the
1.39 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-ds-1.2.xml
1.28 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-ds-1.2.xml
    
Offset 96, 15 lines modifiedOffset 96, 15 lines modified
96 ········<cpe-dict:title·xml:lang="en-us">Debian·Linux·11</cpe-dict:title>96 ········<cpe-dict:title·xml:lang="en-us">Debian·Linux·11</cpe-dict:title>
97 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml">oval:ssg-installed_OS_is_debian11:def:1</cpe-dict:check>97 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml">oval:ssg-installed_OS_is_debian11:def:1</cpe-dict:check>
98 ······</cpe-dict:cpe-item>98 ······</cpe-dict:cpe-item>
99 ····</cpe-dict:cpe-list>99 ····</cpe-dict:cpe-list>
100 ··</ds:component>100 ··</ds:component>
101 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-xccdf.xml"·timestamp="2022-12-20T09:54:05">101 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-xccdf.xml"·timestamp="2022-12-20T09:54:05">
102 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_DEBIAN-11"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">102 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_DEBIAN-11"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
103 ······<xccdf-1.2:status·date="2024-01-14">draft</xccdf-1.2:status>103 ······<xccdf-1.2:status·date="2025-02-15">draft</xccdf-1.2:status>
104 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Debian·11</xccdf-1.2:title>104 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Debian·11</xccdf-1.2:title>
105 ······<xccdf-1.2:description>105 ······<xccdf-1.2:description>
106 ········This·guide·presents·a·catalog·of·security-relevant106 ········This·guide·presents·a·catalog·of·security-relevant
107 configuration·settings·for·Debian·11.·It·is·a·rendering·of107 configuration·settings·for·Debian·11.·It·is·a·rendering·of
108 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)108 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
109 in·order·to·support·security·automation.··The·SCAP·content·is109 in·order·to·support·security·automation.··The·SCAP·content·is
110 is·available·in·the110 is·available·in·the
1.37 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-ds.xml
1.27 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-ds.xml
    
Offset 96, 15 lines modifiedOffset 96, 15 lines modified
96 ········<cpe-dict:title·xml:lang="en-us">Debian·Linux·11</cpe-dict:title>96 ········<cpe-dict:title·xml:lang="en-us">Debian·Linux·11</cpe-dict:title>
97 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml">oval:ssg-installed_OS_is_debian11:def:1</cpe-dict:check>97 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml">oval:ssg-installed_OS_is_debian11:def:1</cpe-dict:check>
98 ······</cpe-dict:cpe-item>98 ······</cpe-dict:cpe-item>
99 ····</cpe-dict:cpe-list>99 ····</cpe-dict:cpe-list>
100 ··</ds:component>100 ··</ds:component>
101 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-xccdf.xml"·timestamp="2022-12-20T09:54:05">101 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-xccdf.xml"·timestamp="2022-12-20T09:54:05">
102 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_DEBIAN-11"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">102 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_DEBIAN-11"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
103 ······<xccdf-1.2:status·date="2024-01-14">draft</xccdf-1.2:status>103 ······<xccdf-1.2:status·date="2025-02-15">draft</xccdf-1.2:status>
104 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Debian·11</xccdf-1.2:title>104 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Debian·11</xccdf-1.2:title>
105 ······<xccdf-1.2:description>105 ······<xccdf-1.2:description>
106 ········This·guide·presents·a·catalog·of·security-relevant106 ········This·guide·presents·a·catalog·of·security-relevant
107 configuration·settings·for·Debian·11.·It·is·a·rendering·of107 configuration·settings·for·Debian·11.·It·is·a·rendering·of
108 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)108 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
109 in·order·to·support·security·automation.··The·SCAP·content·is109 in·order·to·support·security·automation.··The·SCAP·content·is
110 is·available·in·the110 is·available·in·the
1.22 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-xccdf.xml
1.12 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-xccdf.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_DEBIAN-11"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_DEBIAN-11"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.4.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
3 ··<xccdf-1.2:status·date="2024-01-14">draft</xccdf-1.2:status>3 ··<xccdf-1.2:status·date="2025-02-15">draft</xccdf-1.2:status>
4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Debian·11</xccdf-1.2:title>4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Debian·11</xccdf-1.2:title>
5 ··<xccdf-1.2:description>5 ··<xccdf-1.2:description>
6 ····This·guide·presents·a·catalog·of·security-relevant6 ····This·guide·presents·a·catalog·of·security-relevant
7 configuration·settings·for·Debian·11.·It·is·a·rendering·of7 configuration·settings·for·Debian·11.·It·is·a·rendering·of
8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
9 in·order·to·support·security·automation.··The·SCAP·content·is9 in·order·to·support·security·automation.··The·SCAP·content·is
10 is·available·in·the10 is·available·in·the
50.2 MB
ssg-nondebian_0.1.65-1_all.deb
367 B
file list
    
Offset 1, 3 lines modifiedOffset 1, 3 lines modified
1 -rw-r--r--···0········0········0········4·2022-12-20·09:54:05.000000·debian-binary1 -rw-r--r--···0········0········0········4·2022-12-20·09:54:05.000000·debian-binary
2 -rw-r--r--···0········0········0····15428·2022-12-20·09:54:05.000000·control.tar.xz2 -rw-r--r--···0········0········0····15428·2022-12-20·09:54:05.000000·control.tar.xz
3 -rw-r--r--···0········0········0·40201988·2022-12-20·09:54:05.000000·data.tar.xz3 -rw-r--r--···0········0········0·40202904·2022-12-20·09:54:05.000000·data.tar.xz
98.0 B
control.tar.xz
70.0 B
control.tar
48.0 B
./md5sums
30.0 B
./md5sums
Files differ
50.2 MB
data.tar.xz
50.2 MB
data.tar
24.1 KB
./usr/share/doc/ssg-nondebian/ssg-alinux2-guide-cis.html
    
Offset 14293, 16 lines modifiedOffset 14293, 16 lines modified
00037d40:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p00037d40:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p
00037d50:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version00037d50:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version
00037d60:·3a20·3c73·7472·6f6e·673e·302e·312e·3635··:·<strong>0.1.6500037d60:·3a20·3c73·7472·6f6e·673e·302e·312e·3635··:·<strong>0.1.65
00037d70:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul00037d70:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul
00037d80:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra00037d80:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra
00037d90:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····00037d90:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····
00037da0:·2020·2020·2020·2020·2020·2020·2020·2020··················00037da0:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037db0:·2861·7320·6f66·2032·3032·342d·3031·2d31··(as·of·2024-01-100037db0:·2861·7320·6f66·2032·3032·352d·3032·2d31··(as·of·2025-02-1
00037dc0:·3429·0a20·2020·2020·2020·2020·2020·2020··4).·············00037dc0:·3529·0a20·2020·2020·2020·2020·2020·2020··5).·············
00037dd0:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d00037dd0:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d
00037de0:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·00037de0:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·
00037df0:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol00037df0:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol
00037e00:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x00037e00:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x
00037e10:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj00037e10:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj
00037e20:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou00037e20:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou
00037e30:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System00037e30:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System
Offset 83079, 22 lines modifiedOffset 83079, 22 lines modified
00144860:·2054·6573·7420·666f·7220·6578·6973·7465···Test·for·existe00144860:·2054·6573·7420·666f·7220·6578·6973·7465···Test·for·existe
00144870:·6e63·6520·2f62·6f6f·742f·6772·7562·322f··nce·/boot/grub2/00144870:·6e63·6520·2f62·6f6f·742f·6772·7562·322f··nce·/boot/grub2/
00144880:·6772·7562·2e63·6667·0a20·2073·7461·743a··grub.cfg.··stat:00144880:·6772·7562·2e63·6667·0a20·2073·7461·743a··grub.cfg.··stat:
00144890:·0a20·2020·2070·6174·683a·202f·626f·6f74··.····path:·/boot00144890:·0a20·2020·2070·6174·683a·202f·626f·6f74··.····path:·/boot
001448a0:·2f67·7275·6232·2f67·7275·622e·6366·670a··/grub2/grub.cfg.001448a0:·2f67·7275·6232·2f67·7275·622e·6366·670a··/grub2/grub.cfg.
001448b0:·2020·7265·6769·7374·6572·3a20·6669·6c65····register:·file001448b0:·2020·7265·6769·7374·6572·3a20·6669·6c65····register:·file
001448c0:·5f65·7869·7374·730a·2020·7768·656e·3a0a··_exists.··when:.001448c0:·5f65·7869·7374·730a·2020·7768·656e·3a0a··_exists.··when:.
001448d0:·2020·2d20·2722·6772·7562·322d·636f·6d6d····-·'"grub2-comm 
001448e0:·6f6e·2220·696e·2061·6e73·6962·6c65·5f66··on"·in·ansible_f 
001448f0:·6163·7473·2e70·6163·6b61·6765·7327·0a20··acts.packages'.· 
00144900:·202d·2027·222f·626f·6f74·2f65·6669·2220···-·'"/boot/efi"· 
00144910:·6e6f·7420·696e·2061·6e73·6962·6c65·5f6d··not·in·ansible_m 
00144920:·6f75·6e74·7320·7c20·6d61·7028·6174·7472··ounts·|·map(attr 
00144930:·6962·7574·653d·226d·6f75·6e74·2229·207c··ibute="mount")·|001448d0:·2020·2d20·2722·2f62·6f6f·742f·6566·6922····-·'"/boot/efi"
 001448e0:·206e·6f74·2069·6e20·616e·7369·626c·655f···not·in·ansible_
 001448f0:·6d6f·756e·7473·207c·206d·6170·2861·7474··mounts·|·map(att
 00144900:·7269·6275·7465·3d22·6d6f·756e·7422·2920··ribute="mount")·
 00144910:·7c20·6c69·7374·270a·2020·2d20·2722·6772··|·list'.··-·'"gr
 00144920:·7562·322d·636f·6d6d·6f6e·2220·696e·2061··ub2-common"·in·a
 00144930:·6e73·6962·6c65·5f66·6163·7473·2e70·6163··nsible_facts.pac
00144940:·206c·6973·7427·0a20·202d·2061·6e73·6962···list'.··-·ansib00144940:·6b61·6765·7327·0a20·202d·2061·6e73·6962··kages'.··-·ansib
00144950:·6c65·5f76·6972·7475·616c·697a·6174·696f··le_virtualizatio00144950:·6c65·5f76·6972·7475·616c·697a·6174·696f··le_virtualizatio
00144960:·6e5f·7479·7065·206e·6f74·2069·6e20·5b22··n_type·not·in·["00144960:·6e5f·7479·7065·206e·6f74·2069·6e20·5b22··n_type·not·in·["
00144970:·646f·636b·6572·222c·2022·6c78·6322·2c20··docker",·"lxc",·00144970:·646f·636b·6572·222c·2022·6c78·6322·2c20··docker",·"lxc",·
00144980:·226f·7065·6e76·7a22·2c20·2270·6f64·6d61··"openvz",·"podma00144980:·226f·7065·6e76·7a22·2c20·2270·6f64·6d61··"openvz",·"podma
00144990:·6e22·2c20·2263·6f6e·7461·696e·6572·225d··n",·"container"]00144990:·6e22·2c20·2263·6f6e·7461·696e·6572·225d··n",·"container"]
001449a0:·0a20·2074·6167·733a·0a20·202d·2043·4a49··.··tags:.··-·CJI001449a0:·0a20·2074·6167·733a·0a20·202d·2043·4a49··.··tags:.··-·CJI
001449b0:·532d·352e·352e·322e·320a·2020·2d20·4e49··S-5.5.2.2.··-·NI001449b0:·532d·352e·352e·322e·320a·2020·2d20·4e49··S-5.5.2.2.··-·NI
Offset 83115, 22 lines modifiedOffset 83115, 22 lines modified
00144aa0:·3a20·456e·7375·7265·2067·726f·7570·206f··:·Ensure·group·o00144aa0:·3a20·456e·7375·7265·2067·726f·7570·206f··:·Ensure·group·o
00144ab0:·776e·6572·2030·206f·6e20·2f62·6f6f·742f··wner·0·on·/boot/00144ab0:·776e·6572·2030·206f·6e20·2f62·6f6f·742f··wner·0·on·/boot/
00144ac0:·6772·7562·322f·6772·7562·2e63·6667·0a20··grub2/grub.cfg.·00144ac0:·6772·7562·322f·6772·7562·2e63·6667·0a20··grub2/grub.cfg.·
00144ad0:·2066·696c·653a·0a20·2020·2070·6174·683a···file:.····path:00144ad0:·2066·696c·653a·0a20·2020·2070·6174·683a···file:.····path:
00144ae0:·202f·626f·6f74·2f67·7275·6232·2f67·7275···/boot/grub2/gru00144ae0:·202f·626f·6f74·2f67·7275·6232·2f67·7275···/boot/grub2/gru
00144af0:·622e·6366·670a·2020·2020·6772·6f75·703a··b.cfg.····group:00144af0:·622e·6366·670a·2020·2020·6772·6f75·703a··b.cfg.····group:
00144b00:·2027·3027·0a20·2077·6865·6e3a·0a20·202d···'0'.··when:.··-00144b00:·2027·3027·0a20·2077·6865·6e3a·0a20·202d···'0'.··when:.··-
 00144b10:·2027·222f·626f·6f74·2f65·6669·2220·6e6f···'"/boot/efi"·no
 00144b20:·7420·696e·2061·6e73·6962·6c65·5f6d·6f75··t·in·ansible_mou
 00144b30:·6e74·7320·7c20·6d61·7028·6174·7472·6962··nts·|·map(attrib
00144b10:·2027·2267·7275·6232·2d63·6f6d·6d6f·6e22···'"grub2-common" 
00144b20:·2069·6e20·616e·7369·626c·655f·6661·6374···in·ansible_fact 
00144b30:·732e·7061·636b·6167·6573·270a·2020·2d20··s.packages'.··-· 
00144b40:·2722·2f62·6f6f·742f·6566·6922·206e·6f74··'"/boot/efi"·not 
00144b50:·2069·6e20·616e·7369·626c·655f·6d6f·756e···in·ansible_moun 
00144b60:·7473·207c·206d·6170·2861·7474·7269·6275··ts·|·map(attribu 
00144b70:·7465·3d22·6d6f·756e·7422·2920·7c20·6c69··te="mount")·|·li00144b40:·7574·653d·226d·6f75·6e74·2229·207c·206c··ute="mount")·|·l
 00144b50:·6973·7427·0a20·202d·2027·2267·7275·6232··ist'.··-·'"grub2
 00144b60:·2d63·6f6d·6d6f·6e22·2069·6e20·616e·7369··-common"·in·ansi
 00144b70:·626c·655f·6661·6374·732e·7061·636b·6167··ble_facts.packag
00144b80:·7374·270a·2020·2d20·616e·7369·626c·655f··st'.··-·ansible_00144b80:·6573·270a·2020·2d20·616e·7369·626c·655f··es'.··-·ansible_
00144b90:·7669·7274·7561·6c69·7a61·7469·6f6e·5f74··virtualization_t00144b90:·7669·7274·7561·6c69·7a61·7469·6f6e·5f74··virtualization_t
00144ba0:·7970·6520·6e6f·7420·696e·205b·2264·6f63··ype·not·in·["doc00144ba0:·7970·6520·6e6f·7420·696e·205b·2264·6f63··ype·not·in·["doc
00144bb0:·6b65·7222·2c20·226c·7863·222c·2022·6f70··ker",·"lxc",·"op00144bb0:·6b65·7222·2c20·226c·7863·222c·2022·6f70··ker",·"lxc",·"op
00144bc0:·656e·767a·222c·2022·706f·646d·616e·222c··envz",·"podman",00144bc0:·656e·767a·222c·2022·706f·646d·616e·222c··envz",·"podman",
00144bd0:·2022·636f·6e74·6169·6e65·7222·5d0a·2020···"container"].··00144bd0:·2022·636f·6e74·6169·6e65·7222·5d0a·2020···"container"].··
00144be0:·2d20·6669·6c65·5f65·7869·7374·732e·7374··-·file_exists.st00144be0:·2d20·6669·6c65·5f65·7869·7374·732e·7374··-·file_exists.st
00144bf0:·6174·2069·7320·6465·6669·6e65·6420·616e··at·is·defined·an00144bf0:·6174·2069·7320·6465·6669·6e65·6420·616e··at·is·defined·an
Offset 83180, 19 lines modifiedOffset 83180, 19 lines modified
00144eb0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy00144eb0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
00144ec0:·3a3c·2f74·683e·3c74·643e·636f·6e66·6967··:</th><td>config00144ec0:·3a3c·2f74·683e·3c74·643e·636f·6e66·6967··:</th><td>config
00144ed0:·7572·653c·2f74·643e·3c2f·7472·3e3c·2f74··ure</td></tr></t00144ed0:·7572·653c·2f74·643e·3c2f·7472·3e3c·2f74··ure</td></tr></t
00144ee0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>00144ee0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
00144ef0:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is00144ef0:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is
00144f00:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only00144f00:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only
00144f10:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat00144f10:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat
00144f20:·666f·726d·730a·6966·2072·706d·202d·2d71··forms.if·rpm·--q00144f20:·666f·726d·730a·6966·205b·2021·202d·6620··forms.if·[·!·-f·
00144f30:·7569·6574·202d·7120·6772·7562·322d·636f··uiet·-q·grub2-co 
00144f40:·6d6d·6f6e·2026·616d·703b·2661·6d70·3b20··mmon·&amp;&amp;· 
00144f50:·5b20·2120·2d66·202f·7379·732f·6669·726d··[·!·-f·/sys/firm 
00144f60:·7761·7265·2f65·6669·205d·2026·616d·703b··ware/efi·]·&amp;00144f30:·2f73·7973·2f66·6972·6d77·6172·652f·6566··/sys/firmware/ef
 00144f40:·6920·5d20·2661·6d70·3b26·616d·703b·2072··i·]·&amp;&amp;·r
 00144f50:·706d·202d·2d71·7569·6574·202d·7120·6772··pm·--quiet·-q·gr
 00144f60:·7562·322d·636f·6d6d·6f6e·2026·616d·703b··ub2-common·&amp;
00144f70:·2661·6d70·3b20·7b20·5b20·2120·2d66·202f··&amp;·{·[·!·-f·/00144f70:·2661·6d70·3b20·7b20·5b20·2120·2d66·202f··&amp;·{·[·!·-f·/
00144f80:·2e64·6f63·6b65·7265·6e76·205d·2026·616d··.dockerenv·]·&am00144f80:·2e64·6f63·6b65·7265·6e76·205d·2026·616d··.dockerenv·]·&am
00144f90:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/00144f90:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/
00144fa0:·7275·6e2f·2e63·6f6e·7461·696e·6572·656e··run/.containeren00144fa0:·7275·6e2f·2e63·6f6e·7461·696e·6572·656e··run/.containeren
00144fb0:·7620·5d3b·207d·3b20·7468·656e·0a0a·6368··v·];·};·then..ch00144fb0:·7620·5d3b·207d·3b20·7468·656e·0a0a·6368··v·];·};·then..ch
00144fc0:·6772·7020·3020·2f62·6f6f·742f·6772·7562··grp·0·/boot/grub00144fc0:·6772·7020·3020·2f62·6f6f·742f·6772·7562··grp·0·/boot/grub
00144fd0:·322f·6772·7562·2e63·6667·0a0a·656c·7365··2/grub.cfg..else00144fd0:·322f·6772·7562·2e63·6667·0a0a·656c·7365··2/grub.cfg..else
Offset 83658, 22 lines modifiedOffset 83658, 22 lines modified
00146c90:·616d·653a·2054·6573·7420·666f·7220·6578··ame:·Test·for·ex00146c90:·616d·653a·2054·6573·7420·666f·7220·6578··ame:·Test·for·ex
00146ca0:·6973·7465·6e63·6520·2f62·6f6f·742f·6772··istence·/boot/gr00146ca0:·6973·7465·6e63·6520·2f62·6f6f·742f·6772··istence·/boot/gr
00146cb0:·7562·322f·6772·7562·2e63·6667·0a20·2073··ub2/grub.cfg.··s00146cb0:·7562·322f·6772·7562·2e63·6667·0a20·2073··ub2/grub.cfg.··s
00146cc0:·7461·743a·0a20·2020·2070·6174·683a·202f··tat:.····path:·/00146cc0:·7461·743a·0a20·2020·2070·6174·683a·202f··tat:.····path:·/
00146cd0:·626f·6f74·2f67·7275·6232·2f67·7275·622e··boot/grub2/grub.00146cd0:·626f·6f74·2f67·7275·6232·2f67·7275·622e··boot/grub2/grub.
00146ce0:·6366·670a·2020·7265·6769·7374·6572·3a20··cfg.··register:·00146ce0:·6366·670a·2020·7265·6769·7374·6572·3a20··cfg.··register:·
00146cf0:·6669·6c65·5f65·7869·7374·730a·2020·7768··file_exists.··wh00146cf0:·6669·6c65·5f65·7869·7374·730a·2020·7768··file_exists.··wh
00146d00:·656e·3a0a·2020·2d20·2722·6772·7562·322d··en:.··-·'"grub2-00146d00:·656e·3a0a·2020·2d20·2722·2f62·6f6f·742f··en:.··-·'"/boot/
00146d10:·636f·6d6d·6f6e·2220·696e·2061·6e73·6962··common"·in·ansib 
00146d20:·6c65·5f66·6163·7473·2e70·6163·6b61·6765··le_facts.package 
00146d30:·7327·0a20·202d·2027·222f·626f·6f74·2f65··s'.··-·'"/boot/e 
00146d40:·6669·2220·6e6f·7420·696e·2061·6e73·6962··fi"·not·in·ansib 
00146d50:·6c65·5f6d·6f75·6e74·7320·7c20·6d61·7028··le_mounts·|·map( 
00146d60:·6174·7472·6962·7574·653d·226d·6f75·6e74··attribute="mount 
00146d70:·2229·207c·206c·6973·7427·0a20·202d·2061··")·|·list'.··-·a00146d10:·6566·6922·206e·6f74·2069·6e20·616e·7369··efi"·not·in·ansi
 00146d20:·626c·655f·6d6f·756e·7473·207c·206d·6170··ble_mounts·|·map
 00146d30:·2861·7474·7269·6275·7465·3d22·6d6f·756e··(attribute="moun
 00146d40:·7422·2920·7c20·6c69·7374·270a·2020·2d20··t")·|·list'.··-·
 00146d50:·2722·6772·7562·322d·636f·6d6d·6f6e·2220··'"grub2-common"·
 00146d60:·696e·2061·6e73·6962·6c65·5f66·6163·7473··in·ansible_facts
 00146d70:·2e70·6163·6b61·6765·7327·0a20·202d·2061··.packages'.··-·a
00146d80:·6e73·6962·6c65·5f76·6972·7475·616c·697a··nsible_virtualiz00146d80:·6e73·6962·6c65·5f76·6972·7475·616c·697a··nsible_virtualiz
00146d90:·6174·696f·6e5f·7479·7065·206e·6f74·2069··ation_type·not·i00146d90:·6174·696f·6e5f·7479·7065·206e·6f74·2069··ation_type·not·i
00146da0:·6e20·5b22·646f·636b·6572·222c·2022·6c78··n·["docker",·"lx00146da0:·6e20·5b22·646f·636b·6572·222c·2022·6c78··n·["docker",·"lx
00146db0:·6322·2c20·226f·7065·6e76·7a22·2c20·2270··c",·"openvz",·"p00146db0:·6322·2c20·226f·7065·6e76·7a22·2c20·2270··c",·"openvz",·"p
00146dc0:·6f64·6d61·6e22·2c20·2263·6f6e·7461·696e··odman",·"contain00146dc0:·6f64·6d61·6e22·2c20·2263·6f6e·7461·696e··odman",·"contain
00146dd0:·6572·225d·0a20·2074·6167·733a·0a20·202d··er"].··tags:.··-00146dd0:·6572·225d·0a20·2074·6167·733a·0a20·202d··er"].··tags:.··-
00146de0:·2043·4a49·532d·352e·352e·322e·320a·2020···CJIS-5.5.2.2.··00146de0:·2043·4a49·532d·352e·352e·322e·320a·2020···CJIS-5.5.2.2.··
Offset 83693, 22 lines modifiedOffset 83693, 22 lines modified
Max diff block lines reached; 9488/18752 bytes (50.60%) of diff not shown.
5.69 KB
html2text {}
    
Offset 39, 15 lines modifiedOffset 39, 15 lines modified
39 *****·Profile·Information·*****39 *****·Profile·Information·*****
40 Profile·Title·CIS·Aliyun·Linux·2·Benchmark·for·Level·240 Profile·Title·CIS·Aliyun·Linux·2·Benchmark·for·Level·2
41 Profile·ID····xccdf_org.ssgproject.content_profile_cis41 Profile·ID····xccdf_org.ssgproject.content_profile_cis
42 ***·CPE·Platforms·***42 ***·CPE·Platforms·***
43 ····*·cpe:/o:alinux:alibaba_cloud_linux:243 ····*·cpe:/o:alinux:alibaba_cloud_linux:2
44 *****·Revision·History·*****44 *****·Revision·History·*****
45 Current·version:·0.1.6545 Current·version:·0.1.65
46 ····*·draft·(as·of·2024-01-14)46 ····*·draft·(as·of·2025-02-15)
47 *****·Table·of·Contents·*****47 *****·Table·of·Contents·*****
48 ···1.·System_Settings48 ···1.·System_Settings
49 ·········1.·Installing_and_Maintaining_Software49 ·········1.·Installing_and_Maintaining_Software
50 ·········2.·Account_and_Access_Control50 ·········2.·Account_and_Access_Control
51 ·········3.·System_Accounting_with_auditd51 ·········3.·System_Accounting_with_auditd
52 ·········4.·GRUB2_bootloader_configuration52 ·········4.·GRUB2_bootloader_configuration
53 ·········5.·Configure_Syslog53 ·········5.·Configure_Syslog
Offset 6294, 16 lines modifiedOffset 6294, 16 lines modified
6294 ··-·no_reboot_needed6294 ··-·no_reboot_needed
  
6295 -·name:·Test·for·existence·/boot/grub2/grub.cfg6295 -·name:·Test·for·existence·/boot/grub2/grub.cfg
6296 ··stat:6296 ··stat:
6297 ····path:·/boot/grub2/grub.cfg6297 ····path:·/boot/grub2/grub.cfg
6298 ··register:·file_exists6298 ··register:·file_exists
6299 ··when:6299 ··when:
6300 ··-·'"grub2-common"·in·ansible_facts.packages' 
6301 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'6300 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 6301 ··-·'"grub2-common"·in·ansible_facts.packages'
6302 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6302 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
6303 ··tags:6303 ··tags:
6304 ··-·CJIS-5.5.2.26304 ··-·CJIS-5.5.2.2
6305 ··-·NIST-800-171-3.4.56305 ··-·NIST-800-171-3.4.5
6306 ··-·NIST-800-53-AC-6(1)6306 ··-·NIST-800-53-AC-6(1)
6307 ··-·NIST-800-53-CM-6(a)6307 ··-·NIST-800-53-CM-6(a)
6308 ··-·PCI-DSS-Req-7.16308 ··-·PCI-DSS-Req-7.1
Offset 6315, 16 lines modifiedOffset 6315, 16 lines modified
6315 ··-·no_reboot_needed6315 ··-·no_reboot_needed
  
6316 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg6316 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
6317 ··file:6317 ··file:
6318 ····path:·/boot/grub2/grub.cfg6318 ····path:·/boot/grub2/grub.cfg
6319 ····group:·'0'6319 ····group:·'0'
6320 ··when:6320 ··when:
6321 ··-·'"grub2-common"·in·ansible_facts.packages' 
6322 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'6321 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 6322 ··-·'"grub2-common"·in·ansible_facts.packages'
6323 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6323 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
6324 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists6324 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists
6325 ··tags:6325 ··tags:
6326 ··-·CJIS-5.5.2.26326 ··-·CJIS-5.5.2.2
6327 ··-·NIST-800-171-3.4.56327 ··-·NIST-800-171-3.4.5
6328 ··-·NIST-800-53-AC-6(1)6328 ··-·NIST-800-53-AC-6(1)
6329 ··-·NIST-800-53-CM-6(a)6329 ··-·NIST-800-53-CM-6(a)
Offset 6336, 15 lines modifiedOffset 6336, 15 lines modified
6336 ··-·medium_severity6336 ··-·medium_severity
6337 ··-·no_reboot_needed6337 ··-·no_reboot_needed
6338 Remediation_Shell_script_⇲6338 Remediation_Shell_script_⇲
6339 Complexity:·low6339 Complexity:·low
6340 Disruption:·low6340 Disruption:·low
6341 Strategy:···configure6341 Strategy:···configure
6342 #·Remediation·is·applicable·only·in·certain·platforms6342 #·Remediation·is·applicable·only·in·certain·platforms
6343 if·rpm·--quiet·-q·grub2-common·&&·[·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};6343 if·[·!·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};
6344 then6344 then
  
6345 chgrp·0·/boot/grub2/grub.cfg6345 chgrp·0·/boot/grub2/grub.cfg
  
6346 else6346 else
6347 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'6347 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
6348 fi6348 fi
Offset 6382, 16 lines modifiedOffset 6382, 16 lines modified
6382 ··-·no_reboot_needed6382 ··-·no_reboot_needed
  
6383 -·name:·Test·for·existence·/boot/grub2/grub.cfg6383 -·name:·Test·for·existence·/boot/grub2/grub.cfg
6384 ··stat:6384 ··stat:
6385 ····path:·/boot/grub2/grub.cfg6385 ····path:·/boot/grub2/grub.cfg
6386 ··register:·file_exists6386 ··register:·file_exists
6387 ··when:6387 ··when:
6388 ··-·'"grub2-common"·in·ansible_facts.packages' 
6389 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'6388 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 6389 ··-·'"grub2-common"·in·ansible_facts.packages'
6390 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6390 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
6391 ··tags:6391 ··tags:
6392 ··-·CJIS-5.5.2.26392 ··-·CJIS-5.5.2.2
6393 ··-·NIST-800-171-3.4.56393 ··-·NIST-800-171-3.4.5
6394 ··-·NIST-800-53-AC-6(1)6394 ··-·NIST-800-53-AC-6(1)
6395 ··-·NIST-800-53-CM-6(a)6395 ··-·NIST-800-53-CM-6(a)
6396 ··-·PCI-DSS-Req-7.16396 ··-·PCI-DSS-Req-7.1
Offset 6403, 16 lines modifiedOffset 6403, 16 lines modified
6403 ··-·no_reboot_needed6403 ··-·no_reboot_needed
  
6404 -·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg6404 -·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg
6405 ··file:6405 ··file:
6406 ····path:·/boot/grub2/grub.cfg6406 ····path:·/boot/grub2/grub.cfg
6407 ····owner:·'0'6407 ····owner:·'0'
6408 ··when:6408 ··when:
6409 ··-·'"grub2-common"·in·ansible_facts.packages' 
6410 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'6409 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 6410 ··-·'"grub2-common"·in·ansible_facts.packages'
6411 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6411 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
6412 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists6412 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists
6413 ··tags:6413 ··tags:
6414 ··-·CJIS-5.5.2.26414 ··-·CJIS-5.5.2.2
6415 ··-·NIST-800-171-3.4.56415 ··-·NIST-800-171-3.4.5
6416 ··-·NIST-800-53-AC-6(1)6416 ··-·NIST-800-53-AC-6(1)
6417 ··-·NIST-800-53-CM-6(a)6417 ··-·NIST-800-53-CM-6(a)
Offset 6424, 15 lines modifiedOffset 6424, 15 lines modified
6424 ··-·medium_severity6424 ··-·medium_severity
6425 ··-·no_reboot_needed6425 ··-·no_reboot_needed
6426 Remediation_Shell_script_⇲6426 Remediation_Shell_script_⇲
6427 Complexity:·low6427 Complexity:·low
6428 Disruption:·low6428 Disruption:·low
6429 Strategy:···configure6429 Strategy:···configure
6430 #·Remediation·is·applicable·only·in·certain·platforms6430 #·Remediation·is·applicable·only·in·certain·platforms
6431 if·rpm·--quiet·-q·grub2-common·&&·[·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};6431 if·[·!·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};
6432 then6432 then
  
6433 chown·0·/boot/grub2/grub.cfg6433 chown·0·/boot/grub2/grub.cfg
  
6434 else6434 else
6435 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'6435 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
6436 fi6436 fi
Offset 6468, 16 lines modifiedOffset 6468, 16 lines modified
6468 ··-·no_reboot_needed6468 ··-·no_reboot_needed
  
6469 -·name:·Test·for·existence·/boot/grub2/grub.cfg6469 -·name:·Test·for·existence·/boot/grub2/grub.cfg
6470 ··stat:6470 ··stat:
6471 ····path:·/boot/grub2/grub.cfg6471 ····path:·/boot/grub2/grub.cfg
6472 ··register:·file_exists6472 ··register:·file_exists
6473 ··when:6473 ··when:
Max diff block lines reached; 1488/5807 bytes (25.62%) of diff not shown.
24.0 KB
./usr/share/doc/ssg-nondebian/ssg-alinux2-guide-cis_l1.html
    
Offset 14293, 16 lines modifiedOffset 14293, 16 lines modified
00037d40:·7369·6f6e·2048·6973·746f·7279·3c2f·6832··sion·History</h200037d40:·7369·6f6e·2048·6973·746f·7279·3c2f·6832··sion·History</h2
00037d50:·3e3c·703e·4375·7272·656e·7420·7665·7273··><p>Current·vers00037d50:·3e3c·703e·4375·7272·656e·7420·7665·7273··><p>Current·vers
00037d60:·696f·6e3a·203c·7374·726f·6e67·3e30·2e31··ion:·<strong>0.100037d60:·696f·6e3a·203c·7374·726f·6e67·3e30·2e31··ion:·<strong>0.1
00037d70:·2e36·353c·2f73·7472·6f6e·673e·3c2f·703e··.65</strong></p>00037d70:·2e36·353c·2f73·7472·6f6e·673e·3c2f·703e··.65</strong></p>
00037d80:·3c75·6c3e·3c6c·693e·3c73·7472·6f6e·673e··<ul><li><strong>00037d80:·3c75·6c3e·3c6c·693e·3c73·7472·6f6e·673e··<ul><li><strong>
00037d90:·6472·6166·743c·2f73·7472·6f6e·673e·0a20··draft</strong>.·00037d90:·6472·6166·743c·2f73·7472·6f6e·673e·0a20··draft</strong>.·
00037da0:·2020·2020·2020·2020·2020·2020·2020·2020··················00037da0:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037db0:·2020·2028·6173·206f·6620·3230·3234·2d30·····(as·of·2024-000037db0:·2020·2028·6173·206f·6620·3230·3235·2d30·····(as·of·2025-0
00037dc0:·312d·3134·290a·2020·2020·2020·2020·2020··1-14).··········00037dc0:·322d·3135·290a·2020·2020·2020·2020·2020··2-15).··········
00037dd0:·2020·2020·2020·3c2f·6c69·3e3c·2f75·6c3e········</li></ul>00037dd0:·2020·2020·2020·3c2f·6c69·3e3c·2f75·6c3e········</li></ul>
00037de0:·3c2f·6469·763e·3c68·323e·5461·626c·6520··</div><h2>Table·00037de0:·3c2f·6469·763e·3c68·323e·5461·626c·6520··</div><h2>Table·
00037df0:·6f66·2043·6f6e·7465·6e74·733c·2f68·323e··of·Contents</h2>00037df0:·6f66·2043·6f6e·7465·6e74·733c·2f68·323e··of·Contents</h2>
00037e00:·3c6f·6c3e·3c6c·693e·3c61·2068·7265·663d··<ol><li><a·href=00037e00:·3c6f·6c3e·3c6c·693e·3c61·2068·7265·663d··<ol><li><a·href=
00037e10:·2223·7863·6364·665f·6f72·672e·7373·6770··"#xccdf_org.ssgp00037e10:·2223·7863·6364·665f·6f72·672e·7373·6770··"#xccdf_org.ssgp
00037e20:·726f·6a65·6374·2e63·6f6e·7465·6e74·5f67··roject.content_g00037e20:·726f·6a65·6374·2e63·6f6e·7465·6e74·5f67··roject.content_g
00037e30:·726f·7570·5f73·7973·7465·6d22·3e53·7973··roup_system">Sys00037e30:·726f·7570·5f73·7973·7465·6d22·3e53·7973··roup_system">Sys
Offset 36890, 22 lines modifiedOffset 36890, 22 lines modified
00090190:·2d20·6e61·6d65·3a20·5465·7374·2066·6f72··-·name:·Test·for00090190:·2d20·6e61·6d65·3a20·5465·7374·2066·6f72··-·name:·Test·for
000901a0:·2065·7869·7374·656e·6365·202f·626f·6f74···existence·/boot000901a0:·2065·7869·7374·656e·6365·202f·626f·6f74···existence·/boot
000901b0:·2f67·7275·6232·2f67·7275·622e·6366·670a··/grub2/grub.cfg.000901b0:·2f67·7275·6232·2f67·7275·622e·6366·670a··/grub2/grub.cfg.
000901c0:·2020·7374·6174·3a0a·2020·2020·7061·7468····stat:.····path000901c0:·2020·7374·6174·3a0a·2020·2020·7061·7468····stat:.····path
000901d0:·3a20·2f62·6f6f·742f·6772·7562·322f·6772··:·/boot/grub2/gr000901d0:·3a20·2f62·6f6f·742f·6772·7562·322f·6772··:·/boot/grub2/gr
000901e0:·7562·2e63·6667·0a20·2072·6567·6973·7465··ub.cfg.··registe000901e0:·7562·2e63·6667·0a20·2072·6567·6973·7465··ub.cfg.··registe
000901f0:·723a·2066·696c·655f·6578·6973·7473·0a20··r:·file_exists.·000901f0:·723a·2066·696c·655f·6578·6973·7473·0a20··r:·file_exists.·
00090200:·2077·6865·6e3a·0a20·202d·2027·2267·7275···when:.··-·'"gru00090200:·2077·6865·6e3a·0a20·202d·2027·222f·626f···when:.··-·'"/bo
00090210:·6232·2d63·6f6d·6d6f·6e22·2069·6e20·616e··b2-common"·in·an 
00090220:·7369·626c·655f·6661·6374·732e·7061·636b··sible_facts.pack 
00090230:·6167·6573·270a·2020·2d20·2722·2f62·6f6f··ages'.··-·'"/boo 
00090240:·742f·6566·6922·206e·6f74·2069·6e20·616e··t/efi"·not·in·an 
00090250:·7369·626c·655f·6d6f·756e·7473·207c·206d··sible_mounts·|·m 
00090260:·6170·2861·7474·7269·6275·7465·3d22·6d6f··ap(attribute="mo 
00090270:·756e·7422·2920·7c20·6c69·7374·270a·2020··unt")·|·list'.··00090210:·6f74·2f65·6669·2220·6e6f·7420·696e·2061··ot/efi"·not·in·a
 00090220:·6e73·6962·6c65·5f6d·6f75·6e74·7320·7c20··nsible_mounts·|·
 00090230:·6d61·7028·6174·7472·6962·7574·653d·226d··map(attribute="m
 00090240:·6f75·6e74·2229·207c·206c·6973·7427·0a20··ount")·|·list'.·
 00090250:·202d·2027·2267·7275·6232·2d63·6f6d·6d6f···-·'"grub2-commo
 00090260:·6e22·2069·6e20·616e·7369·626c·655f·6661··n"·in·ansible_fa
 00090270:·6374·732e·7061·636b·6167·6573·270a·2020··cts.packages'.··
00090280:·2d20·616e·7369·626c·655f·7669·7274·7561··-·ansible_virtua00090280:·2d20·616e·7369·626c·655f·7669·7274·7561··-·ansible_virtua
00090290:·6c69·7a61·7469·6f6e·5f74·7970·6520·6e6f··lization_type·no00090290:·6c69·7a61·7469·6f6e·5f74·7970·6520·6e6f··lization_type·no
000902a0:·7420·696e·205b·2264·6f63·6b65·7222·2c20··t·in·["docker",·000902a0:·7420·696e·205b·2264·6f63·6b65·7222·2c20··t·in·["docker",·
000902b0:·226c·7863·222c·2022·6f70·656e·767a·222c··"lxc",·"openvz",000902b0:·226c·7863·222c·2022·6f70·656e·767a·222c··"lxc",·"openvz",
000902c0:·2022·706f·646d·616e·222c·2022·636f·6e74···"podman",·"cont000902c0:·2022·706f·646d·616e·222c·2022·636f·6e74···"podman",·"cont
000902d0:·6169·6e65·7222·5d0a·2020·7461·6773·3a0a··ainer"].··tags:.000902d0:·6169·6e65·7222·5d0a·2020·7461·6773·3a0a··ainer"].··tags:.
000902e0:·2020·2d20·434a·4953·2d35·2e35·2e32·2e32····-·CJIS-5.5.2.2000902e0:·2020·2d20·434a·4953·2d35·2e35·2e32·2e32····-·CJIS-5.5.2.2
Offset 36926, 22 lines modifiedOffset 36926, 22 lines modified
000903d0:·0a2d·206e·616d·653a·2045·6e73·7572·6520··.-·name:·Ensure·000903d0:·0a2d·206e·616d·653a·2045·6e73·7572·6520··.-·name:·Ensure·
000903e0:·6772·6f75·7020·6f77·6e65·7220·3020·6f6e··group·owner·0·on000903e0:·6772·6f75·7020·6f77·6e65·7220·3020·6f6e··group·owner·0·on
000903f0:·202f·626f·6f74·2f67·7275·6232·2f67·7275···/boot/grub2/gru000903f0:·202f·626f·6f74·2f67·7275·6232·2f67·7275···/boot/grub2/gru
00090400:·622e·6366·670a·2020·6669·6c65·3a0a·2020··b.cfg.··file:.··00090400:·622e·6366·670a·2020·6669·6c65·3a0a·2020··b.cfg.··file:.··
00090410:·2020·7061·7468·3a20·2f62·6f6f·742f·6772····path:·/boot/gr00090410:·2020·7061·7468·3a20·2f62·6f6f·742f·6772····path:·/boot/gr
00090420:·7562·322f·6772·7562·2e63·6667·0a20·2020··ub2/grub.cfg.···00090420:·7562·322f·6772·7562·2e63·6667·0a20·2020··ub2/grub.cfg.···
00090430:·2067·726f·7570·3a20·2730·270a·2020·7768···group:·'0'.··wh00090430:·2067·726f·7570·3a20·2730·270a·2020·7768···group:·'0'.··wh
00090440:·656e·3a0a·2020·2d20·2722·6772·7562·322d··en:.··-·'"grub2-00090440:·656e·3a0a·2020·2d20·2722·2f62·6f6f·742f··en:.··-·'"/boot/
00090450:·636f·6d6d·6f6e·2220·696e·2061·6e73·6962··common"·in·ansib 
00090460:·6c65·5f66·6163·7473·2e70·6163·6b61·6765··le_facts.package 
00090470:·7327·0a20·202d·2027·222f·626f·6f74·2f65··s'.··-·'"/boot/e 
00090480:·6669·2220·6e6f·7420·696e·2061·6e73·6962··fi"·not·in·ansib 
00090490:·6c65·5f6d·6f75·6e74·7320·7c20·6d61·7028··le_mounts·|·map( 
000904a0:·6174·7472·6962·7574·653d·226d·6f75·6e74··attribute="mount 
000904b0:·2229·207c·206c·6973·7427·0a20·202d·2061··")·|·list'.··-·a00090450:·6566·6922·206e·6f74·2069·6e20·616e·7369··efi"·not·in·ansi
 00090460:·626c·655f·6d6f·756e·7473·207c·206d·6170··ble_mounts·|·map
 00090470:·2861·7474·7269·6275·7465·3d22·6d6f·756e··(attribute="moun
 00090480:·7422·2920·7c20·6c69·7374·270a·2020·2d20··t")·|·list'.··-·
 00090490:·2722·6772·7562·322d·636f·6d6d·6f6e·2220··'"grub2-common"·
 000904a0:·696e·2061·6e73·6962·6c65·5f66·6163·7473··in·ansible_facts
 000904b0:·2e70·6163·6b61·6765·7327·0a20·202d·2061··.packages'.··-·a
000904c0:·6e73·6962·6c65·5f76·6972·7475·616c·697a··nsible_virtualiz000904c0:·6e73·6962·6c65·5f76·6972·7475·616c·697a··nsible_virtualiz
000904d0:·6174·696f·6e5f·7479·7065·206e·6f74·2069··ation_type·not·i000904d0:·6174·696f·6e5f·7479·7065·206e·6f74·2069··ation_type·not·i
000904e0:·6e20·5b22·646f·636b·6572·222c·2022·6c78··n·["docker",·"lx000904e0:·6e20·5b22·646f·636b·6572·222c·2022·6c78··n·["docker",·"lx
000904f0:·6322·2c20·226f·7065·6e76·7a22·2c20·2270··c",·"openvz",·"p000904f0:·6322·2c20·226f·7065·6e76·7a22·2c20·2270··c",·"openvz",·"p
00090500:·6f64·6d61·6e22·2c20·2263·6f6e·7461·696e··odman",·"contain00090500:·6f64·6d61·6e22·2c20·2263·6f6e·7461·696e··odman",·"contain
00090510:·6572·225d·0a20·202d·2066·696c·655f·6578··er"].··-·file_ex00090510:·6572·225d·0a20·202d·2066·696c·655f·6578··er"].··-·file_ex
00090520:·6973·7473·2e73·7461·7420·6973·2064·6566··ists.stat·is·def00090520:·6973·7473·2e73·7461·7420·6973·2064·6566··ists.stat·is·def
Offset 36992, 19 lines modifiedOffset 36992, 19 lines modified
000907f0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td000907f0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
00090800:·3e63·6f6e·6669·6775·7265·3c2f·7464·3e3c··>configure</td><00090800:·3e63·6f6e·6669·6775·7265·3c2f·7464·3e3c··>configure</td><
00090810:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre00090810:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
00090820:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia00090820:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia
00090830:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab00090830:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab
00090840:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa00090840:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa
00090850:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if·00090850:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if·
00090860:·7270·6d20·2d2d·7175·6965·7420·2d71·2067··rpm·--quiet·-q·g 
00090870:·7275·6232·2d63·6f6d·6d6f·6e20·2661·6d70··rub2-common·&amp 
00090880:·3b26·616d·703b·205b·2021·202d·6620·2f73··;&amp;·[·!·-f·/s 
00090890:·7973·2f66·6972·6d77·6172·652f·6566·6920··ys/firmware/efi·00090860:·5b20·2120·2d66·202f·7379·732f·6669·726d··[·!·-f·/sys/firm
 00090870:·7761·7265·2f65·6669·205d·2026·616d·703b··ware/efi·]·&amp;
 00090880:·2661·6d70·3b20·7270·6d20·2d2d·7175·6965··&amp;·rpm·--quie
 00090890:·7420·2d71·2067·7275·6232·2d63·6f6d·6d6f··t·-q·grub2-commo
000908a0:·5d20·2661·6d70·3b26·616d·703b·207b·205b··]·&amp;&amp;·{·[000908a0:·6e20·2661·6d70·3b26·616d·703b·207b·205b··n·&amp;&amp;·{·[
000908b0:·2021·202d·6620·2f2e·646f·636b·6572·656e···!·-f·/.dockeren000908b0:·2021·202d·6620·2f2e·646f·636b·6572·656e···!·-f·/.dockeren
000908c0:·7620·5d20·2661·6d70·3b26·616d·703b·205b··v·]·&amp;&amp;·[000908c0:·7620·5d20·2661·6d70·3b26·616d·703b·205b··v·]·&amp;&amp;·[
000908d0:·2021·202d·6620·2f72·756e·2f2e·636f·6e74···!·-f·/run/.cont000908d0:·2021·202d·6620·2f72·756e·2f2e·636f·6e74···!·-f·/run/.cont
000908e0:·6169·6e65·7265·6e76·205d·3b20·7d3b·2074··ainerenv·];·};·t000908e0:·6169·6e65·7265·6e76·205d·3b20·7d3b·2074··ainerenv·];·};·t
000908f0:·6865·6e0a·0a63·6867·7270·2030·202f·626f··hen..chgrp·0·/bo000908f0:·6865·6e0a·0a63·6867·7270·2030·202f·626f··hen..chgrp·0·/bo
00090900:·6f74·2f67·7275·6232·2f67·7275·622e·6366··ot/grub2/grub.cf00090900:·6f74·2f67·7275·6232·2f67·7275·622e·6366··ot/grub2/grub.cf
00090910:·670a·0a65·6c73·650a·2020·2020·2667·743b··g..else.····&gt;00090910:·670a·0a65·6c73·650a·2020·2020·2667·743b··g..else.····&gt;
Offset 37470, 21 lines modifiedOffset 37470, 21 lines modified
000925d0:·2066·6f72·2065·7869·7374·656e·6365·202f···for·existence·/000925d0:·2066·6f72·2065·7869·7374·656e·6365·202f···for·existence·/
000925e0:·626f·6f74·2f67·7275·6232·2f67·7275·622e··boot/grub2/grub.000925e0:·626f·6f74·2f67·7275·6232·2f67·7275·622e··boot/grub2/grub.
000925f0:·6366·670a·2020·7374·6174·3a0a·2020·2020··cfg.··stat:.····000925f0:·6366·670a·2020·7374·6174·3a0a·2020·2020··cfg.··stat:.····
00092600:·7061·7468·3a20·2f62·6f6f·742f·6772·7562··path:·/boot/grub00092600:·7061·7468·3a20·2f62·6f6f·742f·6772·7562··path:·/boot/grub
00092610:·322f·6772·7562·2e63·6667·0a20·2072·6567··2/grub.cfg.··reg00092610:·322f·6772·7562·2e63·6667·0a20·2072·6567··2/grub.cfg.··reg
00092620:·6973·7465·723a·2066·696c·655f·6578·6973··ister:·file_exis00092620:·6973·7465·723a·2066·696c·655f·6578·6973··ister:·file_exis
00092630:·7473·0a20·2077·6865·6e3a·0a20·202d·2027··ts.··when:.··-·'00092630:·7473·0a20·2077·6865·6e3a·0a20·202d·2027··ts.··when:.··-·'
00092640:·2267·7275·6232·2d63·6f6d·6d6f·6e22·2069··"grub2-common"·i 
00092650:·6e20·616e·7369·626c·655f·6661·6374·732e··n·ansible_facts. 
00092660:·7061·636b·6167·6573·270a·2020·2d20·2722··packages'.··-·'" 
00092670:·2f62·6f6f·742f·6566·6922·206e·6f74·2069··/boot/efi"·not·i 
00092680:·6e20·616e·7369·626c·655f·6d6f·756e·7473··n·ansible_mounts 
00092690:·207c·206d·6170·2861·7474·7269·6275·7465···|·map(attribute 
000926a0:·3d22·6d6f·756e·7422·2920·7c20·6c69·7374··="mount")·|·list00092640:·222f·626f·6f74·2f65·6669·2220·6e6f·7420··"/boot/efi"·not·
 00092650:·696e·2061·6e73·6962·6c65·5f6d·6f75·6e74··in·ansible_mount
 00092660:·7320·7c20·6d61·7028·6174·7472·6962·7574··s·|·map(attribut
 00092670:·653d·226d·6f75·6e74·2229·207c·206c·6973··e="mount")·|·lis
 00092680:·7427·0a20·202d·2027·2267·7275·6232·2d63··t'.··-·'"grub2-c
 00092690:·6f6d·6d6f·6e22·2069·6e20·616e·7369·626c··ommon"·in·ansibl
 000926a0:·655f·6661·6374·732e·7061·636b·6167·6573··e_facts.packages
000926b0:·270a·2020·2d20·616e·7369·626c·655f·7669··'.··-·ansible_vi000926b0:·270a·2020·2d20·616e·7369·626c·655f·7669··'.··-·ansible_vi
000926c0:·7274·7561·6c69·7a61·7469·6f6e·5f74·7970··rtualization_typ000926c0:·7274·7561·6c69·7a61·7469·6f6e·5f74·7970··rtualization_typ
000926d0:·6520·6e6f·7420·696e·205b·2264·6f63·6b65··e·not·in·["docke000926d0:·6520·6e6f·7420·696e·205b·2264·6f63·6b65··e·not·in·["docke
000926e0:·7222·2c20·226c·7863·222c·2022·6f70·656e··r",·"lxc",·"open000926e0:·7222·2c20·226c·7863·222c·2022·6f70·656e··r",·"lxc",·"open
000926f0:·767a·222c·2022·706f·646d·616e·222c·2022··vz",·"podman",·"000926f0:·767a·222c·2022·706f·646d·616e·222c·2022··vz",·"podman",·"
00092700:·636f·6e74·6169·6e65·7222·5d0a·2020·7461··container"].··ta00092700:·636f·6e74·6169·6e65·7222·5d0a·2020·7461··container"].··ta
00092710:·6773·3a0a·2020·2d20·434a·4953·2d35·2e35··gs:.··-·CJIS-5.500092710:·6773·3a0a·2020·2d20·434a·4953·2d35·2e35··gs:.··-·CJIS-5.5
Offset 37505, 22 lines modifiedOffset 37505, 22 lines modified
00092800:·2d20·6e61·6d65·3a20·456e·7375·7265·206f··-·name:·Ensure·o00092800:·2d20·6e61·6d65·3a20·456e·7375·7265·206f··-·name:·Ensure·o
Max diff block lines reached; 9350/18614 bytes (50.23%) of diff not shown.
5.7 KB
html2text {}
    
Offset 39, 15 lines modifiedOffset 39, 15 lines modified
39 *****·Profile·Information·*****39 *****·Profile·Information·*****
40 Profile·Title·CIS·Aliyun·Linux·2·Benchmark·for·Level·140 Profile·Title·CIS·Aliyun·Linux·2·Benchmark·for·Level·1
41 Profile·ID····xccdf_org.ssgproject.content_profile_cis_l141 Profile·ID····xccdf_org.ssgproject.content_profile_cis_l1
42 ***·CPE·Platforms·***42 ***·CPE·Platforms·***
43 ····*·cpe:/o:alinux:alibaba_cloud_linux:243 ····*·cpe:/o:alinux:alibaba_cloud_linux:2
44 *****·Revision·History·*****44 *****·Revision·History·*****
45 Current·version:·0.1.6545 Current·version:·0.1.65
46 ····*·draft·(as·of·2024-01-14)46 ····*·draft·(as·of·2025-02-15)
47 *****·Table·of·Contents·*****47 *****·Table·of·Contents·*****
48 ···1.·System_Settings48 ···1.·System_Settings
49 ·········1.·Installing_and_Maintaining_Software49 ·········1.·Installing_and_Maintaining_Software
50 ·········2.·Account_and_Access_Control50 ·········2.·Account_and_Access_Control
51 ·········3.·GRUB2_bootloader_configuration51 ·········3.·GRUB2_bootloader_configuration
52 ·········4.·Configure_Syslog52 ·········4.·Configure_Syslog
53 ·········5.·Network_Configuration_and_Firewalls53 ·········5.·Network_Configuration_and_Firewalls
Offset 2423, 16 lines modifiedOffset 2423, 16 lines modified
2423 ··-·no_reboot_needed2423 ··-·no_reboot_needed
  
2424 -·name:·Test·for·existence·/boot/grub2/grub.cfg2424 -·name:·Test·for·existence·/boot/grub2/grub.cfg
2425 ··stat:2425 ··stat:
2426 ····path:·/boot/grub2/grub.cfg2426 ····path:·/boot/grub2/grub.cfg
2427 ··register:·file_exists2427 ··register:·file_exists
2428 ··when:2428 ··when:
2429 ··-·'"grub2-common"·in·ansible_facts.packages' 
2430 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'2429 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 2430 ··-·'"grub2-common"·in·ansible_facts.packages'
2431 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2431 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2432 ··tags:2432 ··tags:
2433 ··-·CJIS-5.5.2.22433 ··-·CJIS-5.5.2.2
2434 ··-·NIST-800-171-3.4.52434 ··-·NIST-800-171-3.4.5
2435 ··-·NIST-800-53-AC-6(1)2435 ··-·NIST-800-53-AC-6(1)
2436 ··-·NIST-800-53-CM-6(a)2436 ··-·NIST-800-53-CM-6(a)
2437 ··-·PCI-DSS-Req-7.12437 ··-·PCI-DSS-Req-7.1
Offset 2444, 16 lines modifiedOffset 2444, 16 lines modified
2444 ··-·no_reboot_needed2444 ··-·no_reboot_needed
  
2445 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg2445 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
2446 ··file:2446 ··file:
2447 ····path:·/boot/grub2/grub.cfg2447 ····path:·/boot/grub2/grub.cfg
2448 ····group:·'0'2448 ····group:·'0'
2449 ··when:2449 ··when:
2450 ··-·'"grub2-common"·in·ansible_facts.packages' 
2451 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'2450 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 2451 ··-·'"grub2-common"·in·ansible_facts.packages'
2452 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2452 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2453 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists2453 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists
2454 ··tags:2454 ··tags:
2455 ··-·CJIS-5.5.2.22455 ··-·CJIS-5.5.2.2
2456 ··-·NIST-800-171-3.4.52456 ··-·NIST-800-171-3.4.5
2457 ··-·NIST-800-53-AC-6(1)2457 ··-·NIST-800-53-AC-6(1)
2458 ··-·NIST-800-53-CM-6(a)2458 ··-·NIST-800-53-CM-6(a)
Offset 2465, 15 lines modifiedOffset 2465, 15 lines modified
2465 ··-·medium_severity2465 ··-·medium_severity
2466 ··-·no_reboot_needed2466 ··-·no_reboot_needed
2467 Remediation_Shell_script_⇲2467 Remediation_Shell_script_⇲
2468 Complexity:·low2468 Complexity:·low
2469 Disruption:·low2469 Disruption:·low
2470 Strategy:···configure2470 Strategy:···configure
2471 #·Remediation·is·applicable·only·in·certain·platforms2471 #·Remediation·is·applicable·only·in·certain·platforms
2472 if·rpm·--quiet·-q·grub2-common·&&·[·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};2472 if·[·!·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};
2473 then2473 then
  
2474 chgrp·0·/boot/grub2/grub.cfg2474 chgrp·0·/boot/grub2/grub.cfg
  
2475 else2475 else
2476 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'2476 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
2477 fi2477 fi
Offset 2511, 16 lines modifiedOffset 2511, 16 lines modified
2511 ··-·no_reboot_needed2511 ··-·no_reboot_needed
  
2512 -·name:·Test·for·existence·/boot/grub2/grub.cfg2512 -·name:·Test·for·existence·/boot/grub2/grub.cfg
2513 ··stat:2513 ··stat:
2514 ····path:·/boot/grub2/grub.cfg2514 ····path:·/boot/grub2/grub.cfg
2515 ··register:·file_exists2515 ··register:·file_exists
2516 ··when:2516 ··when:
2517 ··-·'"grub2-common"·in·ansible_facts.packages' 
2518 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'2517 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 2518 ··-·'"grub2-common"·in·ansible_facts.packages'
2519 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2519 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2520 ··tags:2520 ··tags:
2521 ··-·CJIS-5.5.2.22521 ··-·CJIS-5.5.2.2
2522 ··-·NIST-800-171-3.4.52522 ··-·NIST-800-171-3.4.5
2523 ··-·NIST-800-53-AC-6(1)2523 ··-·NIST-800-53-AC-6(1)
2524 ··-·NIST-800-53-CM-6(a)2524 ··-·NIST-800-53-CM-6(a)
2525 ··-·PCI-DSS-Req-7.12525 ··-·PCI-DSS-Req-7.1
Offset 2532, 16 lines modifiedOffset 2532, 16 lines modified
2532 ··-·no_reboot_needed2532 ··-·no_reboot_needed
  
2533 -·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg2533 -·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg
2534 ··file:2534 ··file:
2535 ····path:·/boot/grub2/grub.cfg2535 ····path:·/boot/grub2/grub.cfg
2536 ····owner:·'0'2536 ····owner:·'0'
2537 ··when:2537 ··when:
2538 ··-·'"grub2-common"·in·ansible_facts.packages' 
2539 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'2538 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 2539 ··-·'"grub2-common"·in·ansible_facts.packages'
2540 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2540 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2541 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists2541 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists
2542 ··tags:2542 ··tags:
2543 ··-·CJIS-5.5.2.22543 ··-·CJIS-5.5.2.2
2544 ··-·NIST-800-171-3.4.52544 ··-·NIST-800-171-3.4.5
2545 ··-·NIST-800-53-AC-6(1)2545 ··-·NIST-800-53-AC-6(1)
2546 ··-·NIST-800-53-CM-6(a)2546 ··-·NIST-800-53-CM-6(a)
Offset 2553, 15 lines modifiedOffset 2553, 15 lines modified
2553 ··-·medium_severity2553 ··-·medium_severity
2554 ··-·no_reboot_needed2554 ··-·no_reboot_needed
2555 Remediation_Shell_script_⇲2555 Remediation_Shell_script_⇲
2556 Complexity:·low2556 Complexity:·low
2557 Disruption:·low2557 Disruption:·low
2558 Strategy:···configure2558 Strategy:···configure
2559 #·Remediation·is·applicable·only·in·certain·platforms2559 #·Remediation·is·applicable·only·in·certain·platforms
2560 if·rpm·--quiet·-q·grub2-common·&&·[·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};2560 if·[·!·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};
2561 then2561 then
  
2562 chown·0·/boot/grub2/grub.cfg2562 chown·0·/boot/grub2/grub.cfg
  
2563 else2563 else
2564 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'2564 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
2565 fi2565 fi
Offset 2597, 16 lines modifiedOffset 2597, 16 lines modified
2597 ··-·no_reboot_needed2597 ··-·no_reboot_needed
  
2598 -·name:·Test·for·existence·/boot/grub2/grub.cfg2598 -·name:·Test·for·existence·/boot/grub2/grub.cfg
2599 ··stat:2599 ··stat:
2600 ····path:·/boot/grub2/grub.cfg2600 ····path:·/boot/grub2/grub.cfg
2601 ··register:·file_exists2601 ··register:·file_exists
2602 ··when:2602 ··when:
Max diff block lines reached; 1488/5816 bytes (25.58%) of diff not shown.
1.86 KB
./usr/share/doc/ssg-nondebian/ssg-alinux2-guide-standard.html
    
Offset 14290, 15 lines modifiedOffset 14290, 15 lines modified
00037d10:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v00037d10:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v
00037d20:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>00037d20:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>
00037d30:·302e·312e·3635·3c2f·7374·726f·6e67·3e3c··0.1.65</strong><00037d30:·302e·312e·3635·3c2f·7374·726f·6e67·3e3c··0.1.65</strong><
00037d40:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro00037d40:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro
00037d50:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong00037d50:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong
00037d60:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············00037d60:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············
00037d70:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·20200037d70:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·202
00037d80:·342d·3031·2d31·3429·0a20·2020·2020·2020··4-01-14).·······00037d80:·352d·3032·2d31·3529·0a20·2020·2020·2020··5-02-15).·······
00037d90:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></00037d90:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></
00037da0:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab00037da0:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab
00037db0:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</00037db0:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</
00037dc0:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr00037dc0:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr
00037dd0:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s00037dd0:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s
00037de0:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten00037de0:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten
00037df0:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">00037df0:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">
648 B
html2text {}
    
Offset 39, 15 lines modifiedOffset 39, 15 lines modified
39 *****·Profile·Information·*****39 *****·Profile·Information·*****
40 Profile·Title·Standard·System·Security·Profile·for·Alibaba·Cloud·Linux·240 Profile·Title·Standard·System·Security·Profile·for·Alibaba·Cloud·Linux·2
41 Profile·ID····xccdf_org.ssgproject.content_profile_standard41 Profile·ID····xccdf_org.ssgproject.content_profile_standard
42 ***·CPE·Platforms·***42 ***·CPE·Platforms·***
43 ····*·cpe:/o:alinux:alibaba_cloud_linux:243 ····*·cpe:/o:alinux:alibaba_cloud_linux:2
44 *****·Revision·History·*****44 *****·Revision·History·*****
45 Current·version:·0.1.6545 Current·version:·0.1.65
46 ····*·draft·(as·of·2024-01-14)46 ····*·draft·(as·of·2025-02-15)
47 *****·Table·of·Contents·*****47 *****·Table·of·Contents·*****
48 ···1.·System_Settings48 ···1.·System_Settings
49 ·········1.·Installing_and_Maintaining_Software49 ·········1.·Installing_and_Maintaining_Software
50 ·········2.·System_Accounting_with_auditd50 ·········2.·System_Accounting_with_auditd
51 ·········3.·Network_Configuration_and_Firewalls51 ·········3.·Network_Configuration_and_Firewalls
52 ·········4.·File_Permissions_and_Masks52 ·········4.·File_Permissions_and_Masks
53 ···2.·Services53 ···2.·Services
110 KB
./usr/share/doc/ssg-nondebian/ssg-alinux3-guide-cis.html
    
Offset 14295, 15 lines modifiedOffset 14295, 15 lines modified
00037d60:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>00037d60:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>
00037d70:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:00037d70:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:
00037d80:·203c·7374·726f·6e67·3e30·2e31·2e36·353c···<strong>0.1.65<00037d80:·203c·7374·726f·6e67·3e30·2e31·2e36·353c···<strong>0.1.65<
00037d90:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>00037d90:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>
00037da0:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf00037da0:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf
00037db0:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····00037db0:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····
00037dc0:·2020·2020·2020·2020·2020·2020·2020·2028·················(00037dc0:·2020·2020·2020·2020·2020·2020·2020·2028·················(
00037dd0:·6173·206f·6620·3230·3234·2d30·312d·3134··as·of·2024-01-1400037dd0:·6173·206f·6620·3230·3235·2d30·322d·3135··as·of·2025-02-15
00037de0:·290a·2020·2020·2020·2020·2020·2020·2020··).··············00037de0:·290a·2020·2020·2020·2020·2020·2020·2020··).··············
00037df0:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di00037df0:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di
00037e00:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C00037e00:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C
00037e10:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>00037e10:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>
00037e20:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc00037e20:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc
00037e30:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje00037e30:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje
00037e40:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group00037e40:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group
Offset 41914, 22 lines modifiedOffset 41914, 22 lines modified
000a3b90:·6e65·6564·6564·0a20·202d·2072·6573·7472··needed.··-·restr000a3b90:·6e65·6564·6564·0a20·202d·2072·6573·7472··needed.··-·restr
000a3ba0:·6963·745f·7374·7261·7465·6779·0a0a·2d20··ict_strategy..-·000a3ba0:·6963·745f·7374·7261·7465·6779·0a0a·2d20··ict_strategy..-·
000a3bb0:·6e61·6d65·3a20·5365·7420·6172·6368·6974··name:·Set·archit000a3bb0:·6e61·6d65·3a20·5365·7420·6172·6368·6974··name:·Set·archit
000a3bc0:·6563·7475·7265·2066·6f72·2061·7564·6974··ecture·for·audit000a3bc0:·6563·7475·7265·2066·6f72·2061·7564·6974··ecture·for·audit
000a3bd0:·2074·6173·6b73·0a20·2073·6574·5f66·6163···tasks.··set_fac000a3bd0:·2074·6173·6b73·0a20·2073·6574·5f66·6163···tasks.··set_fac
000a3be0:·743a·0a20·2020·2061·7564·6974·5f61·7263··t:.····audit_arc000a3be0:·743a·0a20·2020·2061·7564·6974·5f61·7263··t:.····audit_arc
000a3bf0:·683a·2062·3634·0a20·2077·6865·6e3a·0a20··h:·b64.··when:.·000a3bf0:·683a·2062·3634·0a20·2077·6865·6e3a·0a20··h:·b64.··when:.·
000a3c00:·202d·2061·6e73·6962·6c65·5f76·6972·7475···-·ansible_virtu 
000a3c10:·616c·697a·6174·696f·6e5f·7479·7065·206e··alization_type·n 
000a3c20:·6f74·2069·6e20·5b22·646f·636b·6572·222c··ot·in·["docker", 
000a3c30:·2022·6c78·6322·2c20·226f·7065·6e76·7a22···"lxc",·"openvz" 
000a3c40:·2c20·2270·6f64·6d61·6e22·2c20·2263·6f6e··,·"podman",·"con 
000a3c50:·7461·696e·6572·225d·0a20·202d·2027·2261··tainer"].··-·'"a 
000a3c60:·7564·6974·2220·696e·2061·6e73·6962·6c65··udit"·in·ansible 
000a3c70:·5f66·6163·7473·2e70·6163·6b61·6765·7327··_facts.packages'000a3c00:·202d·2027·2261·7564·6974·2220·696e·2061···-·'"audit"·in·a
 000a3c10:·6e73·6962·6c65·5f66·6163·7473·2e70·6163··nsible_facts.pac
 000a3c20:·6b61·6765·7327·0a20·202d·2061·6e73·6962··kages'.··-·ansib
 000a3c30:·6c65·5f76·6972·7475·616c·697a·6174·696f··le_virtualizatio
 000a3c40:·6e5f·7479·7065·206e·6f74·2069·6e20·5b22··n_type·not·in·["
 000a3c50:·646f·636b·6572·222c·2022·6c78·6322·2c20··docker",·"lxc",·
 000a3c60:·226f·7065·6e76·7a22·2c20·2270·6f64·6d61··"openvz",·"podma
 000a3c70:·6e22·2c20·2263·6f6e·7461·696e·6572·225d··n",·"container"]
000a3c80:·0a20·202d·2061·6e73·6962·6c65·5f61·7263··.··-·ansible_arc000a3c80:·0a20·202d·2061·6e73·6962·6c65·5f61·7263··.··-·ansible_arc
000a3c90:·6869·7465·6374·7572·6520·3d3d·2022·6161··hitecture·==·"aa000a3c90:·6869·7465·6374·7572·6520·3d3d·2022·6161··hitecture·==·"aa
000a3ca0:·7263·6836·3422·206f·7220·616e·7369·626c··rch64"·or·ansibl000a3ca0:·7263·6836·3422·206f·7220·616e·7369·626c··rch64"·or·ansibl
000a3cb0:·655f·6172·6368·6974·6563·7475·7265·203d··e_architecture·=000a3cb0:·655f·6172·6368·6974·6563·7475·7265·203d··e_architecture·=
000a3cc0:·3d20·2270·7063·3634·2220·6f72·2061·6e73··=·"ppc64"·or·ans000a3cc0:·3d20·2270·7063·3634·2220·6f72·2061·6e73··=·"ppc64"·or·ans
000a3cd0:·6962·6c65·5f61·7263·6869·7465·6374·7572··ible_architectur000a3cd0:·6962·6c65·5f61·7263·6869·7465·6374·7572··ible_architectur
000a3ce0:·650a·2020·2020·3d3d·2022·7070·6336·346c··e.····==·"ppc64l000a3ce0:·650a·2020·2020·3d3d·2022·7070·6336·346c··e.····==·"ppc64l
Offset 42226, 23 lines modifiedOffset 42226, 23 lines modified
000a4f10:·6d65·5f72·756c·6573·0a20·2020·2020·2063··me_rules.······c000a4f10:·6d65·5f72·756c·6573·0a20·2020·2020·2063··me_rules.······c
000a4f20:·7265·6174·653a·2074·7275·650a·2020·2020··reate:·true.····000a4f20:·7265·6174·653a·2074·7275·650a·2020·2020··reate:·true.····
000a4f30:·2020·6d6f·6465·3a20·6f2d·7277·780a·2020····mode:·o-rwx.··000a4f30:·2020·6d6f·6465·3a20·6f2d·7277·780a·2020····mode:·o-rwx.··
000a4f40:·2020·2020·7374·6174·653a·2070·7265·7365······state:·prese000a4f40:·2020·2020·7374·6174·653a·2070·7265·7365······state:·prese
000a4f50:·6e74·0a20·2020·2077·6865·6e3a·2073·7973··nt.····when:·sys000a4f50:·6e74·0a20·2020·2077·6865·6e3a·2073·7973··nt.····when:·sys
000a4f60:·6361·6c6c·735f·666f·756e·6420·7c20·6c65··calls_found·|·le000a4f60:·6361·6c6c·735f·666f·756e·6420·7c20·6c65··calls_found·|·le
000a4f70:·6e67·7468·203d·3d20·300a·2020·7768·656e··ngth·==·0.··when000a4f70:·6e67·7468·203d·3d20·300a·2020·7768·656e··ngth·==·0.··when
000a4f80:·3a0a·2020·2d20·616e·7369·626c·655f·7669··:.··-·ansible_vi 
000a4f90:·7274·7561·6c69·7a61·7469·6f6e·5f74·7970··rtualization_typ 
000a4fa0:·6520·6e6f·7420·696e·205b·2264·6f63·6b65··e·not·in·["docke 
000a4fb0:·7222·2c20·226c·7863·222c·2022·6f70·656e··r",·"lxc",·"open 
000a4fc0:·767a·222c·2022·706f·646d·616e·222c·2022··vz",·"podman",·" 
000a4fd0:·636f·6e74·6169·6e65·7222·5d0a·2020·2d20··container"].··-· 
000a4fe0:·2722·6175·6469·7422·2069·6e20·616e·7369··'"audit"·in·ansi 
000a4ff0:·626c·655f·6661·6374·732e·7061·636b·6167··ble_facts.packag000a4f80:·3a0a·2020·2d20·2722·6175·6469·7422·2069··:.··-·'"audit"·i
 000a4f90:·6e20·616e·7369·626c·655f·6661·6374·732e··n·ansible_facts.
 000a4fa0:·7061·636b·6167·6573·270a·2020·2d20·616e··packages'.··-·an
 000a4fb0:·7369·626c·655f·7669·7274·7561·6c69·7a61··sible_virtualiza
 000a4fc0:·7469·6f6e·5f74·7970·6520·6e6f·7420·696e··tion_type·not·in
 000a4fd0:·205b·2264·6f63·6b65·7222·2c20·226c·7863···["docker",·"lxc
 000a4fe0:·222c·2022·6f70·656e·767a·222c·2022·706f··",·"openvz",·"po
 000a4ff0:·646d·616e·222c·2022·636f·6e74·6169·6e65··dman",·"containe
000a5000:·6573·270a·2020·7461·6773·3a0a·2020·2d20··es'.··tags:.··-·000a5000:·7222·5d0a·2020·7461·6773·3a0a·2020·2d20··r"].··tags:.··-·
000a5010:·434a·4953·2d35·2e34·2e31·2e31·0a20·202d··CJIS-5.4.1.1.··-000a5010:·434a·4953·2d35·2e34·2e31·2e31·0a20·202d··CJIS-5.4.1.1.··-
000a5020:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.000a5020:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.
000a5030:·312e·370a·2020·2d20·4e49·5354·2d38·3030··1.7.··-·NIST-800000a5030:·312e·370a·2020·2d20·4e49·5354·2d38·3030··1.7.··-·NIST-800
000a5040:·2d35·332d·4143·2d36·2839·290a·2020·2d20··-53-AC-6(9).··-·000a5040:·2d35·332d·4143·2d36·2839·290a·2020·2d20··-53-AC-6(9).··-·
000a5050:·4e49·5354·2d38·3030·2d35·332d·4155·2d31··NIST-800-53-AU-1000a5050:·4e49·5354·2d38·3030·2d35·332d·4155·2d31··NIST-800-53-AU-1
000a5060:·3228·6329·0a20·202d·204e·4953·542d·3830··2(c).··-·NIST-80000a5060:·3228·6329·0a20·202d·204e·4953·542d·3830··2(c).··-·NIST-80
000a5070:·302d·3533·2d41·552d·3228·6429·0a20·202d··0-53-AU-2(d).··-000a5070:·302d·3533·2d41·552d·3228·6429·0a20·202d··0-53-AU-2(d).··-
Offset 42526, 22 lines modifiedOffset 42526, 22 lines modified
000a61d0:·756c·6573·0a20·2020·2020·2063·7265·6174··ules.······creat000a61d0:·756c·6573·0a20·2020·2020·2063·7265·6174··ules.······creat
000a61e0:·653a·2074·7275·650a·2020·2020·2020·6d6f··e:·true.······mo000a61e0:·653a·2074·7275·650a·2020·2020·2020·6d6f··e:·true.······mo
000a61f0:·6465·3a20·6f2d·7277·780a·2020·2020·2020··de:·o-rwx.······000a61f0:·6465·3a20·6f2d·7277·780a·2020·2020·2020··de:·o-rwx.······
000a6200:·7374·6174·653a·2070·7265·7365·6e74·0a20··state:·present.·000a6200:·7374·6174·653a·2070·7265·7365·6e74·0a20··state:·present.·
000a6210:·2020·2077·6865·6e3a·2073·7973·6361·6c6c·····when:·syscall000a6210:·2020·2077·6865·6e3a·2073·7973·6361·6c6c·····when:·syscall
000a6220:·735f·666f·756e·6420·7c20·6c65·6e67·7468··s_found·|·length000a6220:·735f·666f·756e·6420·7c20·6c65·6e67·7468··s_found·|·length
000a6230:·203d·3d20·300a·2020·7768·656e·3a0a·2020···==·0.··when:.··000a6230:·203d·3d20·300a·2020·7768·656e·3a0a·2020···==·0.··when:.··
000a6240:·2d20·616e·7369·626c·655f·7669·7274·7561··-·ansible_virtua 
000a6250:·6c69·7a61·7469·6f6e·5f74·7970·6520·6e6f··lization_type·no 
000a6260:·7420·696e·205b·2264·6f63·6b65·7222·2c20··t·in·["docker",· 
000a6270:·226c·7863·222c·2022·6f70·656e·767a·222c··"lxc",·"openvz", 
000a6280:·2022·706f·646d·616e·222c·2022·636f·6e74···"podman",·"cont 
000a6290:·6169·6e65·7222·5d0a·2020·2d20·2722·6175··ainer"].··-·'"au 
000a62a0:·6469·7422·2069·6e20·616e·7369·626c·655f··dit"·in·ansible_ 
000a62b0:·6661·6374·732e·7061·636b·6167·6573·270a··facts.packages'.000a6240:·2d20·2722·6175·6469·7422·2069·6e20·616e··-·'"audit"·in·an
 000a6250:·7369·626c·655f·6661·6374·732e·7061·636b··sible_facts.pack
 000a6260:·6167·6573·270a·2020·2d20·616e·7369·626c··ages'.··-·ansibl
 000a6270:·655f·7669·7274·7561·6c69·7a61·7469·6f6e··e_virtualization
 000a6280:·5f74·7970·6520·6e6f·7420·696e·205b·2264··_type·not·in·["d
 000a6290:·6f63·6b65·7222·2c20·226c·7863·222c·2022··ocker",·"lxc",·"
 000a62a0:·6f70·656e·767a·222c·2022·706f·646d·616e··openvz",·"podman
 000a62b0:·222c·2022·636f·6e74·6169·6e65·7222·5d0a··",·"container"].
000a62c0:·2020·2d20·6175·6469·745f·6172·6368·203d····-·audit_arch·=000a62c0:·2020·2d20·6175·6469·745f·6172·6368·203d····-·audit_arch·=
000a62d0:·3d20·2262·3634·220a·2020·7461·6773·3a0a··=·"b64".··tags:.000a62d0:·3d20·2262·3634·220a·2020·7461·6773·3a0a··=·"b64".··tags:.
000a62e0:·2020·2d20·434a·4953·2d35·2e34·2e31·2e31····-·CJIS-5.4.1.1000a62e0:·2020·2d20·434a·4953·2d35·2e34·2e31·2e31····-·CJIS-5.4.1.1
000a62f0:·0a20·202d·204e·4953·542d·3830·302d·3137··.··-·NIST-800-17000a62f0:·0a20·202d·204e·4953·542d·3830·302d·3137··.··-·NIST-800-17
000a6300:·312d·332e·312e·370a·2020·2d20·4e49·5354··1-3.1.7.··-·NIST000a6300:·312d·332e·312e·370a·2020·2d20·4e49·5354··1-3.1.7.··-·NIST
000a6310:·2d38·3030·2d35·332d·4143·2d36·2839·290a··-800-53-AC-6(9).000a6310:·2d38·3030·2d35·332d·4143·2d36·2839·290a··-800-53-AC-6(9).
000a6320:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-000a6320:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-
Offset 43403, 22 lines modifiedOffset 43403, 22 lines modified
000a98a0:·6565·6465·640a·2020·2d20·7265·7374·7269··eeded.··-·restri000a98a0:·6565·6465·640a·2020·2d20·7265·7374·7269··eeded.··-·restri
000a98b0:·6374·5f73·7472·6174·6567·790a·0a2d·206e··ct_strategy..-·n000a98b0:·6374·5f73·7472·6174·6567·790a·0a2d·206e··ct_strategy..-·n
000a98c0:·616d·653a·2053·6574·2061·7263·6869·7465··ame:·Set·archite000a98c0:·616d·653a·2053·6574·2061·7263·6869·7465··ame:·Set·archite
000a98d0:·6374·7572·6520·666f·7220·6175·6469·7420··cture·for·audit·000a98d0:·6374·7572·6520·666f·7220·6175·6469·7420··cture·for·audit·
000a98e0:·7461·736b·730a·2020·7365·745f·6661·6374··tasks.··set_fact000a98e0:·7461·736b·730a·2020·7365·745f·6661·6374··tasks.··set_fact
000a98f0:·3a0a·2020·2020·6175·6469·745f·6172·6368··:.····audit_arch000a98f0:·3a0a·2020·2020·6175·6469·745f·6172·6368··:.····audit_arch
000a9900:·3a20·6236·340a·2020·7768·656e·3a0a·2020··:·b64.··when:.··000a9900:·3a20·6236·340a·2020·7768·656e·3a0a·2020··:·b64.··when:.··
000a9910:·2d20·616e·7369·626c·655f·7669·7274·7561··-·ansible_virtua 
000a9920:·6c69·7a61·7469·6f6e·5f74·7970·6520·6e6f··lization_type·no 
000a9930:·7420·696e·205b·2264·6f63·6b65·7222·2c20··t·in·["docker",· 
000a9940:·226c·7863·222c·2022·6f70·656e·767a·222c··"lxc",·"openvz", 
000a9950:·2022·706f·646d·616e·222c·2022·636f·6e74···"podman",·"cont 
000a9960:·6169·6e65·7222·5d0a·2020·2d20·2722·6175··ainer"].··-·'"au 
000a9970:·6469·7422·2069·6e20·616e·7369·626c·655f··dit"·in·ansible_ 
000a9980:·6661·6374·732e·7061·636b·6167·6573·270a··facts.packages'.000a9910:·2d20·2722·6175·6469·7422·2069·6e20·616e··-·'"audit"·in·an
 000a9920:·7369·626c·655f·6661·6374·732e·7061·636b··sible_facts.pack
 000a9930:·6167·6573·270a·2020·2d20·616e·7369·626c··ages'.··-·ansibl
 000a9940:·655f·7669·7274·7561·6c69·7a61·7469·6f6e··e_virtualization
 000a9950:·5f74·7970·6520·6e6f·7420·696e·205b·2264··_type·not·in·["d
 000a9960:·6f63·6b65·7222·2c20·226c·7863·222c·2022··ocker",·"lxc",·"
Max diff block lines reached; 77388/86626 bytes (89.34%) of diff not shown.
25.5 KB
html2text {}
    
Offset 40, 15 lines modifiedOffset 40, 15 lines modified
40 *****·Profile·Information·*****40 *****·Profile·Information·*****
41 Profile·Title·CIS·Benchmark·for·Alibaba·Cloud·Linux·3·for·Level·241 Profile·Title·CIS·Benchmark·for·Alibaba·Cloud·Linux·3·for·Level·2
42 Profile·ID····xccdf_org.ssgproject.content_profile_cis42 Profile·ID····xccdf_org.ssgproject.content_profile_cis
43 ***·CPE·Platforms·***43 ***·CPE·Platforms·***
44 ····*·cpe:/o:alinux:alibaba_cloud_linux:344 ····*·cpe:/o:alinux:alibaba_cloud_linux:3
45 *****·Revision·History·*****45 *****·Revision·History·*****
46 Current·version:·0.1.6546 Current·version:·0.1.65
47 ····*·draft·(as·of·2024-01-14)47 ····*·draft·(as·of·2025-02-15)
48 *****·Table·of·Contents·*****48 *****·Table·of·Contents·*****
49 ···1.·System_Settings49 ···1.·System_Settings
50 ·········1.·Installing_and_Maintaining_Software50 ·········1.·Installing_and_Maintaining_Software
51 ·········2.·Account_and_Access_Control51 ·········2.·Account_and_Access_Control
52 ·········3.·System_Accounting_with_auditd52 ·········3.·System_Accounting_with_auditd
53 ·········4.·GRUB2_bootloader_configuration53 ·········4.·GRUB2_bootloader_configuration
54 ·········5.·Configure_Syslog54 ·········5.·Configure_Syslog
Offset 3024, 16 lines modifiedOffset 3024, 16 lines modified
3024 ··-·no_reboot_needed3024 ··-·no_reboot_needed
3025 ··-·restrict_strategy3025 ··-·restrict_strategy
  
3026 -·name:·Set·architecture·for·audit·tasks3026 -·name:·Set·architecture·for·audit·tasks
3027 ··set_fact:3027 ··set_fact:
3028 ····audit_arch:·b643028 ····audit_arch:·b64
3029 ··when:3029 ··when:
3030 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3031 ··-·'"audit"·in·ansible_facts.packages'3030 ··-·'"audit"·in·ansible_facts.packages'
 3031 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3032 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture3032 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
3033 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"3033 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
3034 ··tags:3034 ··tags:
3035 ··-·CJIS-5.4.1.13035 ··-·CJIS-5.4.1.1
3036 ··-·NIST-800-171-3.1.73036 ··-·NIST-800-171-3.1.7
3037 ··-·NIST-800-53-AC-6(9)3037 ··-·NIST-800-53-AC-6(9)
3038 ··-·NIST-800-53-AU-12(c)3038 ··-·NIST-800-53-AU-12(c)
Offset 3166, 16 lines modifiedOffset 3166, 16 lines modified
3166 ······path:·'{{·audit_file·}}'3166 ······path:·'{{·audit_file·}}'
3167 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_time_rules3167 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_time_rules
3168 ······create:·true3168 ······create:·true
3169 ······mode:·o-rwx3169 ······mode:·o-rwx
3170 ······state:·present3170 ······state:·present
3171 ····when:·syscalls_found·|·length·==·03171 ····when:·syscalls_found·|·length·==·0
3172 ··when:3172 ··when:
3173 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3174 ··-·'"audit"·in·ansible_facts.packages'3173 ··-·'"audit"·in·ansible_facts.packages'
 3174 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3175 ··tags:3175 ··tags:
3176 ··-·CJIS-5.4.1.13176 ··-·CJIS-5.4.1.1
3177 ··-·NIST-800-171-3.1.73177 ··-·NIST-800-171-3.1.7
3178 ··-·NIST-800-53-AC-6(9)3178 ··-·NIST-800-53-AC-6(9)
3179 ··-·NIST-800-53-AU-12(c)3179 ··-·NIST-800-53-AU-12(c)
3180 ··-·NIST-800-53-AU-2(d)3180 ··-·NIST-800-53-AU-2(d)
3181 ··-·NIST-800-53-CM-6(a)3181 ··-·NIST-800-53-CM-6(a)
Offset 3305, 16 lines modifiedOffset 3305, 16 lines modified
3305 ······path:·'{{·audit_file·}}'3305 ······path:·'{{·audit_file·}}'
3306 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_time_rules3306 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_time_rules
3307 ······create:·true3307 ······create:·true
3308 ······mode:·o-rwx3308 ······mode:·o-rwx
3309 ······state:·present3309 ······state:·present
3310 ····when:·syscalls_found·|·length·==·03310 ····when:·syscalls_found·|·length·==·0
3311 ··when:3311 ··when:
3312 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3313 ··-·'"audit"·in·ansible_facts.packages'3312 ··-·'"audit"·in·ansible_facts.packages'
 3313 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3314 ··-·audit_arch·==·"b64"3314 ··-·audit_arch·==·"b64"
3315 ··tags:3315 ··tags:
3316 ··-·CJIS-5.4.1.13316 ··-·CJIS-5.4.1.1
3317 ··-·NIST-800-171-3.1.73317 ··-·NIST-800-171-3.1.7
3318 ··-·NIST-800-53-AC-6(9)3318 ··-·NIST-800-53-AC-6(9)
3319 ··-·NIST-800-53-AU-12(c)3319 ··-·NIST-800-53-AU-12(c)
3320 ··-·NIST-800-53-AU-2(d)3320 ··-·NIST-800-53-AU-2(d)
Offset 3380, 16 lines modifiedOffset 3380, 16 lines modified
3380 ··-·no_reboot_needed3380 ··-·no_reboot_needed
3381 ··-·restrict_strategy3381 ··-·restrict_strategy
  
3382 -·name:·Set·architecture·for·audit·tasks3382 -·name:·Set·architecture·for·audit·tasks
3383 ··set_fact:3383 ··set_fact:
3384 ····audit_arch:·b643384 ····audit_arch:·b64
3385 ··when:3385 ··when:
3386 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3387 ··-·'"audit"·in·ansible_facts.packages'3386 ··-·'"audit"·in·ansible_facts.packages'
 3387 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3388 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture3388 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
3389 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"3389 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
3390 ··tags:3390 ··tags:
3391 ··-·CJIS-5.4.1.13391 ··-·CJIS-5.4.1.1
3392 ··-·NIST-800-171-3.1.73392 ··-·NIST-800-171-3.1.7
3393 ··-·NIST-800-53-AC-6(9)3393 ··-·NIST-800-53-AC-6(9)
3394 ··-·NIST-800-53-AU-12(c)3394 ··-·NIST-800-53-AU-12(c)
Offset 3518, 16 lines modifiedOffset 3518, 16 lines modified
3518 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·a0=0x0·-F3518 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·a0=0x0·-F
3519 ········key=time-change3519 ········key=time-change
3520 ······create:·true3520 ······create:·true
3521 ······mode:·o-rwx3521 ······mode:·o-rwx
3522 ······state:·present3522 ······state:·present
3523 ····when:·syscalls_found·|·length·==·03523 ····when:·syscalls_found·|·length·==·0
3524 ··when:3524 ··when:
3525 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3526 ··-·'"audit"·in·ansible_facts.packages'3525 ··-·'"audit"·in·ansible_facts.packages'
 3526 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3527 ··tags:3527 ··tags:
3528 ··-·CJIS-5.4.1.13528 ··-·CJIS-5.4.1.1
3529 ··-·NIST-800-171-3.1.73529 ··-·NIST-800-171-3.1.7
3530 ··-·NIST-800-53-AC-6(9)3530 ··-·NIST-800-53-AC-6(9)
3531 ··-·NIST-800-53-AU-12(c)3531 ··-·NIST-800-53-AU-12(c)
3532 ··-·NIST-800-53-AU-2(d)3532 ··-·NIST-800-53-AU-2(d)
3533 ··-·NIST-800-53-CM-6(a)3533 ··-·NIST-800-53-CM-6(a)
Offset 3654, 16 lines modifiedOffset 3654, 16 lines modified
3654 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·a0=0x0·-F3654 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·a0=0x0·-F
3655 ········key=time-change3655 ········key=time-change
3656 ······create:·true3656 ······create:·true
3657 ······mode:·o-rwx3657 ······mode:·o-rwx
3658 ······state:·present3658 ······state:·present
3659 ····when:·syscalls_found·|·length·==·03659 ····when:·syscalls_found·|·length·==·0
3660 ··when:3660 ··when:
3661 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3662 ··-·'"audit"·in·ansible_facts.packages'3661 ··-·'"audit"·in·ansible_facts.packages'
 3662 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3663 ··-·audit_arch·==·"b64"3663 ··-·audit_arch·==·"b64"
3664 ··tags:3664 ··tags:
3665 ··-·CJIS-5.4.1.13665 ··-·CJIS-5.4.1.1
3666 ··-·NIST-800-171-3.1.73666 ··-·NIST-800-171-3.1.7
3667 ··-·NIST-800-53-AC-6(9)3667 ··-·NIST-800-53-AC-6(9)
3668 ··-·NIST-800-53-AU-12(c)3668 ··-·NIST-800-53-AU-12(c)
3669 ··-·NIST-800-53-AU-2(d)3669 ··-·NIST-800-53-AU-2(d)
Offset 3851, 16 lines modifiedOffset 3851, 16 lines modified
3851 ······path:·'{{·audit_file·}}'3851 ······path:·'{{·audit_file·}}'
3852 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_time_rules3852 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_time_rules
3853 ······create:·true3853 ······create:·true
Max diff block lines reached; 21391/26041 bytes (82.14%) of diff not shown.
23.8 KB
./usr/share/doc/ssg-nondebian/ssg-alinux3-guide-cis_l1.html
    
Offset 14295, 16 lines modifiedOffset 14295, 16 lines modified
00037d60:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>00037d60:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>
00037d70:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi00037d70:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi
00037d80:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.00037d80:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.
00037d90:·3635·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··65</strong></p><00037d90:·3635·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··65</strong></p><
00037da0:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d00037da0:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d
00037db0:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··00037db0:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··
00037dc0:·2020·2020·2020·2020·2020·2020·2020·2020··················00037dc0:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037dd0:·2020·2861·7320·6f66·2032·3032·342d·3031····(as·of·2024-0100037dd0:·2020·2861·7320·6f66·2032·3032·352d·3032····(as·of·2025-02
00037de0:·2d31·3429·0a20·2020·2020·2020·2020·2020··-14).···········00037de0:·2d31·3529·0a20·2020·2020·2020·2020·2020··-15).···········
00037df0:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><00037df0:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><
00037e00:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o00037e00:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o
00037e10:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><00037e10:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><
00037e20:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="00037e20:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="
00037e30:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr00037e30:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr
00037e40:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr00037e40:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr
00037e50:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst00037e50:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst
Offset 40145, 21 lines modifiedOffset 40145, 21 lines modified
0009cd00:·6573·7420·666f·7220·6578·6973·7465·6e63··est·for·existenc0009cd00:·6573·7420·666f·7220·6578·6973·7465·6e63··est·for·existenc
0009cd10:·6520·2f62·6f6f·742f·6772·7562·322f·6772··e·/boot/grub2/gr0009cd10:·6520·2f62·6f6f·742f·6772·7562·322f·6772··e·/boot/grub2/gr
0009cd20:·7562·2e63·6667·0a20·2073·7461·743a·0a20··ub.cfg.··stat:.·0009cd20:·7562·2e63·6667·0a20·2073·7461·743a·0a20··ub.cfg.··stat:.·
0009cd30:·2020·2070·6174·683a·202f·626f·6f74·2f67·····path:·/boot/g0009cd30:·2020·2070·6174·683a·202f·626f·6f74·2f67·····path:·/boot/g
0009cd40:·7275·6232·2f67·7275·622e·6366·670a·2020··rub2/grub.cfg.··0009cd40:·7275·6232·2f67·7275·622e·6366·670a·2020··rub2/grub.cfg.··
0009cd50:·7265·6769·7374·6572·3a20·6669·6c65·5f65··register:·file_e0009cd50:·7265·6769·7374·6572·3a20·6669·6c65·5f65··register:·file_e
0009cd60:·7869·7374·730a·2020·7768·656e·3a0a·2020··xists.··when:.··0009cd60:·7869·7374·730a·2020·7768·656e·3a0a·2020··xists.··when:.··
0009cd70:·2d20·2722·2f62·6f6f·742f·6566·6922·2069··-·'"/boot/efi"·i 
0009cd80:·6e20·616e·7369·626c·655f·6d6f·756e·7473··n·ansible_mounts 
0009cd90:·207c·206d·6170·2861·7474·7269·6275·7465···|·map(attribute 
0009cda0:·3d22·6d6f·756e·7422·2920·7c20·6c69·7374··="mount")·|·list 
0009cdb0:·270a·2020·2d20·2722·6772·7562·322d·636f··'.··-·'"grub2-co0009cd70:·2d20·2722·6772·7562·322d·636f·6d6d·6f6e··-·'"grub2-common
0009cdc0:·6d6d·6f6e·2220·696e·2061·6e73·6962·6c65··mmon"·in·ansible0009cd80:·2220·696e·2061·6e73·6962·6c65·5f66·6163··"·in·ansible_fac
0009cdd0:·5f66·6163·7473·2e70·6163·6b61·6765·7327··_facts.packages'0009cd90:·7473·2e70·6163·6b61·6765·7327·0a20·202d··ts.packages'.··-
 0009cda0:·2027·222f·626f·6f74·2f65·6669·2220·696e···'"/boot/efi"·in
 0009cdb0:·2061·6e73·6962·6c65·5f6d·6f75·6e74·7320···ansible_mounts·
 0009cdc0:·7c20·6d61·7028·6174·7472·6962·7574·653d··|·map(attribute=
 0009cdd0:·226d·6f75·6e74·2229·207c·206c·6973·7427··"mount")·|·list'
0009cde0:·0a20·202d·2061·6e73·6962·6c65·5f76·6972··.··-·ansible_vir0009cde0:·0a20·202d·2061·6e73·6962·6c65·5f76·6972··.··-·ansible_vir
0009cdf0:·7475·616c·697a·6174·696f·6e5f·7479·7065··tualization_type0009cdf0:·7475·616c·697a·6174·696f·6e5f·7479·7065··tualization_type
0009ce00:·206e·6f74·2069·6e20·5b22·646f·636b·6572···not·in·["docker0009ce00:·206e·6f74·2069·6e20·5b22·646f·636b·6572···not·in·["docker
0009ce10:·222c·2022·6c78·6322·2c20·226f·7065·6e76··",·"lxc",·"openv0009ce10:·222c·2022·6c78·6322·2c20·226f·7065·6e76··",·"lxc",·"openv
0009ce20:·7a22·2c20·2270·6f64·6d61·6e22·2c20·2263··z",·"podman",·"c0009ce20:·7a22·2c20·2270·6f64·6d61·6e22·2c20·2263··z",·"podman",·"c
0009ce30:·6f6e·7461·696e·6572·225d·0a20·2074·6167··ontainer"].··tag0009ce30:·6f6e·7461·696e·6572·225d·0a20·2074·6167··ontainer"].··tag
0009ce40:·733a·0a20·202d·2043·4a49·532d·352e·352e··s:.··-·CJIS-5.5.0009ce40:·733a·0a20·202d·2043·4a49·532d·352e·352e··s:.··-·CJIS-5.5.
Offset 40181, 21 lines modifiedOffset 40181, 21 lines modified
0009cf40:·456e·7375·7265·2067·726f·7570·206f·776e··Ensure·group·own0009cf40:·456e·7375·7265·2067·726f·7570·206f·776e··Ensure·group·own
0009cf50:·6572·2030·206f·6e20·2f62·6f6f·742f·6772··er·0·on·/boot/gr0009cf50:·6572·2030·206f·6e20·2f62·6f6f·742f·6772··er·0·on·/boot/gr
0009cf60:·7562·322f·6772·7562·2e63·6667·0a20·2066··ub2/grub.cfg.··f0009cf60:·7562·322f·6772·7562·2e63·6667·0a20·2066··ub2/grub.cfg.··f
0009cf70:·696c·653a·0a20·2020·2070·6174·683a·202f··ile:.····path:·/0009cf70:·696c·653a·0a20·2020·2070·6174·683a·202f··ile:.····path:·/
0009cf80:·626f·6f74·2f67·7275·6232·2f67·7275·622e··boot/grub2/grub.0009cf80:·626f·6f74·2f67·7275·6232·2f67·7275·622e··boot/grub2/grub.
0009cf90:·6366·670a·2020·2020·6772·6f75·703a·2027··cfg.····group:·'0009cf90:·6366·670a·2020·2020·6772·6f75·703a·2027··cfg.····group:·'
0009cfa0:·3027·0a20·2077·6865·6e3a·0a20·202d·2027··0'.··when:.··-·'0009cfa0:·3027·0a20·2077·6865·6e3a·0a20·202d·2027··0'.··when:.··-·'
0009cfb0:·222f·626f·6f74·2f65·6669·2220·696e·2061··"/boot/efi"·in·a 
0009cfc0:·6e73·6962·6c65·5f6d·6f75·6e74·7320·7c20··nsible_mounts·|· 
0009cfd0:·6d61·7028·6174·7472·6962·7574·653d·226d··map(attribute="m 
0009cfe0:·6f75·6e74·2229·207c·206c·6973·7427·0a20··ount")·|·list'.· 
0009cff0:·202d·2027·2267·7275·6232·2d63·6f6d·6d6f···-·'"grub2-commo0009cfb0:·2267·7275·6232·2d63·6f6d·6d6f·6e22·2069··"grub2-common"·i
0009d000:·6e22·2069·6e20·616e·7369·626c·655f·6661··n"·in·ansible_fa0009cfc0:·6e20·616e·7369·626c·655f·6661·6374·732e··n·ansible_facts.
0009d010:·6374·732e·7061·636b·6167·6573·270a·2020··cts.packages'.··0009cfd0:·7061·636b·6167·6573·270a·2020·2d20·2722··packages'.··-·'"
 0009cfe0:·2f62·6f6f·742f·6566·6922·2069·6e20·616e··/boot/efi"·in·an
 0009cff0:·7369·626c·655f·6d6f·756e·7473·207c·206d··sible_mounts·|·m
 0009d000:·6170·2861·7474·7269·6275·7465·3d22·6d6f··ap(attribute="mo
 0009d010:·756e·7422·2920·7c20·6c69·7374·270a·2020··unt")·|·list'.··
0009d020:·2d20·616e·7369·626c·655f·7669·7274·7561··-·ansible_virtua0009d020:·2d20·616e·7369·626c·655f·7669·7274·7561··-·ansible_virtua
0009d030:·6c69·7a61·7469·6f6e·5f74·7970·6520·6e6f··lization_type·no0009d030:·6c69·7a61·7469·6f6e·5f74·7970·6520·6e6f··lization_type·no
0009d040:·7420·696e·205b·2264·6f63·6b65·7222·2c20··t·in·["docker",·0009d040:·7420·696e·205b·2264·6f63·6b65·7222·2c20··t·in·["docker",·
0009d050:·226c·7863·222c·2022·6f70·656e·767a·222c··"lxc",·"openvz",0009d050:·226c·7863·222c·2022·6f70·656e·767a·222c··"lxc",·"openvz",
0009d060:·2022·706f·646d·616e·222c·2022·636f·6e74···"podman",·"cont0009d060:·2022·706f·646d·616e·222c·2022·636f·6e74···"podman",·"cont
0009d070:·6169·6e65·7222·5d0a·2020·2d20·6669·6c65··ainer"].··-·file0009d070:·6169·6e65·7222·5d0a·2020·2d20·6669·6c65··ainer"].··-·file
0009d080:·5f65·7869·7374·732e·7374·6174·2069·7320··_exists.stat·is·0009d080:·5f65·7869·7374·732e·7374·6174·2069·7320··_exists.stat·is·
Offset 40246, 19 lines modifiedOffset 40246, 19 lines modified
0009d350:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<0009d350:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
0009d360:·2f74·683e·3c74·643e·636f·6e66·6967·7572··/th><td>configur0009d360:·2f74·683e·3c74·643e·636f·6e66·6967·7572··/th><td>configur
0009d370:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab0009d370:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
0009d380:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#·0009d380:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#·
0009d390:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a0009d390:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a
0009d3a0:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i0009d3a0:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i
0009d3b0:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo0009d3b0:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo
 0009d3c0:·726d·730a·6966·2072·706d·202d·2d71·7569··rms.if·rpm·--qui
0009d3c0:·726d·730a·6966·205b·202d·6620·2f73·7973··rms.if·[·-f·/sys 
0009d3d0:·2f66·6972·6d77·6172·652f·6566·6920·5d20··/firmware/efi·]· 
0009d3e0:·2661·6d70·3b26·616d·703b·2072·706d·202d··&amp;&amp;·rpm·- 
0009d3f0:·2d71·7569·6574·202d·7120·6772·7562·322d··-quiet·-q·grub2-0009d3d0:·6574·202d·7120·6772·7562·322d·636f·6d6d··et·-q·grub2-comm
0009d400:·636f·6d6d·6f6e·2026·616d·703b·2661·6d70··common·&amp;&amp0009d3e0:·6f6e·2026·616d·703b·2661·6d70·3b20·5b20··on·&amp;&amp;·[·
 0009d3f0:·2d66·202f·7379·732f·6669·726d·7761·7265··-f·/sys/firmware
 0009d400:·2f65·6669·205d·2026·616d·703b·2661·6d70··/efi·]·&amp;&amp
0009d410:·3b20·7b20·5b20·2120·2d66·202f·2e64·6f63··;·{·[·!·-f·/.doc0009d410:·3b20·7b20·5b20·2120·2d66·202f·2e64·6f63··;·{·[·!·-f·/.doc
0009d420:·6b65·7265·6e76·205d·2026·616d·703b·2661··kerenv·]·&amp;&a0009d420:·6b65·7265·6e76·205d·2026·616d·703b·2661··kerenv·]·&amp;&a
0009d430:·6d70·3b20·5b20·2120·2d66·202f·7275·6e2f··mp;·[·!·-f·/run/0009d430:·6d70·3b20·5b20·2120·2d66·202f·7275·6e2f··mp;·[·!·-f·/run/
0009d440:·2e63·6f6e·7461·696e·6572·656e·7620·5d3b··.containerenv·];0009d440:·2e63·6f6e·7461·696e·6572·656e·7620·5d3b··.containerenv·];
0009d450:·207d·3b20·7468·656e·0a0a·6368·6772·7020···};·then..chgrp·0009d450:·207d·3b20·7468·656e·0a0a·6368·6772·7020···};·then..chgrp·
0009d460:·3020·2f62·6f6f·742f·6772·7562·322f·6772··0·/boot/grub2/gr0009d460:·3020·2f62·6f6f·742f·6772·7562·322f·6772··0·/boot/grub2/gr
0009d470:·7562·2e63·6667·0a0a·656c·7365·0a20·2020··ub.cfg..else.···0009d470:·7562·2e63·6667·0a0a·656c·7365·0a20·2020··ub.cfg..else.···
Offset 40637, 22 lines modifiedOffset 40637, 22 lines modified
0009ebc0:·2d20·6e61·6d65·3a20·5465·7374·2066·6f72··-·name:·Test·for0009ebc0:·2d20·6e61·6d65·3a20·5465·7374·2066·6f72··-·name:·Test·for
0009ebd0:·2065·7869·7374·656e·6365·202f·626f·6f74···existence·/boot0009ebd0:·2065·7869·7374·656e·6365·202f·626f·6f74···existence·/boot
0009ebe0:·2f67·7275·6232·2f67·7275·622e·6366·670a··/grub2/grub.cfg.0009ebe0:·2f67·7275·6232·2f67·7275·622e·6366·670a··/grub2/grub.cfg.
0009ebf0:·2020·7374·6174·3a0a·2020·2020·7061·7468····stat:.····path0009ebf0:·2020·7374·6174·3a0a·2020·2020·7061·7468····stat:.····path
0009ec00:·3a20·2f62·6f6f·742f·6772·7562·322f·6772··:·/boot/grub2/gr0009ec00:·3a20·2f62·6f6f·742f·6772·7562·322f·6772··:·/boot/grub2/gr
0009ec10:·7562·2e63·6667·0a20·2072·6567·6973·7465··ub.cfg.··registe0009ec10:·7562·2e63·6667·0a20·2072·6567·6973·7465··ub.cfg.··registe
0009ec20:·723a·2066·696c·655f·6578·6973·7473·0a20··r:·file_exists.·0009ec20:·723a·2066·696c·655f·6578·6973·7473·0a20··r:·file_exists.·
0009ec30:·2077·6865·6e3a·0a20·202d·2027·222f·626f···when:.··-·'"/bo0009ec30:·2077·6865·6e3a·0a20·202d·2027·2267·7275···when:.··-·'"gru
0009ec40:·6f74·2f65·6669·2220·696e·2061·6e73·6962··ot/efi"·in·ansib 
0009ec50:·6c65·5f6d·6f75·6e74·7320·7c20·6d61·7028··le_mounts·|·map( 
0009ec60:·6174·7472·6962·7574·653d·226d·6f75·6e74··attribute="mount 
0009ec70:·2229·207c·206c·6973·7427·0a20·202d·2027··")·|·list'.··-·' 
0009ec80:·2267·7275·6232·2d63·6f6d·6d6f·6e22·2069··"grub2-common"·i0009ec40:·6232·2d63·6f6d·6d6f·6e22·2069·6e20·616e··b2-common"·in·an
0009ec90:·6e20·616e·7369·626c·655f·6661·6374·732e··n·ansible_facts.0009ec50:·7369·626c·655f·6661·6374·732e·7061·636b··sible_facts.pack
0009eca0:·7061·636b·6167·6573·270a·2020·2d20·616e··packages'.··-·an0009ec60:·6167·6573·270a·2020·2d20·2722·2f62·6f6f··ages'.··-·'"/boo
 0009ec70:·742f·6566·6922·2069·6e20·616e·7369·626c··t/efi"·in·ansibl
 0009ec80:·655f·6d6f·756e·7473·207c·206d·6170·2861··e_mounts·|·map(a
 0009ec90:·7474·7269·6275·7465·3d22·6d6f·756e·7422··ttribute="mount"
 0009eca0:·2920·7c20·6c69·7374·270a·2020·2d20·616e··)·|·list'.··-·an
0009ecb0:·7369·626c·655f·7669·7274·7561·6c69·7a61··sible_virtualiza0009ecb0:·7369·626c·655f·7669·7274·7561·6c69·7a61··sible_virtualiza
0009ecc0:·7469·6f6e·5f74·7970·6520·6e6f·7420·696e··tion_type·not·in0009ecc0:·7469·6f6e·5f74·7970·6520·6e6f·7420·696e··tion_type·not·in
0009ecd0:·205b·2264·6f63·6b65·7222·2c20·226c·7863···["docker",·"lxc0009ecd0:·205b·2264·6f63·6b65·7222·2c20·226c·7863···["docker",·"lxc
0009ece0:·222c·2022·6f70·656e·767a·222c·2022·706f··",·"openvz",·"po0009ece0:·222c·2022·6f70·656e·767a·222c·2022·706f··",·"openvz",·"po
0009ecf0:·646d·616e·222c·2022·636f·6e74·6169·6e65··dman",·"containe0009ecf0:·646d·616e·222c·2022·636f·6e74·6169·6e65··dman",·"containe
0009ed00:·7222·5d0a·2020·7461·6773·3a0a·2020·2d20··r"].··tags:.··-·0009ed00:·7222·5d0a·2020·7461·6773·3a0a·2020·2d20··r"].··tags:.··-·
0009ed10:·434a·4953·2d35·2e35·2e32·2e32·0a20·202d··CJIS-5.5.2.2.··-0009ed10:·434a·4953·2d35·2e35·2e32·2e32·0a20·202d··CJIS-5.5.2.2.··-
Offset 40672, 22 lines modifiedOffset 40672, 22 lines modified
0009edf0:·6f6f·745f·6e65·6564·6564·0a0a·2d20·6e61··oot_needed..-·na0009edf0:·6f6f·745f·6e65·6564·6564·0a0a·2d20·6e61··oot_needed..-·na
0009ee00:·6d65·3a20·456e·7375·7265·206f·776e·6572··me:·Ensure·owner0009ee00:·6d65·3a20·456e·7375·7265·206f·776e·6572··me:·Ensure·owner
0009ee10:·2030·206f·6e20·2f62·6f6f·742f·6772·7562···0·on·/boot/grub0009ee10:·2030·206f·6e20·2f62·6f6f·742f·6772·7562···0·on·/boot/grub
0009ee20:·322f·6772·7562·2e63·6667·0a20·2066·696c··2/grub.cfg.··fil0009ee20:·322f·6772·7562·2e63·6667·0a20·2066·696c··2/grub.cfg.··fil
0009ee30:·653a·0a20·2020·2070·6174·683a·202f·626f··e:.····path:·/bo0009ee30:·653a·0a20·2020·2070·6174·683a·202f·626f··e:.····path:·/bo
0009ee40:·6f74·2f67·7275·6232·2f67·7275·622e·6366··ot/grub2/grub.cf0009ee40:·6f74·2f67·7275·6232·2f67·7275·622e·6366··ot/grub2/grub.cf
0009ee50:·670a·2020·2020·6f77·6e65·723a·2027·3027··g.····owner:·'0'0009ee50:·670a·2020·2020·6f77·6e65·723a·2027·3027··g.····owner:·'0'
0009ee60:·0a20·2077·6865·6e3a·0a20·202d·2027·222f··.··when:.··-·'"/0009ee60:·0a20·2077·6865·6e3a·0a20·202d·2027·2267··.··when:.··-·'"g
Max diff block lines reached; 7694/18338 bytes (41.96%) of diff not shown.
5.74 KB
html2text {}
    
Offset 40, 15 lines modifiedOffset 40, 15 lines modified
40 *****·Profile·Information·*****40 *****·Profile·Information·*****
41 Profile·Title·CIS·Benchmark·for·Alibaba·Cloud·Linux·3·for·Level·141 Profile·Title·CIS·Benchmark·for·Alibaba·Cloud·Linux·3·for·Level·1
42 Profile·ID····xccdf_org.ssgproject.content_profile_cis_l142 Profile·ID····xccdf_org.ssgproject.content_profile_cis_l1
43 ***·CPE·Platforms·***43 ***·CPE·Platforms·***
44 ····*·cpe:/o:alinux:alibaba_cloud_linux:344 ····*·cpe:/o:alinux:alibaba_cloud_linux:3
45 *****·Revision·History·*****45 *****·Revision·History·*****
46 Current·version:·0.1.6546 Current·version:·0.1.65
47 ····*·draft·(as·of·2024-01-14)47 ····*·draft·(as·of·2025-02-15)
48 *****·Table·of·Contents·*****48 *****·Table·of·Contents·*****
49 ···1.·System_Settings49 ···1.·System_Settings
50 ·········1.·Installing_and_Maintaining_Software50 ·········1.·Installing_and_Maintaining_Software
51 ·········2.·Account_and_Access_Control51 ·········2.·Account_and_Access_Control
52 ·········3.·GRUB2_bootloader_configuration52 ·········3.·GRUB2_bootloader_configuration
53 ·········4.·Configure_Syslog53 ·········4.·Configure_Syslog
54 ·········5.·Network_Configuration_and_Firewalls54 ·········5.·Network_Configuration_and_Firewalls
Offset 3075, 16 lines modifiedOffset 3075, 16 lines modified
3075 ··-·no_reboot_needed3075 ··-·no_reboot_needed
  
3076 -·name:·Test·for·existence·/boot/grub2/grub.cfg3076 -·name:·Test·for·existence·/boot/grub2/grub.cfg
3077 ··stat:3077 ··stat:
3078 ····path:·/boot/grub2/grub.cfg3078 ····path:·/boot/grub2/grub.cfg
3079 ··register:·file_exists3079 ··register:·file_exists
3080 ··when:3080 ··when:
3081 ··-·'"/boot/efi"·in·ansible_mounts·|·map(attribute="mount")·|·list' 
3082 ··-·'"grub2-common"·in·ansible_facts.packages'3081 ··-·'"grub2-common"·in·ansible_facts.packages'
 3082 ··-·'"/boot/efi"·in·ansible_mounts·|·map(attribute="mount")·|·list'
3083 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3083 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3084 ··tags:3084 ··tags:
3085 ··-·CJIS-5.5.2.23085 ··-·CJIS-5.5.2.2
3086 ··-·NIST-800-171-3.4.53086 ··-·NIST-800-171-3.4.5
3087 ··-·NIST-800-53-AC-6(1)3087 ··-·NIST-800-53-AC-6(1)
3088 ··-·NIST-800-53-CM-6(a)3088 ··-·NIST-800-53-CM-6(a)
3089 ··-·PCI-DSS-Req-7.13089 ··-·PCI-DSS-Req-7.1
Offset 3096, 16 lines modifiedOffset 3096, 16 lines modified
3096 ··-·no_reboot_needed3096 ··-·no_reboot_needed
  
3097 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg3097 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
3098 ··file:3098 ··file:
3099 ····path:·/boot/grub2/grub.cfg3099 ····path:·/boot/grub2/grub.cfg
3100 ····group:·'0'3100 ····group:·'0'
3101 ··when:3101 ··when:
3102 ··-·'"/boot/efi"·in·ansible_mounts·|·map(attribute="mount")·|·list' 
3103 ··-·'"grub2-common"·in·ansible_facts.packages'3102 ··-·'"grub2-common"·in·ansible_facts.packages'
 3103 ··-·'"/boot/efi"·in·ansible_mounts·|·map(attribute="mount")·|·list'
3104 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3104 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3105 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists3105 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists
3106 ··tags:3106 ··tags:
3107 ··-·CJIS-5.5.2.23107 ··-·CJIS-5.5.2.2
3108 ··-·NIST-800-171-3.4.53108 ··-·NIST-800-171-3.4.5
3109 ··-·NIST-800-53-AC-6(1)3109 ··-·NIST-800-53-AC-6(1)
3110 ··-·NIST-800-53-CM-6(a)3110 ··-·NIST-800-53-CM-6(a)
Offset 3117, 15 lines modifiedOffset 3117, 15 lines modified
3117 ··-·medium_severity3117 ··-·medium_severity
3118 ··-·no_reboot_needed3118 ··-·no_reboot_needed
3119 Remediation_Shell_script_⇲3119 Remediation_Shell_script_⇲
3120 Complexity:·low3120 Complexity:·low
3121 Disruption:·low3121 Disruption:·low
3122 Strategy:···configure3122 Strategy:···configure
3123 #·Remediation·is·applicable·only·in·certain·platforms3123 #·Remediation·is·applicable·only·in·certain·platforms
3124 if·[·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/3124 if·rpm·--quiet·-q·grub2-common·&&·[·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/
3125 run/.containerenv·];·};·then3125 run/.containerenv·];·};·then
  
3126 chgrp·0·/boot/grub2/grub.cfg3126 chgrp·0·/boot/grub2/grub.cfg
  
3127 else3127 else
3128 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'3128 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
3129 fi3129 fi
Offset 3162, 16 lines modifiedOffset 3162, 16 lines modified
3162 ··-·no_reboot_needed3162 ··-·no_reboot_needed
  
3163 -·name:·Test·for·existence·/boot/grub2/grub.cfg3163 -·name:·Test·for·existence·/boot/grub2/grub.cfg
3164 ··stat:3164 ··stat:
3165 ····path:·/boot/grub2/grub.cfg3165 ····path:·/boot/grub2/grub.cfg
3166 ··register:·file_exists3166 ··register:·file_exists
3167 ··when:3167 ··when:
3168 ··-·'"/boot/efi"·in·ansible_mounts·|·map(attribute="mount")·|·list' 
3169 ··-·'"grub2-common"·in·ansible_facts.packages'3168 ··-·'"grub2-common"·in·ansible_facts.packages'
 3169 ··-·'"/boot/efi"·in·ansible_mounts·|·map(attribute="mount")·|·list'
3170 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3170 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3171 ··tags:3171 ··tags:
3172 ··-·CJIS-5.5.2.23172 ··-·CJIS-5.5.2.2
3173 ··-·NIST-800-171-3.4.53173 ··-·NIST-800-171-3.4.5
3174 ··-·NIST-800-53-AC-6(1)3174 ··-·NIST-800-53-AC-6(1)
3175 ··-·NIST-800-53-CM-6(a)3175 ··-·NIST-800-53-CM-6(a)
3176 ··-·PCI-DSS-Req-7.13176 ··-·PCI-DSS-Req-7.1
Offset 3183, 16 lines modifiedOffset 3183, 16 lines modified
3183 ··-·no_reboot_needed3183 ··-·no_reboot_needed
  
3184 -·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg3184 -·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg
3185 ··file:3185 ··file:
3186 ····path:·/boot/grub2/grub.cfg3186 ····path:·/boot/grub2/grub.cfg
3187 ····owner:·'0'3187 ····owner:·'0'
3188 ··when:3188 ··when:
3189 ··-·'"/boot/efi"·in·ansible_mounts·|·map(attribute="mount")·|·list' 
3190 ··-·'"grub2-common"·in·ansible_facts.packages'3189 ··-·'"grub2-common"·in·ansible_facts.packages'
 3190 ··-·'"/boot/efi"·in·ansible_mounts·|·map(attribute="mount")·|·list'
3191 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3191 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3192 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists3192 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists
3193 ··tags:3193 ··tags:
3194 ··-·CJIS-5.5.2.23194 ··-·CJIS-5.5.2.2
3195 ··-·NIST-800-171-3.4.53195 ··-·NIST-800-171-3.4.5
3196 ··-·NIST-800-53-AC-6(1)3196 ··-·NIST-800-53-AC-6(1)
3197 ··-·NIST-800-53-CM-6(a)3197 ··-·NIST-800-53-CM-6(a)
Offset 3204, 15 lines modifiedOffset 3204, 15 lines modified
3204 ··-·medium_severity3204 ··-·medium_severity
3205 ··-·no_reboot_needed3205 ··-·no_reboot_needed
3206 Remediation_Shell_script_⇲3206 Remediation_Shell_script_⇲
3207 Complexity:·low3207 Complexity:·low
3208 Disruption:·low3208 Disruption:·low
3209 Strategy:···configure3209 Strategy:···configure
3210 #·Remediation·is·applicable·only·in·certain·platforms3210 #·Remediation·is·applicable·only·in·certain·platforms
3211 if·[·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/3211 if·rpm·--quiet·-q·grub2-common·&&·[·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/
3212 run/.containerenv·];·};·then3212 run/.containerenv·];·};·then
  
3213 chown·0·/boot/grub2/grub.cfg3213 chown·0·/boot/grub2/grub.cfg
  
3214 else3214 else
3215 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'3215 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
3216 fi3216 fi
Offset 3247, 16 lines modifiedOffset 3247, 16 lines modified
3247 ··-·no_reboot_needed3247 ··-·no_reboot_needed
  
3248 -·name:·Test·for·existence·/boot/grub2/grub.cfg3248 -·name:·Test·for·existence·/boot/grub2/grub.cfg
3249 ··stat:3249 ··stat:
3250 ····path:·/boot/grub2/grub.cfg3250 ····path:·/boot/grub2/grub.cfg
3251 ··register:·file_exists3251 ··register:·file_exists
3252 ··when:3252 ··when:
Max diff block lines reached; 1501/5852 bytes (25.65%) of diff not shown.
4.68 KB
./usr/share/doc/ssg-nondebian/ssg-alinux3-guide-standard.html
    
Offset 14290, 15 lines modifiedOffset 14290, 15 lines modified
00037d10:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v00037d10:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v
00037d20:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>00037d20:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>
00037d30:·302e·312e·3635·3c2f·7374·726f·6e67·3e3c··0.1.65</strong><00037d30:·302e·312e·3635·3c2f·7374·726f·6e67·3e3c··0.1.65</strong><
00037d40:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro00037d40:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro
00037d50:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong00037d50:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong
00037d60:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············00037d60:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············
00037d70:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·20200037d70:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·202
00037d80:·342d·3031·2d31·3429·0a20·2020·2020·2020··4-01-14).·······00037d80:·352d·3032·2d31·3529·0a20·2020·2020·2020··5-02-15).·······
00037d90:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></00037d90:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></
00037da0:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab00037da0:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab
00037db0:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</00037db0:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</
00037dc0:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr00037dc0:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr
00037dd0:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s00037dd0:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s
00037de0:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten00037de0:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten
00037df0:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">00037df0:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">
Offset 22916, 20 lines modifiedOffset 22916, 20 lines modified
00059830:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll00059830:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
00059840:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i00059840:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
00059850:·643d·2269·646d·3134·3333·3722·3e3c·7072··d="idm14337"><pr00059850:·643d·2269·646d·3134·3333·3722·3e3c·7072··d="idm14337"><pr
00059860:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi00059860:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi
00059870:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica00059870:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica
00059880:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert00059880:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert
00059890:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if00059890:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if
 000598a0:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q·
 000598b0:·6175·6469·7420·2661·6d70·3b26·616d·703b··audit·&amp;&amp;
000598a0:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker000598c0:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker
000598b0:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp;000598d0:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp;
000598c0:·205b·2021·202d·6620·2f72·756e·2f2e·636f···[·!·-f·/run/.co000598e0:·205b·2021·202d·6620·2f72·756e·2f2e·636f···[·!·-f·/run/.co
000598d0:·6e74·6169·6e65·7265·6e76·205d·2026·616d··ntainerenv·]·&am000598f0:·6e74·6169·6e65·7265·6e76·205d·3b20·7468··ntainerenv·];·th
000598e0:·703b·2661·6d70·3b20·7270·6d20·2d2d·7175··p;&amp;·rpm·--qu 
000598f0:·6965·7420·2d71·2061·7564·6974·3b20·7468··iet·-q·audit;·th 
00059900:·656e·0a0a·2320·4669·7273·7420·7065·7266··en..#·First·perf00059900:·656e·0a0a·2320·4669·7273·7420·7065·7266··en..#·First·perf
00059910:·6f72·6d20·7468·6520·7265·6d65·6469·6174··orm·the·remediat00059910:·6f72·6d20·7468·6520·7265·6d65·6469·6174··orm·the·remediat
00059920:·696f·6e20·6f66·2074·6865·2073·7973·6361··ion·of·the·sysca00059920:·696f·6e20·6f66·2074·6865·2073·7973·6361··ion·of·the·sysca
00059930:·6c6c·2072·756c·650a·2320·5265·7472·6965··ll·rule.#·Retrie00059930:·6c6c·2072·756c·650a·2320·5265·7472·6965··ll·rule.#·Retrie
00059940:·7665·2068·6172·6477·6172·6520·6172·6368··ve·hardware·arch00059940:·7665·2068·6172·6477·6172·6520·6172·6368··ve·hardware·arch
00059950:·6974·6563·7475·7265·206f·6620·7468·6520··itecture·of·the·00059950:·6974·6563·7475·7265·206f·6620·7468·6520··itecture·of·the·
00059960:·756e·6465·726c·7969·6e67·2073·7973·7465··underlying·syste00059960:·756e·6465·726c·7969·6e67·2073·7973·7465··underlying·syste
1.68 KB
html2text {}
    
Offset 39, 15 lines modifiedOffset 39, 15 lines modified
39 *****·Profile·Information·*****39 *****·Profile·Information·*****
40 Profile·Title·Standard·System·Security·Profile·for·Alibaba·Cloud·Linux·340 Profile·Title·Standard·System·Security·Profile·for·Alibaba·Cloud·Linux·3
41 Profile·ID····xccdf_org.ssgproject.content_profile_standard41 Profile·ID····xccdf_org.ssgproject.content_profile_standard
42 ***·CPE·Platforms·***42 ***·CPE·Platforms·***
43 ····*·cpe:/o:alinux:alibaba_cloud_linux:343 ····*·cpe:/o:alinux:alibaba_cloud_linux:3
44 *****·Revision·History·*****44 *****·Revision·History·*****
45 Current·version:·0.1.6545 Current·version:·0.1.65
46 ····*·draft·(as·of·2024-01-14)46 ····*·draft·(as·of·2025-02-15)
47 *****·Table·of·Contents·*****47 *****·Table·of·Contents·*****
48 ···1.·System_Settings48 ···1.·System_Settings
49 ·········1.·Installing_and_Maintaining_Software49 ·········1.·Installing_and_Maintaining_Software
50 ·········2.·System_Accounting_with_auditd50 ·········2.·System_Accounting_with_auditd
51 ·········3.·File_Permissions_and_Masks51 ·········3.·File_Permissions_and_Masks
52 ···2.·Services52 ···2.·Services
53 ·········1.·Base_Services53 ·········1.·Base_Services
Offset 943, 15 lines modifiedOffset 943, 15 lines modified
943 ············4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,943 ············4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,
944 ············A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,944 ············A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,
945 ············A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),945 ············A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),
946 ············AU-12(c),·AC-6(9),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,946 ············AU-12(c),·AC-6(9),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,
947 ············PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·Req-10.2.7947 ············PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·Req-10.2.7
948 Remediation_Shell_script_⇲948 Remediation_Shell_script_⇲
949 #·Remediation·is·applicable·only·in·certain·platforms949 #·Remediation·is·applicable·only·in·certain·platforms
950 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then950 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
951 #·First·perform·the·remediation·of·the·syscall·rule951 #·First·perform·the·remediation·of·the·syscall·rule
952 #·Retrieve·hardware·architecture·of·the·underlying·system952 #·Retrieve·hardware·architecture·of·the·underlying·system
953 #·Note:·32-bit·and·64-bit·kernel·syscall·numbers·not·always·line·up·=>953 #·Note:·32-bit·and·64-bit·kernel·syscall·numbers·not·always·line·up·=>
954 #·······it's·required·on·a·64-bit·system·to·check·also·for·the·presence954 #·······it's·required·on·a·64-bit·system·to·check·also·for·the·presence
955 #·······of·32-bit's·equivalent·of·the·corresponding·rule.955 #·······of·32-bit's·equivalent·of·the·corresponding·rule.
956 #·······(See·`man·7·audit.rules`·for·details·)956 #·······(See·`man·7·audit.rules`·for·details·)
24.2 KB
./usr/share/doc/ssg-nondebian/ssg-anolis8-guide-standard.html
    
Offset 14280, 16 lines modifiedOffset 14280, 16 lines modified
00037c70:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p00037c70:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p
00037c80:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version00037c80:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version
00037c90:·3a20·3c73·7472·6f6e·673e·302e·312e·3635··:·<strong>0.1.6500037c90:·3a20·3c73·7472·6f6e·673e·302e·312e·3635··:·<strong>0.1.65
00037ca0:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul00037ca0:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul
00037cb0:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra00037cb0:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra
00037cc0:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····00037cc0:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····
00037cd0:·2020·2020·2020·2020·2020·2020·2020·2020··················00037cd0:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037ce0:·2861·7320·6f66·2032·3032·342d·3031·2d31··(as·of·2024-01-100037ce0:·2861·7320·6f66·2032·3032·352d·3032·2d31··(as·of·2025-02-1
00037cf0:·3429·0a20·2020·2020·2020·2020·2020·2020··4).·············00037cf0:·3529·0a20·2020·2020·2020·2020·2020·2020··5).·············
00037d00:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d00037d00:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d
00037d10:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·00037d10:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·
00037d20:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol00037d20:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol
00037d30:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x00037d30:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x
00037d40:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj00037d40:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj
00037d50:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou00037d50:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou
00037d60:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System00037d60:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System
Offset 37661, 22 lines modifiedOffset 37661, 22 lines modified
000931c0:·616d·653a·2054·6573·7420·666f·7220·6578··ame:·Test·for·ex000931c0:·616d·653a·2054·6573·7420·666f·7220·6578··ame:·Test·for·ex
000931d0:·6973·7465·6e63·6520·2f62·6f6f·742f·6772··istence·/boot/gr000931d0:·6973·7465·6e63·6520·2f62·6f6f·742f·6772··istence·/boot/gr
000931e0:·7562·322f·6772·7562·2e63·6667·0a20·2073··ub2/grub.cfg.··s000931e0:·7562·322f·6772·7562·2e63·6667·0a20·2073··ub2/grub.cfg.··s
000931f0:·7461·743a·0a20·2020·2070·6174·683a·202f··tat:.····path:·/000931f0:·7461·743a·0a20·2020·2070·6174·683a·202f··tat:.····path:·/
00093200:·626f·6f74·2f67·7275·6232·2f67·7275·622e··boot/grub2/grub.00093200:·626f·6f74·2f67·7275·6232·2f67·7275·622e··boot/grub2/grub.
00093210:·6366·670a·2020·7265·6769·7374·6572·3a20··cfg.··register:·00093210:·6366·670a·2020·7265·6769·7374·6572·3a20··cfg.··register:·
00093220:·6669·6c65·5f65·7869·7374·730a·2020·7768··file_exists.··wh00093220:·6669·6c65·5f65·7869·7374·730a·2020·7768··file_exists.··wh
00093230:·656e·3a0a·2020·2d20·2722·6772·7562·322d··en:.··-·'"grub2-00093230:·656e·3a0a·2020·2d20·2722·2f62·6f6f·742f··en:.··-·'"/boot/
00093240:·636f·6d6d·6f6e·2220·696e·2061·6e73·6962··common"·in·ansib 
00093250:·6c65·5f66·6163·7473·2e70·6163·6b61·6765··le_facts.package 
00093260:·7327·0a20·202d·2027·222f·626f·6f74·2f65··s'.··-·'"/boot/e 
00093270:·6669·2220·6e6f·7420·696e·2061·6e73·6962··fi"·not·in·ansib 
00093280:·6c65·5f6d·6f75·6e74·7320·7c20·6d61·7028··le_mounts·|·map( 
00093290:·6174·7472·6962·7574·653d·226d·6f75·6e74··attribute="mount 
000932a0:·2229·207c·206c·6973·7427·0a20·202d·2061··")·|·list'.··-·a00093240:·6566·6922·206e·6f74·2069·6e20·616e·7369··efi"·not·in·ansi
 00093250:·626c·655f·6d6f·756e·7473·207c·206d·6170··ble_mounts·|·map
 00093260:·2861·7474·7269·6275·7465·3d22·6d6f·756e··(attribute="moun
 00093270:·7422·2920·7c20·6c69·7374·270a·2020·2d20··t")·|·list'.··-·
 00093280:·2722·6772·7562·322d·636f·6d6d·6f6e·2220··'"grub2-common"·
 00093290:·696e·2061·6e73·6962·6c65·5f66·6163·7473··in·ansible_facts
 000932a0:·2e70·6163·6b61·6765·7327·0a20·202d·2061··.packages'.··-·a
000932b0:·6e73·6962·6c65·5f76·6972·7475·616c·697a··nsible_virtualiz000932b0:·6e73·6962·6c65·5f76·6972·7475·616c·697a··nsible_virtualiz
000932c0:·6174·696f·6e5f·7479·7065·206e·6f74·2069··ation_type·not·i000932c0:·6174·696f·6e5f·7479·7065·206e·6f74·2069··ation_type·not·i
000932d0:·6e20·5b22·646f·636b·6572·222c·2022·6c78··n·["docker",·"lx000932d0:·6e20·5b22·646f·636b·6572·222c·2022·6c78··n·["docker",·"lx
000932e0:·6322·2c20·226f·7065·6e76·7a22·2c20·2270··c",·"openvz",·"p000932e0:·6322·2c20·226f·7065·6e76·7a22·2c20·2270··c",·"openvz",·"p
000932f0:·6f64·6d61·6e22·2c20·2263·6f6e·7461·696e··odman",·"contain000932f0:·6f64·6d61·6e22·2c20·2263·6f6e·7461·696e··odman",·"contain
00093300:·6572·225d·0a20·2074·6167·733a·0a20·202d··er"].··tags:.··-00093300:·6572·225d·0a20·2074·6167·733a·0a20·202d··er"].··tags:.··-
00093310:·2043·4a49·532d·352e·352e·322e·320a·2020···CJIS-5.5.2.2.··00093310:·2043·4a49·532d·352e·352e·322e·320a·2020···CJIS-5.5.2.2.··
Offset 37697, 22 lines modifiedOffset 37697, 22 lines modified
00093400:·6e61·6d65·3a20·456e·7375·7265·2067·726f··name:·Ensure·gro00093400:·6e61·6d65·3a20·456e·7375·7265·2067·726f··name:·Ensure·gro
00093410:·7570·206f·776e·6572·2030·206f·6e20·2f62··up·owner·0·on·/b00093410:·7570·206f·776e·6572·2030·206f·6e20·2f62··up·owner·0·on·/b
00093420:·6f6f·742f·6772·7562·322f·6772·7562·2e63··oot/grub2/grub.c00093420:·6f6f·742f·6772·7562·322f·6772·7562·2e63··oot/grub2/grub.c
00093430:·6667·0a20·2066·696c·653a·0a20·2020·2070··fg.··file:.····p00093430:·6667·0a20·2066·696c·653a·0a20·2020·2070··fg.··file:.····p
00093440:·6174·683a·202f·626f·6f74·2f67·7275·6232··ath:·/boot/grub200093440:·6174·683a·202f·626f·6f74·2f67·7275·6232··ath:·/boot/grub2
00093450:·2f67·7275·622e·6366·670a·2020·2020·6772··/grub.cfg.····gr00093450:·2f67·7275·622e·6366·670a·2020·2020·6772··/grub.cfg.····gr
00093460:·6f75·703a·2027·3027·0a20·2077·6865·6e3a··oup:·'0'.··when:00093460:·6f75·703a·2027·3027·0a20·2077·6865·6e3a··oup:·'0'.··when:
00093470:·0a20·202d·2027·2267·7275·6232·2d63·6f6d··.··-·'"grub2-com 
00093480:·6d6f·6e22·2069·6e20·616e·7369·626c·655f··mon"·in·ansible_ 
00093490:·6661·6374·732e·7061·636b·6167·6573·270a··facts.packages'. 
000934a0:·2020·2d20·2722·2f62·6f6f·742f·6566·6922····-·'"/boot/efi" 
000934b0:·206e·6f74·2069·6e20·616e·7369·626c·655f···not·in·ansible_ 
000934c0:·6d6f·756e·7473·207c·206d·6170·2861·7474··mounts·|·map(att 
000934d0:·7269·6275·7465·3d22·6d6f·756e·7422·2920··ribute="mount")·00093470:·0a20·202d·2027·222f·626f·6f74·2f65·6669··.··-·'"/boot/efi
 00093480:·2220·6e6f·7420·696e·2061·6e73·6962·6c65··"·not·in·ansible
 00093490:·5f6d·6f75·6e74·7320·7c20·6d61·7028·6174··_mounts·|·map(at
 000934a0:·7472·6962·7574·653d·226d·6f75·6e74·2229··tribute="mount")
 000934b0:·207c·206c·6973·7427·0a20·202d·2027·2267···|·list'.··-·'"g
 000934c0:·7275·6232·2d63·6f6d·6d6f·6e22·2069·6e20··rub2-common"·in·
 000934d0:·616e·7369·626c·655f·6661·6374·732e·7061··ansible_facts.pa
000934e0:·7c20·6c69·7374·270a·2020·2d20·616e·7369··|·list'.··-·ansi000934e0:·636b·6167·6573·270a·2020·2d20·616e·7369··ckages'.··-·ansi
000934f0:·626c·655f·7669·7274·7561·6c69·7a61·7469··ble_virtualizati000934f0:·626c·655f·7669·7274·7561·6c69·7a61·7469··ble_virtualizati
00093500:·6f6e·5f74·7970·6520·6e6f·7420·696e·205b··on_type·not·in·[00093500:·6f6e·5f74·7970·6520·6e6f·7420·696e·205b··on_type·not·in·[
00093510:·2264·6f63·6b65·7222·2c20·226c·7863·222c··"docker",·"lxc",00093510:·2264·6f63·6b65·7222·2c20·226c·7863·222c··"docker",·"lxc",
00093520:·2022·6f70·656e·767a·222c·2022·706f·646d···"openvz",·"podm00093520:·2022·6f70·656e·767a·222c·2022·706f·646d···"openvz",·"podm
00093530:·616e·222c·2022·636f·6e74·6169·6e65·7222··an",·"container"00093530:·616e·222c·2022·636f·6e74·6169·6e65·7222··an",·"container"
00093540:·5d0a·2020·2d20·6669·6c65·5f65·7869·7374··].··-·file_exist00093540:·5d0a·2020·2d20·6669·6c65·5f65·7869·7374··].··-·file_exist
00093550:·732e·7374·6174·2069·7320·6465·6669·6e65··s.stat·is·define00093550:·732e·7374·6174·2069·7320·6465·6669·6e65··s.stat·is·define
Offset 37762, 19 lines modifiedOffset 37762, 19 lines modified
00093810:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra00093810:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
00093820:·7465·6779·3a3c·2f74·683e·3c74·643e·636f··tegy:</th><td>co00093820:·7465·6779·3a3c·2f74·683e·3c74·643e·636f··tegy:</th><td>co
00093830:·6e66·6967·7572·653c·2f74·643e·3c2f·7472··nfigure</td></tr00093830:·6e66·6967·7572·653c·2f74·643e·3c2f·7472··nfigure</td></tr
00093840:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c00093840:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
00093850:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio00093850:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio
00093860:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·00093860:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·
00093870:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·00093870:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·
00093880:·706c·6174·666f·726d·730a·6966·2072·706d··platforms.if·rpm00093880:·706c·6174·666f·726d·730a·6966·205b·2021··platforms.if·[·!
00093890:·202d·2d71·7569·6574·202d·7120·6772·7562···--quiet·-q·grub 
000938a0:·322d·636f·6d6d·6f6e·2026·616d·703b·2661··2-common·&amp;&a 
000938b0:·6d70·3b20·5b20·2120·2d66·202f·7379·732f··mp;·[·!·-f·/sys/ 
000938c0:·6669·726d·7761·7265·2f65·6669·205d·2026··firmware/efi·]·&00093890:·202d·6620·2f73·7973·2f66·6972·6d77·6172···-f·/sys/firmwar
 000938a0:·652f·6566·6920·5d20·2661·6d70·3b26·616d··e/efi·]·&amp;&am
 000938b0:·703b·2072·706d·202d·2d71·7569·6574·202d··p;·rpm·--quiet·-
 000938c0:·7120·6772·7562·322d·636f·6d6d·6f6e·2026··q·grub2-common·&
000938d0:·616d·703b·2661·6d70·3b20·7b20·5b20·2120··amp;&amp;·{·[·!·000938d0:·616d·703b·2661·6d70·3b20·7b20·5b20·2120··amp;&amp;·{·[·!·
000938e0:·2d66·202f·2e64·6f63·6b65·7265·6e76·205d··-f·/.dockerenv·]000938e0:·2d66·202f·2e64·6f63·6b65·7265·6e76·205d··-f·/.dockerenv·]
000938f0:·2026·616d·703b·2661·6d70·3b20·5b20·2120···&amp;&amp;·[·!·000938f0:·2026·616d·703b·2661·6d70·3b20·5b20·2120···&amp;&amp;·[·!·
00093900:·2d66·202f·7275·6e2f·2e63·6f6e·7461·696e··-f·/run/.contain00093900:·2d66·202f·7275·6e2f·2e63·6f6e·7461·696e··-f·/run/.contain
00093910:·6572·656e·7620·5d3b·207d·3b20·7468·656e··erenv·];·};·then00093910:·6572·656e·7620·5d3b·207d·3b20·7468·656e··erenv·];·};·then
00093920:·0a0a·6368·6772·7020·3020·2f62·6f6f·742f··..chgrp·0·/boot/00093920:·0a0a·6368·6772·7020·3020·2f62·6f6f·742f··..chgrp·0·/boot/
00093930:·6772·7562·322f·6772·7562·2e63·6667·0a0a··grub2/grub.cfg..00093930:·6772·7562·322f·6772·7562·2e63·6667·0a0a··grub2/grub.cfg..
Offset 38236, 22 lines modifiedOffset 38236, 22 lines modified
000955b0:·3a20·5465·7374·2066·6f72·2065·7869·7374··:·Test·for·exist000955b0:·3a20·5465·7374·2066·6f72·2065·7869·7374··:·Test·for·exist
000955c0:·656e·6365·202f·626f·6f74·2f67·7275·6232··ence·/boot/grub2000955c0:·656e·6365·202f·626f·6f74·2f67·7275·6232··ence·/boot/grub2
000955d0:·2f67·7275·622e·6366·670a·2020·7374·6174··/grub.cfg.··stat000955d0:·2f67·7275·622e·6366·670a·2020·7374·6174··/grub.cfg.··stat
000955e0:·3a0a·2020·2020·7061·7468·3a20·2f62·6f6f··:.····path:·/boo000955e0:·3a0a·2020·2020·7061·7468·3a20·2f62·6f6f··:.····path:·/boo
000955f0:·742f·6772·7562·322f·6772·7562·2e63·6667··t/grub2/grub.cfg000955f0:·742f·6772·7562·322f·6772·7562·2e63·6667··t/grub2/grub.cfg
00095600:·0a20·2072·6567·6973·7465·723a·2066·696c··.··register:·fil00095600:·0a20·2072·6567·6973·7465·723a·2066·696c··.··register:·fil
00095610:·655f·6578·6973·7473·0a20·2077·6865·6e3a··e_exists.··when:00095610:·655f·6578·6973·7473·0a20·2077·6865·6e3a··e_exists.··when:
00095620:·0a20·202d·2027·2267·7275·6232·2d63·6f6d··.··-·'"grub2-com 
00095630:·6d6f·6e22·2069·6e20·616e·7369·626c·655f··mon"·in·ansible_ 
00095640:·6661·6374·732e·7061·636b·6167·6573·270a··facts.packages'. 
00095650:·2020·2d20·2722·2f62·6f6f·742f·6566·6922····-·'"/boot/efi" 
00095660:·206e·6f74·2069·6e20·616e·7369·626c·655f···not·in·ansible_ 
00095670:·6d6f·756e·7473·207c·206d·6170·2861·7474··mounts·|·map(att 
00095680:·7269·6275·7465·3d22·6d6f·756e·7422·2920··ribute="mount")·00095620:·0a20·202d·2027·222f·626f·6f74·2f65·6669··.··-·'"/boot/efi
 00095630:·2220·6e6f·7420·696e·2061·6e73·6962·6c65··"·not·in·ansible
 00095640:·5f6d·6f75·6e74·7320·7c20·6d61·7028·6174··_mounts·|·map(at
 00095650:·7472·6962·7574·653d·226d·6f75·6e74·2229··tribute="mount")
 00095660:·207c·206c·6973·7427·0a20·202d·2027·2267···|·list'.··-·'"g
 00095670:·7275·6232·2d63·6f6d·6d6f·6e22·2069·6e20··rub2-common"·in·
 00095680:·616e·7369·626c·655f·6661·6374·732e·7061··ansible_facts.pa
00095690:·7c20·6c69·7374·270a·2020·2d20·616e·7369··|·list'.··-·ansi00095690:·636b·6167·6573·270a·2020·2d20·616e·7369··ckages'.··-·ansi
000956a0:·626c·655f·7669·7274·7561·6c69·7a61·7469··ble_virtualizati000956a0:·626c·655f·7669·7274·7561·6c69·7a61·7469··ble_virtualizati
000956b0:·6f6e·5f74·7970·6520·6e6f·7420·696e·205b··on_type·not·in·[000956b0:·6f6e·5f74·7970·6520·6e6f·7420·696e·205b··on_type·not·in·[
000956c0:·2264·6f63·6b65·7222·2c20·226c·7863·222c··"docker",·"lxc",000956c0:·2264·6f63·6b65·7222·2c20·226c·7863·222c··"docker",·"lxc",
000956d0:·2022·6f70·656e·767a·222c·2022·706f·646d···"openvz",·"podm000956d0:·2022·6f70·656e·767a·222c·2022·706f·646d···"openvz",·"podm
000956e0:·616e·222c·2022·636f·6e74·6169·6e65·7222··an",·"container"000956e0:·616e·222c·2022·636f·6e74·6169·6e65·7222··an",·"container"
000956f0:·5d0a·2020·7461·6773·3a0a·2020·2d20·434a··].··tags:.··-·CJ000956f0:·5d0a·2020·7461·6773·3a0a·2020·2d20·434a··].··tags:.··-·CJ
00095700:·4953·2d35·2e35·2e32·2e32·0a20·202d·204e··IS-5.5.2.2.··-·N00095700:·4953·2d35·2e35·2e32·2e32·0a20·202d·204e··IS-5.5.2.2.··-·N
Offset 38271, 22 lines modifiedOffset 38271, 22 lines modified
Max diff block lines reached; 9626/18890 bytes (50.96%) of diff not shown.
5.63 KB
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *****·Profile·Information·*****37 *****·Profile·Information·*****
38 Profile·Title·Standard·System·Security·Profile·for·Anolis·OS·838 Profile·Title·Standard·System·Security·Profile·for·Anolis·OS·8
39 Profile·ID····xccdf_org.ssgproject.content_profile_standard39 Profile·ID····xccdf_org.ssgproject.content_profile_standard
40 ***·CPE·Platforms·***40 ***·CPE·Platforms·***
41 ····*·cpe:/o:anolis:anolis_os:841 ····*·cpe:/o:anolis:anolis_os:8
42 *****·Revision·History·*****42 *****·Revision·History·*****
43 Current·version:·0.1.6543 Current·version:·0.1.65
44 ····*·draft·(as·of·2024-01-14)44 ····*·draft·(as·of·2025-02-15)
45 *****·Table·of·Contents·*****45 *****·Table·of·Contents·*****
46 ···1.·System_Settings46 ···1.·System_Settings
47 ·········1.·Installing_and_Maintaining_Software47 ·········1.·Installing_and_Maintaining_Software
48 ·········2.·Account_and_Access_Control48 ·········2.·Account_and_Access_Control
49 ·········3.·System_Accounting_with_auditd49 ·········3.·System_Accounting_with_auditd
50 ·········4.·GRUB2_bootloader_configuration50 ·········4.·GRUB2_bootloader_configuration
51 ·········5.·Configure_Syslog51 ·········5.·Configure_Syslog
Offset 2699, 16 lines modifiedOffset 2699, 16 lines modified
2699 ··-·no_reboot_needed2699 ··-·no_reboot_needed
  
2700 -·name:·Test·for·existence·/boot/grub2/grub.cfg2700 -·name:·Test·for·existence·/boot/grub2/grub.cfg
2701 ··stat:2701 ··stat:
2702 ····path:·/boot/grub2/grub.cfg2702 ····path:·/boot/grub2/grub.cfg
2703 ··register:·file_exists2703 ··register:·file_exists
2704 ··when:2704 ··when:
2705 ··-·'"grub2-common"·in·ansible_facts.packages' 
2706 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'2705 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 2706 ··-·'"grub2-common"·in·ansible_facts.packages'
2707 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2707 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2708 ··tags:2708 ··tags:
2709 ··-·CJIS-5.5.2.22709 ··-·CJIS-5.5.2.2
2710 ··-·NIST-800-171-3.4.52710 ··-·NIST-800-171-3.4.5
2711 ··-·NIST-800-53-AC-6(1)2711 ··-·NIST-800-53-AC-6(1)
2712 ··-·NIST-800-53-CM-6(a)2712 ··-·NIST-800-53-CM-6(a)
2713 ··-·PCI-DSS-Req-7.12713 ··-·PCI-DSS-Req-7.1
Offset 2720, 16 lines modifiedOffset 2720, 16 lines modified
2720 ··-·no_reboot_needed2720 ··-·no_reboot_needed
  
2721 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg2721 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
2722 ··file:2722 ··file:
2723 ····path:·/boot/grub2/grub.cfg2723 ····path:·/boot/grub2/grub.cfg
2724 ····group:·'0'2724 ····group:·'0'
2725 ··when:2725 ··when:
2726 ··-·'"grub2-common"·in·ansible_facts.packages' 
2727 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'2726 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 2727 ··-·'"grub2-common"·in·ansible_facts.packages'
2728 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2728 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2729 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists2729 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists
2730 ··tags:2730 ··tags:
2731 ··-·CJIS-5.5.2.22731 ··-·CJIS-5.5.2.2
2732 ··-·NIST-800-171-3.4.52732 ··-·NIST-800-171-3.4.5
2733 ··-·NIST-800-53-AC-6(1)2733 ··-·NIST-800-53-AC-6(1)
2734 ··-·NIST-800-53-CM-6(a)2734 ··-·NIST-800-53-CM-6(a)
Offset 2741, 15 lines modifiedOffset 2741, 15 lines modified
2741 ··-·medium_severity2741 ··-·medium_severity
2742 ··-·no_reboot_needed2742 ··-·no_reboot_needed
2743 Remediation_Shell_script_⇲2743 Remediation_Shell_script_⇲
2744 Complexity:·low2744 Complexity:·low
2745 Disruption:·low2745 Disruption:·low
2746 Strategy:···configure2746 Strategy:···configure
2747 #·Remediation·is·applicable·only·in·certain·platforms2747 #·Remediation·is·applicable·only·in·certain·platforms
2748 if·rpm·--quiet·-q·grub2-common·&&·[·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/2748 if·[·!·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/
2749 run/.containerenv·];·};·then2749 run/.containerenv·];·};·then
  
2750 chgrp·0·/boot/grub2/grub.cfg2750 chgrp·0·/boot/grub2/grub.cfg
  
2751 else2751 else
2752 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'2752 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
2753 fi2753 fi
Offset 2788, 16 lines modifiedOffset 2788, 16 lines modified
2788 ··-·no_reboot_needed2788 ··-·no_reboot_needed
  
2789 -·name:·Test·for·existence·/boot/grub2/grub.cfg2789 -·name:·Test·for·existence·/boot/grub2/grub.cfg
2790 ··stat:2790 ··stat:
2791 ····path:·/boot/grub2/grub.cfg2791 ····path:·/boot/grub2/grub.cfg
2792 ··register:·file_exists2792 ··register:·file_exists
2793 ··when:2793 ··when:
2794 ··-·'"grub2-common"·in·ansible_facts.packages' 
2795 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'2794 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 2795 ··-·'"grub2-common"·in·ansible_facts.packages'
2796 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2796 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2797 ··tags:2797 ··tags:
2798 ··-·CJIS-5.5.2.22798 ··-·CJIS-5.5.2.2
2799 ··-·NIST-800-171-3.4.52799 ··-·NIST-800-171-3.4.5
2800 ··-·NIST-800-53-AC-6(1)2800 ··-·NIST-800-53-AC-6(1)
2801 ··-·NIST-800-53-CM-6(a)2801 ··-·NIST-800-53-CM-6(a)
2802 ··-·PCI-DSS-Req-7.12802 ··-·PCI-DSS-Req-7.1
Offset 2809, 16 lines modifiedOffset 2809, 16 lines modified
2809 ··-·no_reboot_needed2809 ··-·no_reboot_needed
  
2810 -·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg2810 -·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg
2811 ··file:2811 ··file:
2812 ····path:·/boot/grub2/grub.cfg2812 ····path:·/boot/grub2/grub.cfg
2813 ····owner:·'0'2813 ····owner:·'0'
2814 ··when:2814 ··when:
2815 ··-·'"grub2-common"·in·ansible_facts.packages' 
2816 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'2815 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 2816 ··-·'"grub2-common"·in·ansible_facts.packages'
2817 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2817 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2818 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists2818 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists
2819 ··tags:2819 ··tags:
2820 ··-·CJIS-5.5.2.22820 ··-·CJIS-5.5.2.2
2821 ··-·NIST-800-171-3.4.52821 ··-·NIST-800-171-3.4.5
2822 ··-·NIST-800-53-AC-6(1)2822 ··-·NIST-800-53-AC-6(1)
2823 ··-·NIST-800-53-CM-6(a)2823 ··-·NIST-800-53-CM-6(a)
Offset 2830, 15 lines modifiedOffset 2830, 15 lines modified
2830 ··-·medium_severity2830 ··-·medium_severity
2831 ··-·no_reboot_needed2831 ··-·no_reboot_needed
2832 Remediation_Shell_script_⇲2832 Remediation_Shell_script_⇲
2833 Complexity:·low2833 Complexity:·low
2834 Disruption:·low2834 Disruption:·low
2835 Strategy:···configure2835 Strategy:···configure
2836 #·Remediation·is·applicable·only·in·certain·platforms2836 #·Remediation·is·applicable·only·in·certain·platforms
2837 if·rpm·--quiet·-q·grub2-common·&&·[·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/2837 if·[·!·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/
2838 run/.containerenv·];·};·then2838 run/.containerenv·];·};·then
  
2839 chown·0·/boot/grub2/grub.cfg2839 chown·0·/boot/grub2/grub.cfg
  
2840 else2840 else
2841 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'2841 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
2842 fi2842 fi
Offset 2875, 16 lines modifiedOffset 2875, 16 lines modified
2875 ··-·no_reboot_needed2875 ··-·no_reboot_needed
  
2876 -·name:·Test·for·existence·/boot/grub2/grub.cfg2876 -·name:·Test·for·existence·/boot/grub2/grub.cfg
2877 ··stat:2877 ··stat:
2878 ····path:·/boot/grub2/grub.cfg2878 ····path:·/boot/grub2/grub.cfg
2879 ··register:·file_exists2879 ··register:·file_exists
2880 ··when:2880 ··when:
Max diff block lines reached; 1466/5744 bytes (25.52%) of diff not shown.
541 KB
./usr/share/doc/ssg-nondebian/ssg-centos7-guide-pci-dss.html
    
Offset 14450, 16 lines modifiedOffset 14450, 16 lines modified
00038710:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h00038710:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h
00038720:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver00038720:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver
00038730:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.00038730:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.
00038740:·312e·3635·3c2f·7374·726f·6e67·3e3c·2f70··1.65</strong></p00038740:·312e·3635·3c2f·7374·726f·6e67·3e3c·2f70··1.65</strong></p
00038750:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong00038750:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong
00038760:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.00038760:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.
00038770:·2020·2020·2020·2020·2020·2020·2020·2020··················00038770:·2020·2020·2020·2020·2020·2020·2020·2020··················
00038780:·2020·2020·2861·7320·6f66·2032·3032·342d······(as·of·2024-00038780:·2020·2020·2861·7320·6f66·2032·3032·352d······(as·of·2025-
00038790:·3031·2d31·3429·0a20·2020·2020·2020·2020··01-14).·········00038790:·3032·2d31·3529·0a20·2020·2020·2020·2020··02-15).·········
000387a0:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul000387a0:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul
000387b0:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table000387b0:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table
000387c0:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h2000387c0:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h2
000387d0:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href000387d0:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href
000387e0:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg000387e0:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg
000387f0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_000387f0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_
00038800:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy00038800:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy
Offset 48543, 23 lines modifiedOffset 48543, 23 lines modified
000bd9e0:·640a·2020·2d20·7265·7374·7269·6374·5f73··d.··-·restrict_s000bd9e0:·640a·2020·2d20·7265·7374·7269·6374·5f73··d.··-·restrict_s
000bd9f0:·7472·6174·6567·790a·0a2d·206e·616d·653a··trategy..-·name:000bd9f0:·7472·6174·6567·790a·0a2d·206e·616d·653a··trategy..-·name:
000bda00:·2053·6574·2061·7263·6869·7465·6374·7572···Set·architectur000bda00:·2053·6574·2061·7263·6869·7465·6374·7572···Set·architectur
000bda10:·6520·666f·7220·6175·6469·7420·6368·6d6f··e·for·audit·chmo000bda10:·6520·666f·7220·6175·6469·7420·6368·6d6f··e·for·audit·chmo
000bda20:·6420·7461·736b·730a·2020·7365·745f·6661··d·tasks.··set_fa000bda20:·6420·7461·736b·730a·2020·7365·745f·6661··d·tasks.··set_fa
000bda30:·6374·3a0a·2020·2020·6175·6469·745f·6172··ct:.····audit_ar000bda30:·6374·3a0a·2020·2020·6175·6469·745f·6172··ct:.····audit_ar
000bda40:·6368·3a20·6236·340a·2020·7768·656e·3a0a··ch:·b64.··when:.000bda40:·6368·3a20·6236·340a·2020·7768·656e·3a0a··ch:·b64.··when:.
000bda50:·2020·2d20·616e·7369·626c·655f·7669·7274····-·ansible_virt 
000bda60:·7561·6c69·7a61·7469·6f6e·5f74·7970·6520··ualization_type· 
000bda70:·6e6f·7420·696e·205b·2264·6f63·6b65·7222··not·in·["docker" 
000bda80:·2c20·226c·7863·222c·2022·6f70·656e·767a··,·"lxc",·"openvz 
000bda90:·222c·2022·706f·646d·616e·222c·2022·636f··",·"podman",·"co 
000bdaa0:·6e74·6169·6e65·7222·5d0a·2020·2d20·2722··ntainer"].··-·'" 
000bdab0:·6175·6469·7422·2069·6e20·616e·7369·626c··audit"·in·ansibl 
000bdac0:·655f·6661·6374·732e·7061·636b·6167·6573··e_facts.packages000bda50:·2020·2d20·2722·6175·6469·7422·2069·6e20····-·'"audit"·in·
 000bda60:·616e·7369·626c·655f·6661·6374·732e·7061··ansible_facts.pa
 000bda70:·636b·6167·6573·270a·2020·2d20·616e·7369··ckages'.··-·ansi
 000bda80:·626c·655f·7669·7274·7561·6c69·7a61·7469··ble_virtualizati
 000bda90:·6f6e·5f74·7970·6520·6e6f·7420·696e·205b··on_type·not·in·[
 000bdaa0:·2264·6f63·6b65·7222·2c20·226c·7863·222c··"docker",·"lxc",
 000bdab0:·2022·6f70·656e·767a·222c·2022·706f·646d···"openvz",·"podm
 000bdac0:·616e·222c·2022·636f·6e74·6169·6e65·7222··an",·"container"
000bdad0:·270a·2020·2d20·616e·7369·626c·655f·6172··'.··-·ansible_ar000bdad0:·5d0a·2020·2d20·616e·7369·626c·655f·6172··].··-·ansible_ar
000bdae0:·6368·6974·6563·7475·7265·203d·3d20·2261··chitecture·==·"a000bdae0:·6368·6974·6563·7475·7265·203d·3d20·2261··chitecture·==·"a
000bdaf0:·6172·6368·3634·2220·6f72·2061·6e73·6962··arch64"·or·ansib000bdaf0:·6172·6368·3634·2220·6f72·2061·6e73·6962··arch64"·or·ansib
000bdb00:·6c65·5f61·7263·6869·7465·6374·7572·6520··le_architecture·000bdb00:·6c65·5f61·7263·6869·7465·6374·7572·6520··le_architecture·
000bdb10:·3d3d·2022·7070·6336·3422·206f·7220·616e··==·"ppc64"·or·an000bdb10:·3d3d·2022·7070·6336·3422·206f·7220·616e··==·"ppc64"·or·an
000bdb20:·7369·626c·655f·6172·6368·6974·6563·7475··sible_architectu000bdb20:·7369·626c·655f·6172·6368·6974·6563·7475··sible_architectu
000bdb30:·7265·0a20·2020·203d·3d20·2270·7063·3634··re.····==·"ppc64000bdb30:·7265·0a20·2020·203d·3d20·2270·7063·3634··re.····==·"ppc64
000bdb40:·6c65·2220·6f72·2061·6e73·6962·6c65·5f61··le"·or·ansible_a000bdb40:·6c65·2220·6f72·2061·6e73·6962·6c65·5f61··le"·or·ansible_a
Offset 48866, 23 lines modifiedOffset 48866, 23 lines modified
000bee10:·3d70·6572·6d5f·6d6f·640a·2020·2020·2020··=perm_mod.······000bee10:·3d70·6572·6d5f·6d6f·640a·2020·2020·2020··=perm_mod.······
000bee20:·6372·6561·7465·3a20·7472·7565·0a20·2020··create:·true.···000bee20:·6372·6561·7465·3a20·7472·7565·0a20·2020··create:·true.···
000bee30:·2020·206d·6f64·653a·206f·2d72·7778·0a20·····mode:·o-rwx.·000bee30:·2020·206d·6f64·653a·206f·2d72·7778·0a20·····mode:·o-rwx.·
000bee40:·2020·2020·2073·7461·7465·3a20·7072·6573·······state:·pres000bee40:·2020·2020·2073·7461·7465·3a20·7072·6573·······state:·pres
000bee50:·656e·740a·2020·2020·7768·656e·3a20·7379··ent.····when:·sy000bee50:·656e·740a·2020·2020·7768·656e·3a20·7379··ent.····when:·sy
000bee60:·7363·616c·6c73·5f66·6f75·6e64·207c·206c··scalls_found·|·l000bee60:·7363·616c·6c73·5f66·6f75·6e64·207c·206c··scalls_found·|·l
000bee70:·656e·6774·6820·3d3d·2030·0a20·2077·6865··ength·==·0.··whe000bee70:·656e·6774·6820·3d3d·2030·0a20·2077·6865··ength·==·0.··whe
000bee80:·6e3a·0a20·202d·2061·6e73·6962·6c65·5f76··n:.··-·ansible_v 
000bee90:·6972·7475·616c·697a·6174·696f·6e5f·7479··irtualization_ty 
000beea0:·7065·206e·6f74·2069·6e20·5b22·646f·636b··pe·not·in·["dock 
000beeb0:·6572·222c·2022·6c78·6322·2c20·226f·7065··er",·"lxc",·"ope 
000beec0:·6e76·7a22·2c20·2270·6f64·6d61·6e22·2c20··nvz",·"podman",· 
000beed0:·2263·6f6e·7461·696e·6572·225d·0a20·202d··"container"].··- 
000beee0:·2027·2261·7564·6974·2220·696e·2061·6e73···'"audit"·in·ans 
000beef0:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa000bee80:·6e3a·0a20·202d·2027·2261·7564·6974·2220··n:.··-·'"audit"·
 000bee90:·696e·2061·6e73·6962·6c65·5f66·6163·7473··in·ansible_facts
 000beea0:·2e70·6163·6b61·6765·7327·0a20·202d·2061··.packages'.··-·a
 000beeb0:·6e73·6962·6c65·5f76·6972·7475·616c·697a··nsible_virtualiz
 000beec0:·6174·696f·6e5f·7479·7065·206e·6f74·2069··ation_type·not·i
 000beed0:·6e20·5b22·646f·636b·6572·222c·2022·6c78··n·["docker",·"lx
 000beee0:·6322·2c20·226f·7065·6e76·7a22·2c20·2270··c",·"openvz",·"p
 000beef0:·6f64·6d61·6e22·2c20·2263·6f6e·7461·696e··odman",·"contain
000bef00:·6765·7327·0a20·2074·6167·733a·0a20·202d··ges'.··tags:.··-000bef00:·6572·225d·0a20·2074·6167·733a·0a20·202d··er"].··tags:.··-
000bef10:·2043·4a49·532d·352e·342e·312e·310a·2020···CJIS-5.4.1.1.··000bef10:·2043·4a49·532d·352e·342e·312e·310a·2020···CJIS-5.4.1.1.··
000bef20:·2d20·4449·5341·2d53·5449·472d·5248·454c··-·DISA-STIG-RHEL000bef20:·2d20·4449·5341·2d53·5449·472d·5248·454c··-·DISA-STIG-RHEL
000bef30:·2d30·372d·3033·3034·3130·0a20·202d·204e··-07-030410.··-·N000bef30:·2d30·372d·3033·3034·3130·0a20·202d·204e··-07-030410.··-·N
000bef40:·4953·542d·3830·302d·3137·312d·332e·312e··IST-800-171-3.1.000bef40:·4953·542d·3830·302d·3137·312d·332e·312e··IST-800-171-3.1.
000bef50:·370a·2020·2d20·4e49·5354·2d38·3030·2d35··7.··-·NIST-800-5000bef50:·370a·2020·2d20·4e49·5354·2d38·3030·2d35··7.··-·NIST-800-5
000bef60:·332d·4155·2d31·3228·6329·0a20·202d·204e··3-AU-12(c).··-·N000bef60:·332d·4155·2d31·3228·6329·0a20·202d·204e··3-AU-12(c).··-·N
000bef70:·4953·542d·3830·302d·3533·2d41·552d·3228··IST-800-53-AU-2(000bef70:·4953·542d·3830·302d·3533·2d41·552d·3228··IST-800-53-AU-2(
Offset 49178, 22 lines modifiedOffset 49178, 22 lines modified
000c0190:·6d6f·640a·2020·2020·2020·6372·6561·7465··mod.······create000c0190:·6d6f·640a·2020·2020·2020·6372·6561·7465··mod.······create
000c01a0:·3a20·7472·7565·0a20·2020·2020·206d·6f64··:·true.······mod000c01a0:·3a20·7472·7565·0a20·2020·2020·206d·6f64··:·true.······mod
000c01b0:·653a·206f·2d72·7778·0a20·2020·2020·2073··e:·o-rwx.······s000c01b0:·653a·206f·2d72·7778·0a20·2020·2020·2073··e:·o-rwx.······s
000c01c0:·7461·7465·3a20·7072·6573·656e·740a·2020··tate:·present.··000c01c0:·7461·7465·3a20·7072·6573·656e·740a·2020··tate:·present.··
000c01d0:·2020·7768·656e·3a20·7379·7363·616c·6c73····when:·syscalls000c01d0:·2020·7768·656e·3a20·7379·7363·616c·6c73····when:·syscalls
000c01e0:·5f66·6f75·6e64·207c·206c·656e·6774·6820··_found·|·length·000c01e0:·5f66·6f75·6e64·207c·206c·656e·6774·6820··_found·|·length·
000c01f0:·3d3d·2030·0a20·2077·6865·6e3a·0a20·202d··==·0.··when:.··-000c01f0:·3d3d·2030·0a20·2077·6865·6e3a·0a20·202d··==·0.··when:.··-
000c0200:·2061·6e73·6962·6c65·5f76·6972·7475·616c···ansible_virtual 
000c0210:·697a·6174·696f·6e5f·7479·7065·206e·6f74··ization_type·not 
000c0220:·2069·6e20·5b22·646f·636b·6572·222c·2022···in·["docker",·" 
000c0230:·6c78·6322·2c20·226f·7065·6e76·7a22·2c20··lxc",·"openvz",· 
000c0240:·2270·6f64·6d61·6e22·2c20·2263·6f6e·7461··"podman",·"conta 
000c0250:·696e·6572·225d·0a20·202d·2027·2261·7564··iner"].··-·'"aud 
000c0260:·6974·2220·696e·2061·6e73·6962·6c65·5f66··it"·in·ansible_f 
000c0270:·6163·7473·2e70·6163·6b61·6765·7327·0a20··acts.packages'.·000c0200:·2027·2261·7564·6974·2220·696e·2061·6e73···'"audit"·in·ans
 000c0210:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa
 000c0220:·6765·7327·0a20·202d·2061·6e73·6962·6c65··ges'.··-·ansible
 000c0230:·5f76·6972·7475·616c·697a·6174·696f·6e5f··_virtualization_
 000c0240:·7479·7065·206e·6f74·2069·6e20·5b22·646f··type·not·in·["do
 000c0250:·636b·6572·222c·2022·6c78·6322·2c20·226f··cker",·"lxc",·"o
 000c0260:·7065·6e76·7a22·2c20·2270·6f64·6d61·6e22··penvz",·"podman"
 000c0270:·2c20·2263·6f6e·7461·696e·6572·225d·0a20··,·"container"].·
000c0280:·202d·2061·7564·6974·5f61·7263·6820·3d3d···-·audit_arch·==000c0280:·202d·2061·7564·6974·5f61·7263·6820·3d3d···-·audit_arch·==
000c0290:·2022·6236·3422·0a20·2074·6167·733a·0a20···"b64".··tags:.·000c0290:·2022·6236·3422·0a20·2074·6167·733a·0a20···"b64".··tags:.·
000c02a0:·202d·2043·4a49·532d·352e·342e·312e·310a···-·CJIS-5.4.1.1.000c02a0:·202d·2043·4a49·532d·352e·342e·312e·310a···-·CJIS-5.4.1.1.
000c02b0:·2020·2d20·4449·5341·2d53·5449·472d·5248····-·DISA-STIG-RH000c02b0:·2020·2d20·4449·5341·2d53·5449·472d·5248····-·DISA-STIG-RH
000c02c0:·454c·2d30·372d·3033·3034·3130·0a20·202d··EL-07-030410.··-000c02c0:·454c·2d30·372d·3033·3034·3130·0a20·202d··EL-07-030410.··-
000c02d0:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.000c02d0:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.
000c02e0:·312e·370a·2020·2d20·4e49·5354·2d38·3030··1.7.··-·NIST-800000c02e0:·312e·370a·2020·2d20·4e49·5354·2d38·3030··1.7.··-·NIST-800
Offset 49227, 21 lines modifiedOffset 49227, 21 lines modified
000c04a0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class000c04a0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
000c04b0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse000c04b0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
000c04c0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i000c04c0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
000c04d0:·646d·3137·3133·3322·3e3c·7072·653e·3c63··dm17133"><pre><c000c04d0:·646d·3137·3133·3322·3e3c·7072·653e·3c63··dm17133"><pre><c
000c04e0:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio000c04e0:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio
000c04f0:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·000c04f0:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·
000c0500:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·000c0500:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·
000c0510:·706c·6174·666f·726d·730a·6966·205b·2021··platforms.if·[·!000c0510:·706c·6174·666f·726d·730a·6966·2072·706d··platforms.if·rpm
 000c0520:·202d·2d71·7569·6574·202d·7120·6175·6469···--quiet·-q·audi
 000c0530:·7420·2661·6d70·3b26·616d·703b·205b·2021··t·&amp;&amp;·[·!
000c0520:·202d·6620·2f2e·646f·636b·6572·656e·7620···-f·/.dockerenv·000c0540:·202d·6620·2f2e·646f·636b·6572·656e·7620···-f·/.dockerenv·
000c0530:·5d20·2661·6d70·3b26·616d·703b·205b·2021··]·&amp;&amp;·[·!000c0550:·5d20·2661·6d70·3b26·616d·703b·205b·2021··]·&amp;&amp;·[·!
000c0540:·202d·6620·2f72·756e·2f2e·636f·6e74·6169···-f·/run/.contai000c0560:·202d·6620·2f72·756e·2f2e·636f·6e74·6169···-f·/run/.contai
 000c0570:·6e65·7265·6e76·205d·3b20·7468·656e·0a0a··nerenv·];·then..
000c0550:·6e65·7265·6e76·205d·2026·616d·703b·2661··nerenv·]·&amp;&a 
000c0560:·6d70·3b20·7270·6d20·2d2d·7175·6965·7420··mp;·rpm·--quiet· 
000c0570:·2d71·2061·7564·6974·3b20·7468·656e·0a0a··-q·audit;·then.. 
000c0580:·2320·4669·7273·7420·7065·7266·6f72·6d20··#·First·perform·000c0580:·2320·4669·7273·7420·7065·7266·6f72·6d20··#·First·perform·
Max diff block lines reached; 407817/417262 bytes (97.74%) of diff not shown.
134 KB
html2text {}
    
Offset 59, 15 lines modifiedOffset 59, 15 lines modified
59 ····*·cpe:/o:redhat:enterprise_linux:7::computenode59 ····*·cpe:/o:redhat:enterprise_linux:7::computenode
60 ····*·cpe:/o:redhat:enterprise_linux:7::server60 ····*·cpe:/o:redhat:enterprise_linux:7::server
61 ····*·cpe:/o:redhat:enterprise_linux:7::workstation61 ····*·cpe:/o:redhat:enterprise_linux:7::workstation
62 ····*·cpe:/o:redhat:enterprise_linux:762 ····*·cpe:/o:redhat:enterprise_linux:7
63 ····*·cpe:/o:centos:centos:763 ····*·cpe:/o:centos:centos:7
64 *****·Revision·History·*****64 *****·Revision·History·*****
65 Current·version:·0.1.6565 Current·version:·0.1.65
66 ····*·draft·(as·of·2024-01-14)66 ····*·draft·(as·of·2025-02-15)
67 *****·Table·of·Contents·*****67 *****·Table·of·Contents·*****
68 ···1.·System_Settings68 ···1.·System_Settings
69 ·········1.·Installing_and_Maintaining_Software69 ·········1.·Installing_and_Maintaining_Software
70 ·········2.·Account_and_Access_Control70 ·········2.·Account_and_Access_Control
71 ·········3.·System_Accounting_with_auditd71 ·········3.·System_Accounting_with_auditd
72 ·········4.·GRUB2_bootloader_configuration72 ·········4.·GRUB2_bootloader_configuration
73 ·········5.·Configure_Syslog73 ·········5.·Configure_Syslog
Offset 6287, 16 lines modifiedOffset 6287, 16 lines modified
6287 ··-·reboot_required6287 ··-·reboot_required
6288 ··-·restrict_strategy6288 ··-·restrict_strategy
  
6289 -·name:·Set·architecture·for·audit·chmod·tasks6289 -·name:·Set·architecture·for·audit·chmod·tasks
6290 ··set_fact:6290 ··set_fact:
6291 ····audit_arch:·b646291 ····audit_arch:·b64
6292 ··when:6292 ··when:
6293 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
6294 ··-·'"audit"·in·ansible_facts.packages'6293 ··-·'"audit"·in·ansible_facts.packages'
 6294 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
6295 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture6295 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
6296 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"6296 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
6297 ··tags:6297 ··tags:
6298 ··-·CJIS-5.4.1.16298 ··-·CJIS-5.4.1.1
6299 ··-·DISA-STIG-RHEL-07-0304106299 ··-·DISA-STIG-RHEL-07-030410
6300 ··-·NIST-800-171-3.1.76300 ··-·NIST-800-171-3.1.7
6301 ··-·NIST-800-53-AU-12(c)6301 ··-·NIST-800-53-AU-12(c)
Offset 6433, 16 lines modifiedOffset 6433, 16 lines modified
6433 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10006433 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
6434 ········-F·auid!=unset·-F·key=perm_mod6434 ········-F·auid!=unset·-F·key=perm_mod
6435 ······create:·true6435 ······create:·true
6436 ······mode:·o-rwx6436 ······mode:·o-rwx
6437 ······state:·present6437 ······state:·present
6438 ····when:·syscalls_found·|·length·==·06438 ····when:·syscalls_found·|·length·==·0
6439 ··when:6439 ··when:
6440 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
6441 ··-·'"audit"·in·ansible_facts.packages'6440 ··-·'"audit"·in·ansible_facts.packages'
 6441 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
6442 ··tags:6442 ··tags:
6443 ··-·CJIS-5.4.1.16443 ··-·CJIS-5.4.1.1
6444 ··-·DISA-STIG-RHEL-07-0304106444 ··-·DISA-STIG-RHEL-07-030410
6445 ··-·NIST-800-171-3.1.76445 ··-·NIST-800-171-3.1.7
6446 ··-·NIST-800-53-AU-12(c)6446 ··-·NIST-800-53-AU-12(c)
6447 ··-·NIST-800-53-AU-2(d)6447 ··-·NIST-800-53-AU-2(d)
6448 ··-·NIST-800-53-CM-6(a)6448 ··-·NIST-800-53-CM-6(a)
Offset 6577, 16 lines modifiedOffset 6577, 16 lines modified
6577 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10006577 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
6578 ········-F·auid!=unset·-F·key=perm_mod6578 ········-F·auid!=unset·-F·key=perm_mod
6579 ······create:·true6579 ······create:·true
6580 ······mode:·o-rwx6580 ······mode:·o-rwx
6581 ······state:·present6581 ······state:·present
6582 ····when:·syscalls_found·|·length·==·06582 ····when:·syscalls_found·|·length·==·0
6583 ··when:6583 ··when:
6584 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
6585 ··-·'"audit"·in·ansible_facts.packages'6584 ··-·'"audit"·in·ansible_facts.packages'
 6585 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
6586 ··-·audit_arch·==·"b64"6586 ··-·audit_arch·==·"b64"
6587 ··tags:6587 ··tags:
6588 ··-·CJIS-5.4.1.16588 ··-·CJIS-5.4.1.1
6589 ··-·DISA-STIG-RHEL-07-0304106589 ··-·DISA-STIG-RHEL-07-030410
6590 ··-·NIST-800-171-3.1.76590 ··-·NIST-800-171-3.1.7
6591 ··-·NIST-800-53-AU-12(c)6591 ··-·NIST-800-53-AU-12(c)
6592 ··-·NIST-800-53-AU-2(d)6592 ··-·NIST-800-53-AU-2(d)
Offset 6596, 15 lines modifiedOffset 6596, 15 lines modified
6596 ··-·low_complexity6596 ··-·low_complexity
6597 ··-·low_disruption6597 ··-·low_disruption
6598 ··-·medium_severity6598 ··-·medium_severity
6599 ··-·reboot_required6599 ··-·reboot_required
6600 ··-·restrict_strategy6600 ··-·restrict_strategy
6601 Remediation_Shell_script_⇲6601 Remediation_Shell_script_⇲
6602 #·Remediation·is·applicable·only·in·certain·platforms6602 #·Remediation·is·applicable·only·in·certain·platforms
6603 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then6603 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
6604 #·First·perform·the·remediation·of·the·syscall·rule6604 #·First·perform·the·remediation·of·the·syscall·rule
6605 #·Retrieve·hardware·architecture·of·the·underlying·system6605 #·Retrieve·hardware·architecture·of·the·underlying·system
6606 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")6606 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
6607 for·ARCH·in·"${RULE_ARCHS[@]}"6607 for·ARCH·in·"${RULE_ARCHS[@]}"
6608 do6608 do
Offset 6965, 16 lines modifiedOffset 6965, 16 lines modified
6965 ··-·reboot_required6965 ··-·reboot_required
6966 ··-·restrict_strategy6966 ··-·restrict_strategy
  
6967 -·name:·Set·architecture·for·audit·chown·tasks6967 -·name:·Set·architecture·for·audit·chown·tasks
6968 ··set_fact:6968 ··set_fact:
6969 ····audit_arch:·b646969 ····audit_arch:·b64
6970 ··when:6970 ··when:
6971 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
6972 ··-·'"audit"·in·ansible_facts.packages'6971 ··-·'"audit"·in·ansible_facts.packages'
 6972 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
6973 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture6973 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
6974 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"6974 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
6975 ··tags:6975 ··tags:
6976 ··-·CJIS-5.4.1.16976 ··-·CJIS-5.4.1.1
6977 ··-·DISA-STIG-RHEL-07-0303706977 ··-·DISA-STIG-RHEL-07-030370
6978 ··-·NIST-800-171-3.1.76978 ··-·NIST-800-171-3.1.7
6979 ··-·NIST-800-53-AU-12(c)6979 ··-·NIST-800-53-AU-12(c)
Offset 7113, 16 lines modifiedOffset 7113, 16 lines modified
7113 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10007113 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
7114 ········-F·auid!=unset·-F·key=perm_mod7114 ········-F·auid!=unset·-F·key=perm_mod
7115 ······create:·true7115 ······create:·true
7116 ······mode:·o-rwx7116 ······mode:·o-rwx
7117 ······state:·present7117 ······state:·present
7118 ····when:·syscalls_found·|·length·==·07118 ····when:·syscalls_found·|·length·==·0
7119 ··when:7119 ··when:
7120 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
7121 ··-·'"audit"·in·ansible_facts.packages'7120 ··-·'"audit"·in·ansible_facts.packages'
 7121 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
7122 ··tags:7122 ··tags:
7123 ··-·CJIS-5.4.1.17123 ··-·CJIS-5.4.1.1
7124 ··-·DISA-STIG-RHEL-07-0303707124 ··-·DISA-STIG-RHEL-07-030370
7125 ··-·NIST-800-171-3.1.77125 ··-·NIST-800-171-3.1.7
7126 ··-·NIST-800-53-AU-12(c)7126 ··-·NIST-800-53-AU-12(c)
7127 ··-·NIST-800-53-AU-2(d)7127 ··-·NIST-800-53-AU-2(d)
7128 ··-·NIST-800-53-CM-6(a)7128 ··-·NIST-800-53-CM-6(a)
Offset 7259, 16 lines modifiedOffset 7259, 16 lines modified
7259 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10007259 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
7260 ········-F·auid!=unset·-F·key=perm_mod7260 ········-F·auid!=unset·-F·key=perm_mod
7261 ······create:·true7261 ······create:·true
7262 ······mode:·o-rwx7262 ······mode:·o-rwx
7263 ······state:·present7263 ······state:·present
Max diff block lines reached; 132163/136925 bytes (96.52%) of diff not shown.
407 KB
./usr/share/doc/ssg-nondebian/ssg-centos7-guide-standard.html
    
Offset 14457, 16 lines modifiedOffset 14457, 16 lines modified
00038780:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>00038780:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>
00038790:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi00038790:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi
000387a0:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.000387a0:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.
000387b0:·3635·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··65</strong></p><000387b0:·3635·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··65</strong></p><
000387c0:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d000387c0:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d
000387d0:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··000387d0:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··
000387e0:·2020·2020·2020·2020·2020·2020·2020·2020··················000387e0:·2020·2020·2020·2020·2020·2020·2020·2020··················
000387f0:·2020·2861·7320·6f66·2032·3032·342d·3031····(as·of·2024-01000387f0:·2020·2861·7320·6f66·2032·3032·352d·3032····(as·of·2025-02
00038800:·2d31·3429·0a20·2020·2020·2020·2020·2020··-14).···········00038800:·2d31·3529·0a20·2020·2020·2020·2020·2020··-15).···········
00038810:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><00038810:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><
00038820:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o00038820:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o
00038830:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><00038830:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><
00038840:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="00038840:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="
00038850:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr00038850:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr
00038860:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr00038860:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr
00038870:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst00038870:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst
Offset 23962, 23 lines modifiedOffset 23962, 23 lines modified
0005d990:·6571·7569·7265·640a·2020·2d20·7265·7374··equired.··-·rest0005d990:·6571·7569·7265·640a·2020·2d20·7265·7374··equired.··-·rest
0005d9a0:·7269·6374·5f73·7472·6174·6567·790a·0a2d··rict_strategy..-0005d9a0:·7269·6374·5f73·7472·6174·6567·790a·0a2d··rict_strategy..-
0005d9b0:·206e·616d·653a·2053·6574·2061·7263·6869···name:·Set·archi0005d9b0:·206e·616d·653a·2053·6574·2061·7263·6869···name:·Set·archi
0005d9c0:·7465·6374·7572·6520·666f·7220·6175·6469··tecture·for·audi0005d9c0:·7465·6374·7572·6520·666f·7220·6175·6469··tecture·for·audi
0005d9d0:·7420·6368·6d6f·6420·7461·736b·730a·2020··t·chmod·tasks.··0005d9d0:·7420·6368·6d6f·6420·7461·736b·730a·2020··t·chmod·tasks.··
0005d9e0:·7365·745f·6661·6374·3a0a·2020·2020·6175··set_fact:.····au0005d9e0:·7365·745f·6661·6374·3a0a·2020·2020·6175··set_fact:.····au
0005d9f0:·6469·745f·6172·6368·3a20·6236·340a·2020··dit_arch:·b64.··0005d9f0:·6469·745f·6172·6368·3a20·6236·340a·2020··dit_arch:·b64.··
0005da00:·7768·656e·3a0a·2020·2d20·616e·7369·626c··when:.··-·ansibl0005da00:·7768·656e·3a0a·2020·2d20·2722·6175·6469··when:.··-·'"audi
0005da10:·655f·7669·7274·7561·6c69·7a61·7469·6f6e··e_virtualization 
0005da20:·5f74·7970·6520·6e6f·7420·696e·205b·2264··_type·not·in·["d 
0005da30:·6f63·6b65·7222·2c20·226c·7863·222c·2022··ocker",·"lxc",·" 
0005da40:·6f70·656e·767a·222c·2022·706f·646d·616e··openvz",·"podman 
0005da50:·222c·2022·636f·6e74·6169·6e65·7222·5d0a··",·"container"]. 
0005da60:·2020·2d20·2722·6175·6469·7422·2069·6e20····-·'"audit"·in· 
0005da70:·616e·7369·626c·655f·6661·6374·732e·7061··ansible_facts.pa0005da10:·7422·2069·6e20·616e·7369·626c·655f·6661··t"·in·ansible_fa
 0005da20:·6374·732e·7061·636b·6167·6573·270a·2020··cts.packages'.··
 0005da30:·2d20·616e·7369·626c·655f·7669·7274·7561··-·ansible_virtua
 0005da40:·6c69·7a61·7469·6f6e·5f74·7970·6520·6e6f··lization_type·no
 0005da50:·7420·696e·205b·2264·6f63·6b65·7222·2c20··t·in·["docker",·
 0005da60:·226c·7863·222c·2022·6f70·656e·767a·222c··"lxc",·"openvz",
 0005da70:·2022·706f·646d·616e·222c·2022·636f·6e74···"podman",·"cont
0005da80:·636b·6167·6573·270a·2020·2d20·616e·7369··ckages'.··-·ansi0005da80:·6169·6e65·7222·5d0a·2020·2d20·616e·7369··ainer"].··-·ansi
0005da90:·626c·655f·6172·6368·6974·6563·7475·7265··ble_architecture0005da90:·626c·655f·6172·6368·6974·6563·7475·7265··ble_architecture
0005daa0:·203d·3d20·2261·6172·6368·3634·2220·6f72···==·"aarch64"·or0005daa0:·203d·3d20·2261·6172·6368·3634·2220·6f72···==·"aarch64"·or
0005dab0:·2061·6e73·6962·6c65·5f61·7263·6869·7465···ansible_archite0005dab0:·2061·6e73·6962·6c65·5f61·7263·6869·7465···ansible_archite
0005dac0:·6374·7572·6520·3d3d·2022·7070·6336·3422··cture·==·"ppc64"0005dac0:·6374·7572·6520·3d3d·2022·7070·6336·3422··cture·==·"ppc64"
0005dad0:·206f·7220·616e·7369·626c·655f·6172·6368···or·ansible_arch0005dad0:·206f·7220·616e·7369·626c·655f·6172·6368···or·ansible_arch
0005dae0:·6974·6563·7475·7265·0a20·2020·203d·3d20··itecture.····==·0005dae0:·6974·6563·7475·7265·0a20·2020·203d·3d20··itecture.····==·
0005daf0:·2270·7063·3634·6c65·2220·6f72·2061·6e73··"ppc64le"·or·ans0005daf0:·2270·7063·3634·6c65·2220·6f72·2061·6e73··"ppc64le"·or·ans
Offset 24285, 23 lines modifiedOffset 24285, 23 lines modified
0005edc0:·2d46·206b·6579·3d70·6572·6d5f·6d6f·640a··-F·key=perm_mod.0005edc0:·2d46·206b·6579·3d70·6572·6d5f·6d6f·640a··-F·key=perm_mod.
0005edd0:·2020·2020·2020·6372·6561·7465·3a20·7472········create:·tr0005edd0:·2020·2020·2020·6372·6561·7465·3a20·7472········create:·tr
0005ede0:·7565·0a20·2020·2020·206d·6f64·653a·206f··ue.······mode:·o0005ede0:·7565·0a20·2020·2020·206d·6f64·653a·206f··ue.······mode:·o
0005edf0:·2d72·7778·0a20·2020·2020·2073·7461·7465··-rwx.······state0005edf0:·2d72·7778·0a20·2020·2020·2073·7461·7465··-rwx.······state
0005ee00:·3a20·7072·6573·656e·740a·2020·2020·7768··:·present.····wh0005ee00:·3a20·7072·6573·656e·740a·2020·2020·7768··:·present.····wh
0005ee10:·656e·3a20·7379·7363·616c·6c73·5f66·6f75··en:·syscalls_fou0005ee10:·656e·3a20·7379·7363·616c·6c73·5f66·6f75··en:·syscalls_fou
0005ee20:·6e64·207c·206c·656e·6774·6820·3d3d·2030··nd·|·length·==·00005ee20:·6e64·207c·206c·656e·6774·6820·3d3d·2030··nd·|·length·==·0
0005ee30:·0a20·2077·6865·6e3a·0a20·202d·2061·6e73··.··when:.··-·ans0005ee30:·0a20·2077·6865·6e3a·0a20·202d·2027·2261··.··when:.··-·'"a
0005ee40:·6962·6c65·5f76·6972·7475·616c·697a·6174··ible_virtualizat 
0005ee50:·696f·6e5f·7479·7065·206e·6f74·2069·6e20··ion_type·not·in· 
0005ee60:·5b22·646f·636b·6572·222c·2022·6c78·6322··["docker",·"lxc" 
0005ee70:·2c20·226f·7065·6e76·7a22·2c20·2270·6f64··,·"openvz",·"pod 
0005ee80:·6d61·6e22·2c20·2263·6f6e·7461·696e·6572··man",·"container 
0005ee90:·225d·0a20·202d·2027·2261·7564·6974·2220··"].··-·'"audit"· 
0005eea0:·696e·2061·6e73·6962·6c65·5f66·6163·7473··in·ansible_facts 
0005eeb0:·2e70·6163·6b61·6765·7327·0a20·2074·6167··.packages'.··tag0005ee40:·7564·6974·2220·696e·2061·6e73·6962·6c65··udit"·in·ansible
 0005ee50:·5f66·6163·7473·2e70·6163·6b61·6765·7327··_facts.packages'
 0005ee60:·0a20·202d·2061·6e73·6962·6c65·5f76·6972··.··-·ansible_vir
 0005ee70:·7475·616c·697a·6174·696f·6e5f·7479·7065··tualization_type
 0005ee80:·206e·6f74·2069·6e20·5b22·646f·636b·6572···not·in·["docker
 0005ee90:·222c·2022·6c78·6322·2c20·226f·7065·6e76··",·"lxc",·"openv
 0005eea0:·7a22·2c20·2270·6f64·6d61·6e22·2c20·2263··z",·"podman",·"c
 0005eeb0:·6f6e·7461·696e·6572·225d·0a20·2074·6167··ontainer"].··tag
0005eec0:·733a·0a20·202d·2043·4a49·532d·352e·342e··s:.··-·CJIS-5.4.0005eec0:·733a·0a20·202d·2043·4a49·532d·352e·342e··s:.··-·CJIS-5.4.
0005eed0:·312e·310a·2020·2d20·4449·5341·2d53·5449··1.1.··-·DISA-STI0005eed0:·312e·310a·2020·2d20·4449·5341·2d53·5449··1.1.··-·DISA-STI
0005eee0:·472d·5248·454c·2d30·372d·3033·3034·3130··G-RHEL-07-0304100005eee0:·472d·5248·454c·2d30·372d·3033·3034·3130··G-RHEL-07-030410
0005eef0:·0a20·202d·204e·4953·542d·3830·302d·3137··.··-·NIST-800-170005eef0:·0a20·202d·204e·4953·542d·3830·302d·3137··.··-·NIST-800-17
0005ef00:·312d·332e·312e·370a·2020·2d20·4e49·5354··1-3.1.7.··-·NIST0005ef00:·312d·332e·312e·370a·2020·2d20·4e49·5354··1-3.1.7.··-·NIST
0005ef10:·2d38·3030·2d35·332d·4155·2d31·3228·6329··-800-53-AU-12(c)0005ef10:·2d38·3030·2d35·332d·4155·2d31·3228·6329··-800-53-AU-12(c)
0005ef20:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-530005ef20:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
Offset 24597, 23 lines modifiedOffset 24597, 23 lines modified
00060140:·3d70·6572·6d5f·6d6f·640a·2020·2020·2020··=perm_mod.······00060140:·3d70·6572·6d5f·6d6f·640a·2020·2020·2020··=perm_mod.······
00060150:·6372·6561·7465·3a20·7472·7565·0a20·2020··create:·true.···00060150:·6372·6561·7465·3a20·7472·7565·0a20·2020··create:·true.···
00060160:·2020·206d·6f64·653a·206f·2d72·7778·0a20·····mode:·o-rwx.·00060160:·2020·206d·6f64·653a·206f·2d72·7778·0a20·····mode:·o-rwx.·
00060170:·2020·2020·2073·7461·7465·3a20·7072·6573·······state:·pres00060170:·2020·2020·2073·7461·7465·3a20·7072·6573·······state:·pres
00060180:·656e·740a·2020·2020·7768·656e·3a20·7379··ent.····when:·sy00060180:·656e·740a·2020·2020·7768·656e·3a20·7379··ent.····when:·sy
00060190:·7363·616c·6c73·5f66·6f75·6e64·207c·206c··scalls_found·|·l00060190:·7363·616c·6c73·5f66·6f75·6e64·207c·206c··scalls_found·|·l
000601a0:·656e·6774·6820·3d3d·2030·0a20·2077·6865··ength·==·0.··whe000601a0:·656e·6774·6820·3d3d·2030·0a20·2077·6865··ength·==·0.··whe
000601b0:·6e3a·0a20·202d·2061·6e73·6962·6c65·5f76··n:.··-·ansible_v 
000601c0:·6972·7475·616c·697a·6174·696f·6e5f·7479··irtualization_ty 
000601d0:·7065·206e·6f74·2069·6e20·5b22·646f·636b··pe·not·in·["dock 
000601e0:·6572·222c·2022·6c78·6322·2c20·226f·7065··er",·"lxc",·"ope 
000601f0:·6e76·7a22·2c20·2270·6f64·6d61·6e22·2c20··nvz",·"podman",· 
00060200:·2263·6f6e·7461·696e·6572·225d·0a20·202d··"container"].··- 
00060210:·2027·2261·7564·6974·2220·696e·2061·6e73···'"audit"·in·ans 
00060220:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa000601b0:·6e3a·0a20·202d·2027·2261·7564·6974·2220··n:.··-·'"audit"·
 000601c0:·696e·2061·6e73·6962·6c65·5f66·6163·7473··in·ansible_facts
 000601d0:·2e70·6163·6b61·6765·7327·0a20·202d·2061··.packages'.··-·a
 000601e0:·6e73·6962·6c65·5f76·6972·7475·616c·697a··nsible_virtualiz
 000601f0:·6174·696f·6e5f·7479·7065·206e·6f74·2069··ation_type·not·i
 00060200:·6e20·5b22·646f·636b·6572·222c·2022·6c78··n·["docker",·"lx
 00060210:·6322·2c20·226f·7065·6e76·7a22·2c20·2270··c",·"openvz",·"p
 00060220:·6f64·6d61·6e22·2c20·2263·6f6e·7461·696e··odman",·"contain
00060230:·6765·7327·0a20·202d·2061·7564·6974·5f61··ges'.··-·audit_a00060230:·6572·225d·0a20·202d·2061·7564·6974·5f61··er"].··-·audit_a
00060240:·7263·6820·3d3d·2022·6236·3422·0a20·2074··rch·==·"b64".··t00060240:·7263·6820·3d3d·2022·6236·3422·0a20·2074··rch·==·"b64".··t
00060250:·6167·733a·0a20·202d·2043·4a49·532d·352e··ags:.··-·CJIS-5.00060250:·6167·733a·0a20·202d·2043·4a49·532d·352e··ags:.··-·CJIS-5.
00060260:·342e·312e·310a·2020·2d20·4449·5341·2d53··4.1.1.··-·DISA-S00060260:·342e·312e·310a·2020·2d20·4449·5341·2d53··4.1.1.··-·DISA-S
00060270:·5449·472d·5248·454c·2d30·372d·3033·3034··TIG-RHEL-07-030400060270:·5449·472d·5248·454c·2d30·372d·3033·3034··TIG-RHEL-07-0304
00060280:·3130·0a20·202d·204e·4953·542d·3830·302d··10.··-·NIST-800-00060280:·3130·0a20·202d·204e·4953·542d·3830·302d··10.··-·NIST-800-
00060290:·3137·312d·332e·312e·370a·2020·2d20·4e49··171-3.1.7.··-·NI00060290:·3137·312d·332e·312e·370a·2020·2d20·4e49··171-3.1.7.··-·NI
000602a0:·5354·2d38·3030·2d35·332d·4155·2d31·3228··ST-800-53-AU-12(000602a0:·5354·2d38·3030·2d35·332d·4155·2d31·3228··ST-800-53-AU-12(
Offset 24647, 20 lines modifiedOffset 24647, 20 lines modified
00060460:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co00060460:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
00060470:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"00060470:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
00060480:·2069·643d·2269·646d·3137·3133·3322·3e3c···id="idm17133"><00060480:·2069·643d·2269·646d·3137·3133·3322·3e3c···id="idm17133"><
00060490:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme00060490:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme
000604a0:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli000604a0:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli
000604b0:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce000604b0:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce
000604c0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.000604c0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.
 000604d0:·6966·2072·706d·202d·2d71·7569·6574·202d··if·rpm·--quiet·-
 000604e0:·7120·6175·6469·7420·2661·6d70·3b26·616d··q·audit·&amp;&am
000604d0:·6966·205b·2021·202d·6620·2f2e·646f·636b··if·[·!·-f·/.dock000604f0:·703b·205b·2021·202d·6620·2f2e·646f·636b··p;·[·!·-f·/.dock
000604e0:·6572·656e·7620·5d20·2661·6d70·3b26·616d··erenv·]·&amp;&am00060500:·6572·656e·7620·5d20·2661·6d70·3b26·616d··erenv·]·&amp;&am
000604f0:·703b·205b·2021·202d·6620·2f72·756e·2f2e··p;·[·!·-f·/run/.00060510:·703b·205b·2021·202d·6620·2f72·756e·2f2e··p;·[·!·-f·/run/.
00060500:·636f·6e74·6169·6e65·7265·6e76·205d·2026··containerenv·]·&00060520:·636f·6e74·6169·6e65·7265·6e76·205d·3b20··containerenv·];·
00060510:·616d·703b·2661·6d70·3b20·7270·6d20·2d2d··amp;&amp;·rpm·-- 
00060520:·7175·6965·7420·2d71·2061·7564·6974·3b20··quiet·-q·audit;· 
00060530:·7468·656e·0a0a·2320·4669·7273·7420·7065··then..#·First·pe00060530:·7468·656e·0a0a·2320·4669·7273·7420·7065··then..#·First·pe
00060540:·7266·6f72·6d20·7468·6520·7265·6d65·6469··rform·the·remedi00060540:·7266·6f72·6d20·7468·6520·7265·6d65·6469··rform·the·remedi
00060550:·6174·696f·6e20·6f66·2074·6865·2073·7973··ation·of·the·sys00060550:·6174·696f·6e20·6f66·2074·6865·2073·7973··ation·of·the·sys
Max diff block lines reached; 304463/314046 bytes (96.95%) of diff not shown.
100 KB
html2text {}
    
Offset 61, 15 lines modifiedOffset 61, 15 lines modified
61 ····*·cpe:/o:redhat:enterprise_linux:7::computenode61 ····*·cpe:/o:redhat:enterprise_linux:7::computenode
62 ····*·cpe:/o:redhat:enterprise_linux:7::server62 ····*·cpe:/o:redhat:enterprise_linux:7::server
63 ····*·cpe:/o:redhat:enterprise_linux:7::workstation63 ····*·cpe:/o:redhat:enterprise_linux:7::workstation
64 ····*·cpe:/o:redhat:enterprise_linux:764 ····*·cpe:/o:redhat:enterprise_linux:7
65 ····*·cpe:/o:centos:centos:765 ····*·cpe:/o:centos:centos:7
66 *****·Revision·History·*****66 *****·Revision·History·*****
67 Current·version:·0.1.6567 Current·version:·0.1.65
68 ····*·draft·(as·of·2024-01-14)68 ····*·draft·(as·of·2025-02-15)
69 *****·Table·of·Contents·*****69 *****·Table·of·Contents·*****
70 ···1.·System_Settings70 ···1.·System_Settings
71 ·········1.·Installing_and_Maintaining_Software71 ·········1.·Installing_and_Maintaining_Software
72 ·········2.·Account_and_Access_Control72 ·········2.·Account_and_Access_Control
73 ·········3.·System_Accounting_with_auditd73 ·········3.·System_Accounting_with_auditd
74 ·········4.·Configure_Syslog74 ·········4.·Configure_Syslog
75 ·········5.·File_Permissions_and_Masks75 ·········5.·File_Permissions_and_Masks
Offset 1100, 16 lines modifiedOffset 1100, 16 lines modified
1100 ··-·reboot_required1100 ··-·reboot_required
1101 ··-·restrict_strategy1101 ··-·restrict_strategy
  
1102 -·name:·Set·architecture·for·audit·chmod·tasks1102 -·name:·Set·architecture·for·audit·chmod·tasks
1103 ··set_fact:1103 ··set_fact:
1104 ····audit_arch:·b641104 ····audit_arch:·b64
1105 ··when:1105 ··when:
1106 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1107 ··-·'"audit"·in·ansible_facts.packages'1106 ··-·'"audit"·in·ansible_facts.packages'
 1107 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1108 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture1108 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
1109 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"1109 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
1110 ··tags:1110 ··tags:
1111 ··-·CJIS-5.4.1.11111 ··-·CJIS-5.4.1.1
1112 ··-·DISA-STIG-RHEL-07-0304101112 ··-·DISA-STIG-RHEL-07-030410
1113 ··-·NIST-800-171-3.1.71113 ··-·NIST-800-171-3.1.7
1114 ··-·NIST-800-53-AU-12(c)1114 ··-·NIST-800-53-AU-12(c)
Offset 1246, 16 lines modifiedOffset 1246, 16 lines modified
1246 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10001246 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
1247 ········-F·auid!=unset·-F·key=perm_mod1247 ········-F·auid!=unset·-F·key=perm_mod
1248 ······create:·true1248 ······create:·true
1249 ······mode:·o-rwx1249 ······mode:·o-rwx
1250 ······state:·present1250 ······state:·present
1251 ····when:·syscalls_found·|·length·==·01251 ····when:·syscalls_found·|·length·==·0
1252 ··when:1252 ··when:
1253 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1254 ··-·'"audit"·in·ansible_facts.packages'1253 ··-·'"audit"·in·ansible_facts.packages'
 1254 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1255 ··tags:1255 ··tags:
1256 ··-·CJIS-5.4.1.11256 ··-·CJIS-5.4.1.1
1257 ··-·DISA-STIG-RHEL-07-0304101257 ··-·DISA-STIG-RHEL-07-030410
1258 ··-·NIST-800-171-3.1.71258 ··-·NIST-800-171-3.1.7
1259 ··-·NIST-800-53-AU-12(c)1259 ··-·NIST-800-53-AU-12(c)
1260 ··-·NIST-800-53-AU-2(d)1260 ··-·NIST-800-53-AU-2(d)
1261 ··-·NIST-800-53-CM-6(a)1261 ··-·NIST-800-53-CM-6(a)
Offset 1390, 16 lines modifiedOffset 1390, 16 lines modified
1390 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10001390 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
1391 ········-F·auid!=unset·-F·key=perm_mod1391 ········-F·auid!=unset·-F·key=perm_mod
1392 ······create:·true1392 ······create:·true
1393 ······mode:·o-rwx1393 ······mode:·o-rwx
1394 ······state:·present1394 ······state:·present
1395 ····when:·syscalls_found·|·length·==·01395 ····when:·syscalls_found·|·length·==·0
1396 ··when:1396 ··when:
1397 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1398 ··-·'"audit"·in·ansible_facts.packages'1397 ··-·'"audit"·in·ansible_facts.packages'
 1398 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1399 ··-·audit_arch·==·"b64"1399 ··-·audit_arch·==·"b64"
1400 ··tags:1400 ··tags:
1401 ··-·CJIS-5.4.1.11401 ··-·CJIS-5.4.1.1
1402 ··-·DISA-STIG-RHEL-07-0304101402 ··-·DISA-STIG-RHEL-07-030410
1403 ··-·NIST-800-171-3.1.71403 ··-·NIST-800-171-3.1.7
1404 ··-·NIST-800-53-AU-12(c)1404 ··-·NIST-800-53-AU-12(c)
1405 ··-·NIST-800-53-AU-2(d)1405 ··-·NIST-800-53-AU-2(d)
Offset 1409, 15 lines modifiedOffset 1409, 15 lines modified
1409 ··-·low_complexity1409 ··-·low_complexity
1410 ··-·low_disruption1410 ··-·low_disruption
1411 ··-·medium_severity1411 ··-·medium_severity
1412 ··-·reboot_required1412 ··-·reboot_required
1413 ··-·restrict_strategy1413 ··-·restrict_strategy
1414 Remediation_Shell_script_⇲1414 Remediation_Shell_script_⇲
1415 #·Remediation·is·applicable·only·in·certain·platforms1415 #·Remediation·is·applicable·only·in·certain·platforms
1416 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then1416 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
1417 #·First·perform·the·remediation·of·the·syscall·rule1417 #·First·perform·the·remediation·of·the·syscall·rule
1418 #·Retrieve·hardware·architecture·of·the·underlying·system1418 #·Retrieve·hardware·architecture·of·the·underlying·system
1419 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")1419 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
1420 for·ARCH·in·"${RULE_ARCHS[@]}"1420 for·ARCH·in·"${RULE_ARCHS[@]}"
1421 do1421 do
Offset 1778, 16 lines modifiedOffset 1778, 16 lines modified
1778 ··-·reboot_required1778 ··-·reboot_required
1779 ··-·restrict_strategy1779 ··-·restrict_strategy
  
1780 -·name:·Set·architecture·for·audit·chown·tasks1780 -·name:·Set·architecture·for·audit·chown·tasks
1781 ··set_fact:1781 ··set_fact:
1782 ····audit_arch:·b641782 ····audit_arch:·b64
1783 ··when:1783 ··when:
1784 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1785 ··-·'"audit"·in·ansible_facts.packages'1784 ··-·'"audit"·in·ansible_facts.packages'
 1785 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1786 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture1786 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
1787 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"1787 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
1788 ··tags:1788 ··tags:
1789 ··-·CJIS-5.4.1.11789 ··-·CJIS-5.4.1.1
1790 ··-·DISA-STIG-RHEL-07-0303701790 ··-·DISA-STIG-RHEL-07-030370
1791 ··-·NIST-800-171-3.1.71791 ··-·NIST-800-171-3.1.7
1792 ··-·NIST-800-53-AU-12(c)1792 ··-·NIST-800-53-AU-12(c)
Offset 1926, 16 lines modifiedOffset 1926, 16 lines modified
1926 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10001926 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
1927 ········-F·auid!=unset·-F·key=perm_mod1927 ········-F·auid!=unset·-F·key=perm_mod
1928 ······create:·true1928 ······create:·true
1929 ······mode:·o-rwx1929 ······mode:·o-rwx
1930 ······state:·present1930 ······state:·present
1931 ····when:·syscalls_found·|·length·==·01931 ····when:·syscalls_found·|·length·==·0
1932 ··when:1932 ··when:
1933 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1934 ··-·'"audit"·in·ansible_facts.packages'1933 ··-·'"audit"·in·ansible_facts.packages'
 1934 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1935 ··tags:1935 ··tags:
1936 ··-·CJIS-5.4.1.11936 ··-·CJIS-5.4.1.1
1937 ··-·DISA-STIG-RHEL-07-0303701937 ··-·DISA-STIG-RHEL-07-030370
1938 ··-·NIST-800-171-3.1.71938 ··-·NIST-800-171-3.1.7
1939 ··-·NIST-800-53-AU-12(c)1939 ··-·NIST-800-53-AU-12(c)
1940 ··-·NIST-800-53-AU-2(d)1940 ··-·NIST-800-53-AU-2(d)
1941 ··-·NIST-800-53-CM-6(a)1941 ··-·NIST-800-53-CM-6(a)
Offset 2072, 16 lines modifiedOffset 2072, 16 lines modified
2072 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002072 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2073 ········-F·auid!=unset·-F·key=perm_mod2073 ········-F·auid!=unset·-F·key=perm_mod
2074 ······create:·true2074 ······create:·true
2075 ······mode:·o-rwx2075 ······mode:·o-rwx
2076 ······state:·present2076 ······state:·present
Max diff block lines reached; 97603/102361 bytes (95.35%) of diff not shown.
7.1 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-anssi_bp28_enhanced.html
    
Offset 14554, 15 lines modifiedOffset 14554, 15 lines modified
00038d90:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v00038d90:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v
00038da0:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>00038da0:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>
00038db0:·302e·312e·3635·3c2f·7374·726f·6e67·3e3c··0.1.65</strong><00038db0:·302e·312e·3635·3c2f·7374·726f·6e67·3e3c··0.1.65</strong><
00038dc0:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro00038dc0:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro
00038dd0:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong00038dd0:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong
00038de0:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············00038de0:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············
00038df0:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·20200038df0:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·202
00038e00:·342d·3031·2d31·3429·0a20·2020·2020·2020··4-01-14).·······00038e00:·352d·3032·2d31·3529·0a20·2020·2020·2020··5-02-15).·······
00038e10:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></00038e10:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></
00038e20:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab00038e20:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab
00038e30:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</00038e30:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</
00038e40:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr00038e40:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr
00038e50:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s00038e50:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s
00038e60:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten00038e60:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten
00038e70:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">00038e70:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">
Offset 54859, 23 lines modifiedOffset 54859, 23 lines modified
000d64a0:·7072·6976·696c·6567·6564·0a20·2020·2020··privileged.·····000d64a0:·7072·6976·696c·6567·6564·0a20·2020·2020··privileged.·····
000d64b0:·2063·7265·6174·653a·2074·7275·650a·2020···create:·true.··000d64b0:·2063·7265·6174·653a·2074·7275·650a·2020···create:·true.··
000d64c0:·2020·2020·6d6f·6465·3a20·6f2d·7277·780a······mode:·o-rwx.000d64c0:·2020·2020·6d6f·6465·3a20·6f2d·7277·780a······mode:·o-rwx.
000d64d0:·2020·2020·2020·7374·6174·653a·2070·7265········state:·pre000d64d0:·2020·2020·2020·7374·6174·653a·2070·7265········state:·pre
000d64e0:·7365·6e74·0a20·2020·2077·6865·6e3a·2073··sent.····when:·s000d64e0:·7365·6e74·0a20·2020·2077·6865·6e3a·2073··sent.····when:·s
000d64f0:·7973·6361·6c6c·735f·666f·756e·6420·7c20··yscalls_found·|·000d64f0:·7973·6361·6c6c·735f·666f·756e·6420·7c20··yscalls_found·|·
000d6500:·6c65·6e67·7468·203d·3d20·300a·2020·7768··length·==·0.··wh000d6500:·6c65·6e67·7468·203d·3d20·300a·2020·7768··length·==·0.··wh
000d6510:·656e·3a0a·2020·2d20·2722·6175·6469·7422··en:.··-·'"audit" 
000d6520:·2069·6e20·616e·7369·626c·655f·6661·6374···in·ansible_fact 
000d6530:·732e·7061·636b·6167·6573·270a·2020·2d20··s.packages'.··-· 
000d6540:·616e·7369·626c·655f·7669·7274·7561·6c69··ansible_virtuali 
000d6550:·7a61·7469·6f6e·5f74·7970·6520·6e6f·7420··zation_type·not· 
000d6560:·696e·205b·2264·6f63·6b65·7222·2c20·226c··in·["docker",·"l 
000d6570:·7863·222c·2022·6f70·656e·767a·222c·2022··xc",·"openvz",·" 
000d6580:·706f·646d·616e·222c·2022·636f·6e74·6169··podman",·"contai000d6510:·656e·3a0a·2020·2d20·616e·7369·626c·655f··en:.··-·ansible_
 000d6520:·7669·7274·7561·6c69·7a61·7469·6f6e·5f74··virtualization_t
 000d6530:·7970·6520·6e6f·7420·696e·205b·2264·6f63··ype·not·in·["doc
 000d6540:·6b65·7222·2c20·226c·7863·222c·2022·6f70··ker",·"lxc",·"op
 000d6550:·656e·767a·222c·2022·706f·646d·616e·222c··envz",·"podman",
 000d6560:·2022·636f·6e74·6169·6e65·7222·5d0a·2020···"container"].··
 000d6570:·2d20·2722·6175·6469·7422·2069·6e20·616e··-·'"audit"·in·an
 000d6580:·7369·626c·655f·6661·6374·732e·7061·636b··sible_facts.pack
000d6590:·6e65·7222·5d0a·2020·7461·6773·3a0a·2020··ner"].··tags:.··000d6590:·6167·6573·270a·2020·7461·6773·3a0a·2020··ages'.··tags:.··
000d65a0:·2d20·4449·5341·2d53·5449·472d·5248·454c··-·DISA-STIG-RHEL000d65a0:·2d20·4449·5341·2d53·5449·472d·5248·454c··-·DISA-STIG-RHEL
000d65b0:·2d30·382d·3033·3035·3530·0a20·202d·204e··-08-030550.··-·N000d65b0:·2d30·382d·3033·3035·3530·0a20·202d·204e··-08-030550.··-·N
000d65c0:·4953·542d·3830·302d·3137·312d·332e·312e··IST-800-171-3.1.000d65c0:·4953·542d·3830·302d·3137·312d·332e·312e··IST-800-171-3.1.
000d65d0:·370a·2020·2d20·4e49·5354·2d38·3030·2d35··7.··-·NIST-800-5000d65d0:·370a·2020·2d20·4e49·5354·2d38·3030·2d35··7.··-·NIST-800-5
000d65e0:·332d·4143·2d36·2839·290a·2020·2d20·4e49··3-AC-6(9).··-·NI000d65e0:·332d·4143·2d36·2839·290a·2020·2d20·4e49··3-AC-6(9).··-·NI
000d65f0:·5354·2d38·3030·2d35·332d·4155·2d31·3228··ST-800-53-AU-12(000d65f0:·5354·2d38·3030·2d35·332d·4155·2d31·3228··ST-800-53-AU-12(
000d6600:·6329·0a20·202d·204e·4953·542d·3830·302d··c).··-·NIST-800-000d6600:·6329·0a20·202d·204e·4953·542d·3830·302d··c).··-·NIST-800-
Offset 54906, 21 lines modifiedOffset 54906, 21 lines modified
000d6790:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla000d6790:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
000d67a0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap000d67a0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
000d67b0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=000d67b0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
000d67c0:·2269·646d·3335·3834·3122·3e3c·7072·653e··"idm35841"><pre>000d67c0:·2269·646d·3335·3834·3122·3e3c·7072·653e··"idm35841"><pre>
000d67d0:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat000d67d0:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat
000d67e0:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl000d67e0:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl
000d67f0:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai000d67f0:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai
000d6800:·6e20·706c·6174·666f·726d·730a·6966·2072··n·platforms.if·r000d6800:·6e20·706c·6174·666f·726d·730a·6966·205b··n·platforms.if·[
000d6810:·706d·202d·2d71·7569·6574·202d·7120·6175··pm·--quiet·-q·au 
000d6820:·6469·7420·2661·6d70·3b26·616d·703b·205b··dit·&amp;&amp;·[ 
000d6830:·2021·202d·6620·2f2e·646f·636b·6572·656e···!·-f·/.dockeren000d6810:·2021·202d·6620·2f2e·646f·636b·6572·656e···!·-f·/.dockeren
000d6840:·7620·5d20·2661·6d70·3b26·616d·703b·205b··v·]·&amp;&amp;·[000d6820:·7620·5d20·2661·6d70·3b26·616d·703b·205b··v·]·&amp;&amp;·[
000d6850:·2021·202d·6620·2f72·756e·2f2e·636f·6e74···!·-f·/run/.cont000d6830:·2021·202d·6620·2f72·756e·2f2e·636f·6e74···!·-f·/run/.cont
000d6860:·6169·6e65·7265·6e76·205d·3b20·7468·656e··ainerenv·];·then000d6840:·6169·6e65·7265·6e76·205d·2026·616d·703b··ainerenv·]·&amp;
 000d6850:·2661·6d70·3b20·7270·6d20·2d2d·7175·6965··&amp;·rpm·--quie
 000d6860:·7420·2d71·2061·7564·6974·3b20·7468·656e··t·-q·audit;·then
000d6870:·0a0a·4143·5449·4f4e·5f41·5243·485f·4649··..ACTION_ARCH_FI000d6870:·0a0a·4143·5449·4f4e·5f41·5243·485f·4649··..ACTION_ARCH_FI
000d6880:·4c54·4552·533d·222d·6120·616c·7761·7973··LTERS="-a·always000d6880:·4c54·4552·533d·222d·6120·616c·7761·7973··LTERS="-a·always
000d6890:·2c65·7869·7422·0a4f·5448·4552·5f46·494c··,exit".OTHER_FIL000d6890:·2c65·7869·7422·0a4f·5448·4552·5f46·494c··,exit".OTHER_FIL
000d68a0:·5445·5253·3d22·2d46·2070·6174·683d·2f75··TERS="-F·path=/u000d68a0:·5445·5253·3d22·2d46·2070·6174·683d·2f75··TERS="-F·path=/u
000d68b0:·7372·2f62·696e·2f73·7564·6f20·2d46·2070··sr/bin/sudo·-F·p000d68b0:·7372·2f62·696e·2f73·7564·6f20·2d46·2070··sr/bin/sudo·-F·p
000d68c0:·6572·6d3d·7822·0a41·5549·445f·4649·4c54··erm=x".AUID_FILT000d68c0:·6572·6d3d·7822·0a41·5549·445f·4649·4c54··erm=x".AUID_FILT
000d68d0:·4552·533d·222d·4620·6175·6964·2667·743b··ERS="-F·auid&gt;000d68d0:·4552·533d·222d·4620·6175·6964·2667·743b··ERS="-F·auid&gt;
1.76 KB
html2text {}
    
Offset 72, 15 lines modifiedOffset 72, 15 lines modified
72 ····*·cpe:/o:redhat:enterprise_linux:8.772 ····*·cpe:/o:redhat:enterprise_linux:8.7
73 ····*·cpe:/o:redhat:enterprise_linux:8.873 ····*·cpe:/o:redhat:enterprise_linux:8.8
74 ····*·cpe:/o:redhat:enterprise_linux:8.974 ····*·cpe:/o:redhat:enterprise_linux:8.9
75 ····*·cpe:/o:redhat:enterprise_linux:875 ····*·cpe:/o:redhat:enterprise_linux:8
76 ····*·cpe:/o:centos:centos:876 ····*·cpe:/o:centos:centos:8
77 *****·Revision·History·*****77 *****·Revision·History·*****
78 Current·version:·0.1.6578 Current·version:·0.1.65
79 ····*·draft·(as·of·2024-01-14)79 ····*·draft·(as·of·2025-02-15)
80 *****·Table·of·Contents·*****80 *****·Table·of·Contents·*****
81 ···1.·System_Settings81 ···1.·System_Settings
82 ·········1.·Installing_and_Maintaining_Software82 ·········1.·Installing_and_Maintaining_Software
83 ·········2.·Account_and_Access_Control83 ·········2.·Account_and_Access_Control
84 ·········3.·System_Accounting_with_auditd84 ·········3.·System_Accounting_with_auditd
85 ·········4.·GRUB2_bootloader_configuration85 ·········4.·GRUB2_bootloader_configuration
86 ·········5.·Configure_Syslog86 ·········5.·Configure_Syslog
Offset 8157, 16 lines modifiedOffset 8157, 16 lines modified
8157 ······line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x8157 ······line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
8158 ········-F·auid>=1000·-F·auid!=unset·-F·key=privileged8158 ········-F·auid>=1000·-F·auid!=unset·-F·key=privileged
8159 ······create:·true8159 ······create:·true
8160 ······mode:·o-rwx8160 ······mode:·o-rwx
8161 ······state:·present8161 ······state:·present
8162 ····when:·syscalls_found·|·length·==·08162 ····when:·syscalls_found·|·length·==·0
8163 ··when:8163 ··when:
8164 ··-·'"audit"·in·ansible_facts.packages' 
8165 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8164 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 8165 ··-·'"audit"·in·ansible_facts.packages'
8166 ··tags:8166 ··tags:
8167 ··-·DISA-STIG-RHEL-08-0305508167 ··-·DISA-STIG-RHEL-08-030550
8168 ··-·NIST-800-171-3.1.78168 ··-·NIST-800-171-3.1.7
8169 ··-·NIST-800-53-AC-6(9)8169 ··-·NIST-800-53-AC-6(9)
8170 ··-·NIST-800-53-AU-12(c)8170 ··-·NIST-800-53-AU-12(c)
8171 ··-·NIST-800-53-AU-2(d)8171 ··-·NIST-800-53-AU-2(d)
8172 ··-·NIST-800-53-CM-6(a)8172 ··-·NIST-800-53-CM-6(a)
Offset 8174, 15 lines modifiedOffset 8174, 15 lines modified
8174 ··-·low_complexity8174 ··-·low_complexity
8175 ··-·low_disruption8175 ··-·low_disruption
8176 ··-·medium_severity8176 ··-·medium_severity
8177 ··-·no_reboot_needed8177 ··-·no_reboot_needed
8178 ··-·restrict_strategy8178 ··-·restrict_strategy
8179 Remediation_Shell_script_⇲8179 Remediation_Shell_script_⇲
8180 #·Remediation·is·applicable·only·in·certain·platforms8180 #·Remediation·is·applicable·only·in·certain·platforms
8181 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then8181 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
8182 ACTION_ARCH_FILTERS="-a·always,exit"8182 ACTION_ARCH_FILTERS="-a·always,exit"
8183 OTHER_FILTERS="-F·path=/usr/bin/sudo·-F·perm=x"8183 OTHER_FILTERS="-F·path=/usr/bin/sudo·-F·perm=x"
8184 AUID_FILTERS="-F·auid>=1000·-F·auid!=unset"8184 AUID_FILTERS="-F·auid>=1000·-F·auid!=unset"
8185 SYSCALL=""8185 SYSCALL=""
8186 KEY="privileged"8186 KEY="privileged"
8187 SYSCALL_GROUPING=""8187 SYSCALL_GROUPING=""
6.89 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-anssi_bp28_high.html
    
Offset 14553, 15 lines modifiedOffset 14553, 15 lines modified
00038d80:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v00038d80:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v
00038d90:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>00038d90:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>
00038da0:·302e·312e·3635·3c2f·7374·726f·6e67·3e3c··0.1.65</strong><00038da0:·302e·312e·3635·3c2f·7374·726f·6e67·3e3c··0.1.65</strong><
00038db0:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro00038db0:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro
00038dc0:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong00038dc0:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong
00038dd0:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············00038dd0:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············
00038de0:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·20200038de0:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·202
00038df0:·342d·3031·2d31·3429·0a20·2020·2020·2020··4-01-14).·······00038df0:·352d·3032·2d31·3529·0a20·2020·2020·2020··5-02-15).·······
00038e00:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></00038e00:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></
00038e10:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab00038e10:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab
00038e20:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</00038e20:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</
00038e30:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr00038e30:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr
00038e40:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s00038e40:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s
00038e50:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten00038e50:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten
00038e60:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">00038e60:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">
Offset 56867, 22 lines modifiedOffset 56867, 22 lines modified
000de220:·6765·640a·2020·2020·2020·6372·6561·7465··ged.······create000de220:·6765·640a·2020·2020·2020·6372·6561·7465··ged.······create
000de230:·3a20·7472·7565·0a20·2020·2020·206d·6f64··:·true.······mod000de230:·3a20·7472·7565·0a20·2020·2020·206d·6f64··:·true.······mod
000de240:·653a·206f·2d72·7778·0a20·2020·2020·2073··e:·o-rwx.······s000de240:·653a·206f·2d72·7778·0a20·2020·2020·2073··e:·o-rwx.······s
000de250:·7461·7465·3a20·7072·6573·656e·740a·2020··tate:·present.··000de250:·7461·7465·3a20·7072·6573·656e·740a·2020··tate:·present.··
000de260:·2020·7768·656e·3a20·7379·7363·616c·6c73····when:·syscalls000de260:·2020·7768·656e·3a20·7379·7363·616c·6c73····when:·syscalls
000de270:·5f66·6f75·6e64·207c·206c·656e·6774·6820··_found·|·length·000de270:·5f66·6f75·6e64·207c·206c·656e·6774·6820··_found·|·length·
000de280:·3d3d·2030·0a20·2077·6865·6e3a·0a20·202d··==·0.··when:.··-000de280:·3d3d·2030·0a20·2077·6865·6e3a·0a20·202d··==·0.··when:.··-
000de290:·2027·2261·7564·6974·2220·696e·2061·6e73···'"audit"·in·ans 
000de2a0:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa 
000de2b0:·6765·7327·0a20·202d·2061·6e73·6962·6c65··ges'.··-·ansible 
000de2c0:·5f76·6972·7475·616c·697a·6174·696f·6e5f··_virtualization_ 
000de2d0:·7479·7065·206e·6f74·2069·6e20·5b22·646f··type·not·in·["do 
000de2e0:·636b·6572·222c·2022·6c78·6322·2c20·226f··cker",·"lxc",·"o 
000de2f0:·7065·6e76·7a22·2c20·2270·6f64·6d61·6e22··penvz",·"podman" 
000de300:·2c20·2263·6f6e·7461·696e·6572·225d·0a20··,·"container"].·000de290:·2061·6e73·6962·6c65·5f76·6972·7475·616c···ansible_virtual
 000de2a0:·697a·6174·696f·6e5f·7479·7065·206e·6f74··ization_type·not
 000de2b0:·2069·6e20·5b22·646f·636b·6572·222c·2022···in·["docker",·"
 000de2c0:·6c78·6322·2c20·226f·7065·6e76·7a22·2c20··lxc",·"openvz",·
 000de2d0:·2270·6f64·6d61·6e22·2c20·2263·6f6e·7461··"podman",·"conta
 000de2e0:·696e·6572·225d·0a20·202d·2027·2261·7564··iner"].··-·'"aud
 000de2f0:·6974·2220·696e·2061·6e73·6962·6c65·5f66··it"·in·ansible_f
 000de300:·6163·7473·2e70·6163·6b61·6765·7327·0a20··acts.packages'.·
000de310:·2074·6167·733a·0a20·202d·2044·4953·412d···tags:.··-·DISA-000de310:·2074·6167·733a·0a20·202d·2044·4953·412d···tags:.··-·DISA-
000de320:·5354·4947·2d52·4845·4c2d·3038·2d30·3330··STIG-RHEL-08-030000de320:·5354·4947·2d52·4845·4c2d·3038·2d30·3330··STIG-RHEL-08-030
000de330:·3535·300a·2020·2d20·4e49·5354·2d38·3030··550.··-·NIST-800000de330:·3535·300a·2020·2d20·4e49·5354·2d38·3030··550.··-·NIST-800
000de340:·2d31·3731·2d33·2e31·2e37·0a20·202d·204e··-171-3.1.7.··-·N000de340:·2d31·3731·2d33·2e31·2e37·0a20·202d·204e··-171-3.1.7.··-·N
000de350:·4953·542d·3830·302d·3533·2d41·432d·3628··IST-800-53-AC-6(000de350:·4953·542d·3830·302d·3533·2d41·432d·3628··IST-800-53-AC-6(
000de360:·3929·0a20·202d·204e·4953·542d·3830·302d··9).··-·NIST-800-000de360:·3929·0a20·202d·204e·4953·542d·3830·302d··9).··-·NIST-800-
000de370:·3533·2d41·552d·3132·2863·290a·2020·2d20··53-AU-12(c).··-·000de370:·3533·2d41·552d·3132·2863·290a·2020·2d20··53-AU-12(c).··-·
Offset 56914, 21 lines modifiedOffset 56914, 21 lines modified
000de510:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan000de510:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
000de520:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll000de520:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
000de530:·6170·7365·2220·6964·3d22·6964·6d33·3538··apse"·id="idm358000de530:·6170·7365·2220·6964·3d22·6964·6d33·3538··apse"·id="idm358
000de540:·3431·223e·3c70·7265·3e3c·636f·6465·3e23··41"><pre><code>#000de540:·3431·223e·3c70·7265·3e3c·636f·6465·3e23··41"><pre><code>#
000de550:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·000de550:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
000de560:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·000de560:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
000de570:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf000de570:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
000de580:·6f72·6d73·0a69·6620·7270·6d20·2d2d·7175··orms.if·rpm·--qu000de580:·6f72·6d73·0a69·6620·5b20·2120·2d66·202f··orms.if·[·!·-f·/
000de590:·6965·7420·2d71·2061·7564·6974·2026·616d··iet·-q·audit·&am000de590:·2e64·6f63·6b65·7265·6e76·205d·2026·616d··.dockerenv·]·&am
000de5a0:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/000de5a0:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/
000de5b0:·2e64·6f63·6b65·7265·6e76·205d·2026·616d··.dockerenv·]·&am 
000de5c0:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/ 
000de5d0:·7275·6e2f·2e63·6f6e·7461·696e·6572·656e··run/.containeren000de5b0:·7275·6e2f·2e63·6f6e·7461·696e·6572·656e··run/.containeren
 000de5c0:·7620·5d20·2661·6d70·3b26·616d·703b·2072··v·]·&amp;&amp;·r
 000de5d0:·706d·202d·2d71·7569·6574·202d·7120·6175··pm·--quiet·-q·au
000de5e0:·7620·5d3b·2074·6865·6e0a·0a41·4354·494f··v·];·then..ACTIO000de5e0:·6469·743b·2074·6865·6e0a·0a41·4354·494f··dit;·then..ACTIO
000de5f0:·4e5f·4152·4348·5f46·494c·5445·5253·3d22··N_ARCH_FILTERS="000de5f0:·4e5f·4152·4348·5f46·494c·5445·5253·3d22··N_ARCH_FILTERS="
000de600:·2d61·2061·6c77·6179·732c·6578·6974·220a··-a·always,exit".000de600:·2d61·2061·6c77·6179·732c·6578·6974·220a··-a·always,exit".
000de610:·4f54·4845·525f·4649·4c54·4552·533d·222d··OTHER_FILTERS="-000de610:·4f54·4845·525f·4649·4c54·4552·533d·222d··OTHER_FILTERS="-
000de620:·4620·7061·7468·3d2f·7573·722f·6269·6e2f··F·path=/usr/bin/000de620:·4620·7061·7468·3d2f·7573·722f·6269·6e2f··F·path=/usr/bin/
000de630:·7375·646f·202d·4620·7065·726d·3d78·220a··sudo·-F·perm=x".000de630:·7375·646f·202d·4620·7065·726d·3d78·220a··sudo·-F·perm=x".
000de640:·4155·4944·5f46·494c·5445·5253·3d22·2d46··AUID_FILTERS="-F000de640:·4155·4944·5f46·494c·5445·5253·3d22·2d46··AUID_FILTERS="-F
000de650:·2061·7569·6426·6774·3b3d·3130·3030·202d···auid&gt;=1000·-000de650:·2061·7569·6426·6774·3b3d·3130·3030·202d···auid&gt;=1000·-
1.76 KB
html2text {}
    
Offset 72, 15 lines modifiedOffset 72, 15 lines modified
72 ····*·cpe:/o:redhat:enterprise_linux:8.772 ····*·cpe:/o:redhat:enterprise_linux:8.7
73 ····*·cpe:/o:redhat:enterprise_linux:8.873 ····*·cpe:/o:redhat:enterprise_linux:8.8
74 ····*·cpe:/o:redhat:enterprise_linux:8.974 ····*·cpe:/o:redhat:enterprise_linux:8.9
75 ····*·cpe:/o:redhat:enterprise_linux:875 ····*·cpe:/o:redhat:enterprise_linux:8
76 ····*·cpe:/o:centos:centos:876 ····*·cpe:/o:centos:centos:8
77 *****·Revision·History·*****77 *****·Revision·History·*****
78 Current·version:·0.1.6578 Current·version:·0.1.65
79 ····*·draft·(as·of·2024-01-14)79 ····*·draft·(as·of·2025-02-15)
80 *****·Table·of·Contents·*****80 *****·Table·of·Contents·*****
81 ···1.·System_Settings81 ···1.·System_Settings
82 ·········1.·Installing_and_Maintaining_Software82 ·········1.·Installing_and_Maintaining_Software
83 ·········2.·Account_and_Access_Control83 ·········2.·Account_and_Access_Control
84 ·········3.·System_Accounting_with_auditd84 ·········3.·System_Accounting_with_auditd
85 ·········4.·GRUB2_bootloader_configuration85 ·········4.·GRUB2_bootloader_configuration
86 ·········5.·Configure_Syslog86 ·········5.·Configure_Syslog
Offset 8459, 16 lines modifiedOffset 8459, 16 lines modified
8459 ······line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x8459 ······line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
8460 ········-F·auid>=1000·-F·auid!=unset·-F·key=privileged8460 ········-F·auid>=1000·-F·auid!=unset·-F·key=privileged
8461 ······create:·true8461 ······create:·true
8462 ······mode:·o-rwx8462 ······mode:·o-rwx
8463 ······state:·present8463 ······state:·present
8464 ····when:·syscalls_found·|·length·==·08464 ····when:·syscalls_found·|·length·==·0
8465 ··when:8465 ··when:
8466 ··-·'"audit"·in·ansible_facts.packages' 
8467 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8466 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 8467 ··-·'"audit"·in·ansible_facts.packages'
8468 ··tags:8468 ··tags:
8469 ··-·DISA-STIG-RHEL-08-0305508469 ··-·DISA-STIG-RHEL-08-030550
8470 ··-·NIST-800-171-3.1.78470 ··-·NIST-800-171-3.1.7
8471 ··-·NIST-800-53-AC-6(9)8471 ··-·NIST-800-53-AC-6(9)
8472 ··-·NIST-800-53-AU-12(c)8472 ··-·NIST-800-53-AU-12(c)
8473 ··-·NIST-800-53-AU-2(d)8473 ··-·NIST-800-53-AU-2(d)
8474 ··-·NIST-800-53-CM-6(a)8474 ··-·NIST-800-53-CM-6(a)
Offset 8476, 15 lines modifiedOffset 8476, 15 lines modified
8476 ··-·low_complexity8476 ··-·low_complexity
8477 ··-·low_disruption8477 ··-·low_disruption
8478 ··-·medium_severity8478 ··-·medium_severity
8479 ··-·no_reboot_needed8479 ··-·no_reboot_needed
8480 ··-·restrict_strategy8480 ··-·restrict_strategy
8481 Remediation_Shell_script_⇲8481 Remediation_Shell_script_⇲
8482 #·Remediation·is·applicable·only·in·certain·platforms8482 #·Remediation·is·applicable·only·in·certain·platforms
8483 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then8483 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
8484 ACTION_ARCH_FILTERS="-a·always,exit"8484 ACTION_ARCH_FILTERS="-a·always,exit"
8485 OTHER_FILTERS="-F·path=/usr/bin/sudo·-F·perm=x"8485 OTHER_FILTERS="-F·path=/usr/bin/sudo·-F·perm=x"
8486 AUID_FILTERS="-F·auid>=1000·-F·auid!=unset"8486 AUID_FILTERS="-F·auid>=1000·-F·auid!=unset"
8487 SYSCALL=""8487 SYSCALL=""
8488 KEY="privileged"8488 KEY="privileged"
8489 SYSCALL_GROUPING=""8489 SYSCALL_GROUPING=""
6.98 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-anssi_bp28_intermediary.html
    
Offset 14555, 15 lines modifiedOffset 14555, 15 lines modified
00038da0:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v00038da0:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v
00038db0:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>00038db0:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>
00038dc0:·302e·312e·3635·3c2f·7374·726f·6e67·3e3c··0.1.65</strong><00038dc0:·302e·312e·3635·3c2f·7374·726f·6e67·3e3c··0.1.65</strong><
00038dd0:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro00038dd0:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro
00038de0:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong00038de0:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong
00038df0:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············00038df0:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············
00038e00:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·20200038e00:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·202
00038e10:·342d·3031·2d31·3429·0a20·2020·2020·2020··4-01-14).·······00038e10:·352d·3032·2d31·3529·0a20·2020·2020·2020··5-02-15).·······
00038e20:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></00038e20:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></
00038e30:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab00038e30:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab
00038e40:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</00038e40:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</
00038e50:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr00038e50:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr
00038e60:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s00038e60:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s
00038e70:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten00038e70:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten
00038e80:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">00038e80:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">
Offset 52529, 23 lines modifiedOffset 52529, 23 lines modified
000cd300:·793d·7072·6976·696c·6567·6564·0a20·2020··y=privileged.···000cd300:·793d·7072·6976·696c·6567·6564·0a20·2020··y=privileged.···
000cd310:·2020·2063·7265·6174·653a·2074·7275·650a·····create:·true.000cd310:·2020·2063·7265·6174·653a·2074·7275·650a·····create:·true.
000cd320:·2020·2020·2020·6d6f·6465·3a20·6f2d·7277········mode:·o-rw000cd320:·2020·2020·2020·6d6f·6465·3a20·6f2d·7277········mode:·o-rw
000cd330:·780a·2020·2020·2020·7374·6174·653a·2070··x.······state:·p000cd330:·780a·2020·2020·2020·7374·6174·653a·2070··x.······state:·p
000cd340:·7265·7365·6e74·0a20·2020·2077·6865·6e3a··resent.····when:000cd340:·7265·7365·6e74·0a20·2020·2077·6865·6e3a··resent.····when:
000cd350:·2073·7973·6361·6c6c·735f·666f·756e·6420···syscalls_found·000cd350:·2073·7973·6361·6c6c·735f·666f·756e·6420···syscalls_found·
000cd360:·7c20·6c65·6e67·7468·203d·3d20·300a·2020··|·length·==·0.··000cd360:·7c20·6c65·6e67·7468·203d·3d20·300a·2020··|·length·==·0.··
000cd370:·7768·656e·3a0a·2020·2d20·2722·6175·6469··when:.··-·'"audi000cd370:·7768·656e·3a0a·2020·2d20·616e·7369·626c··when:.··-·ansibl
000cd380:·7422·2069·6e20·616e·7369·626c·655f·6661··t"·in·ansible_fa 
000cd390:·6374·732e·7061·636b·6167·6573·270a·2020··cts.packages'.·· 
000cd3a0:·2d20·616e·7369·626c·655f·7669·7274·7561··-·ansible_virtua 
000cd3b0:·6c69·7a61·7469·6f6e·5f74·7970·6520·6e6f··lization_type·no 
000cd3c0:·7420·696e·205b·2264·6f63·6b65·7222·2c20··t·in·["docker",· 
000cd3d0:·226c·7863·222c·2022·6f70·656e·767a·222c··"lxc",·"openvz", 
000cd3e0:·2022·706f·646d·616e·222c·2022·636f·6e74···"podman",·"cont000cd380:·655f·7669·7274·7561·6c69·7a61·7469·6f6e··e_virtualization
 000cd390:·5f74·7970·6520·6e6f·7420·696e·205b·2264··_type·not·in·["d
 000cd3a0:·6f63·6b65·7222·2c20·226c·7863·222c·2022··ocker",·"lxc",·"
 000cd3b0:·6f70·656e·767a·222c·2022·706f·646d·616e··openvz",·"podman
 000cd3c0:·222c·2022·636f·6e74·6169·6e65·7222·5d0a··",·"container"].
 000cd3d0:·2020·2d20·2722·6175·6469·7422·2069·6e20····-·'"audit"·in·
 000cd3e0:·616e·7369·626c·655f·6661·6374·732e·7061··ansible_facts.pa
000cd3f0:·6169·6e65·7222·5d0a·2020·7461·6773·3a0a··ainer"].··tags:.000cd3f0:·636b·6167·6573·270a·2020·7461·6773·3a0a··ckages'.··tags:.
000cd400:·2020·2d20·4449·5341·2d53·5449·472d·5248····-·DISA-STIG-RH000cd400:·2020·2d20·4449·5341·2d53·5449·472d·5248····-·DISA-STIG-RH
000cd410:·454c·2d30·382d·3033·3035·3530·0a20·202d··EL-08-030550.··-000cd410:·454c·2d30·382d·3033·3035·3530·0a20·202d··EL-08-030550.··-
000cd420:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.000cd420:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.
000cd430:·312e·370a·2020·2d20·4e49·5354·2d38·3030··1.7.··-·NIST-800000cd430:·312e·370a·2020·2d20·4e49·5354·2d38·3030··1.7.··-·NIST-800
000cd440:·2d35·332d·4143·2d36·2839·290a·2020·2d20··-53-AC-6(9).··-·000cd440:·2d35·332d·4143·2d36·2839·290a·2020·2d20··-53-AC-6(9).··-·
000cd450:·4e49·5354·2d38·3030·2d35·332d·4155·2d31··NIST-800-53-AU-1000cd450:·4e49·5354·2d38·3030·2d35·332d·4155·2d31··NIST-800-53-AU-1
000cd460:·3228·6329·0a20·202d·204e·4953·542d·3830··2(c).··-·NIST-80000cd460:·3228·6329·0a20·202d·204e·4953·542d·3830··2(c).··-·NIST-80
Offset 52577, 20 lines modifiedOffset 52577, 20 lines modified
000cd600:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll000cd600:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
000cd610:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i000cd610:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
000cd620:·643d·2269·646d·3335·3834·3122·3e3c·7072··d="idm35841"><pr000cd620:·643d·2269·646d·3335·3834·3122·3e3c·7072··d="idm35841"><pr
000cd630:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi000cd630:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi
000cd640:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica000cd640:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica
000cd650:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert000cd650:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert
000cd660:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if000cd660:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if
000cd670:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q· 
000cd680:·6175·6469·7420·2661·6d70·3b26·616d·703b··audit·&amp;&amp; 
000cd690:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker000cd670:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker
000cd6a0:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp;000cd680:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp;
000cd6b0:·205b·2021·202d·6620·2f72·756e·2f2e·636f···[·!·-f·/run/.co000cd690:·205b·2021·202d·6620·2f72·756e·2f2e·636f···[·!·-f·/run/.co
000cd6c0:·6e74·6169·6e65·7265·6e76·205d·3b20·7468··ntainerenv·];·th000cd6a0:·6e74·6169·6e65·7265·6e76·205d·2026·616d··ntainerenv·]·&am
 000cd6b0:·703b·2661·6d70·3b20·7270·6d20·2d2d·7175··p;&amp;·rpm·--qu
 000cd6c0:·6965·7420·2d71·2061·7564·6974·3b20·7468··iet·-q·audit;·th
000cd6d0:·656e·0a0a·4143·5449·4f4e·5f41·5243·485f··en..ACTION_ARCH_000cd6d0:·656e·0a0a·4143·5449·4f4e·5f41·5243·485f··en..ACTION_ARCH_
000cd6e0:·4649·4c54·4552·533d·222d·6120·616c·7761··FILTERS="-a·alwa000cd6e0:·4649·4c54·4552·533d·222d·6120·616c·7761··FILTERS="-a·alwa
000cd6f0:·7973·2c65·7869·7422·0a4f·5448·4552·5f46··ys,exit".OTHER_F000cd6f0:·7973·2c65·7869·7422·0a4f·5448·4552·5f46··ys,exit".OTHER_F
000cd700:·494c·5445·5253·3d22·2d46·2070·6174·683d··ILTERS="-F·path=000cd700:·494c·5445·5253·3d22·2d46·2070·6174·683d··ILTERS="-F·path=
000cd710:·2f75·7372·2f62·696e·2f73·7564·6f20·2d46··/usr/bin/sudo·-F000cd710:·2f75·7372·2f62·696e·2f73·7564·6f20·2d46··/usr/bin/sudo·-F
000cd720:·2070·6572·6d3d·7822·0a41·5549·445f·4649···perm=x".AUID_FI000cd720:·2070·6572·6d3d·7822·0a41·5549·445f·4649···perm=x".AUID_FI
000cd730:·4c54·4552·533d·222d·4620·6175·6964·2667··LTERS="-F·auid&g000cd730:·4c54·4552·533d·222d·4620·6175·6964·2667··LTERS="-F·auid&g
1.76 KB
html2text {}
    
Offset 72, 15 lines modifiedOffset 72, 15 lines modified
72 ····*·cpe:/o:redhat:enterprise_linux:8.772 ····*·cpe:/o:redhat:enterprise_linux:8.7
73 ····*·cpe:/o:redhat:enterprise_linux:8.873 ····*·cpe:/o:redhat:enterprise_linux:8.8
74 ····*·cpe:/o:redhat:enterprise_linux:8.974 ····*·cpe:/o:redhat:enterprise_linux:8.9
75 ····*·cpe:/o:redhat:enterprise_linux:875 ····*·cpe:/o:redhat:enterprise_linux:8
76 ····*·cpe:/o:centos:centos:876 ····*·cpe:/o:centos:centos:8
77 *****·Revision·History·*****77 *****·Revision·History·*****
78 Current·version:·0.1.6578 Current·version:·0.1.65
79 ····*·draft·(as·of·2024-01-14)79 ····*·draft·(as·of·2025-02-15)
80 *****·Table·of·Contents·*****80 *****·Table·of·Contents·*****
81 ···1.·System_Settings81 ···1.·System_Settings
82 ·········1.·Installing_and_Maintaining_Software82 ·········1.·Installing_and_Maintaining_Software
83 ·········2.·Account_and_Access_Control83 ·········2.·Account_and_Access_Control
84 ·········3.·System_Accounting_with_auditd84 ·········3.·System_Accounting_with_auditd
85 ·········4.·Configure_Syslog85 ·········4.·Configure_Syslog
86 ·········5.·Network_Configuration_and_Firewalls86 ·········5.·Network_Configuration_and_Firewalls
Offset 7744, 16 lines modifiedOffset 7744, 16 lines modified
7744 ······line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x7744 ······line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
7745 ········-F·auid>=1000·-F·auid!=unset·-F·key=privileged7745 ········-F·auid>=1000·-F·auid!=unset·-F·key=privileged
7746 ······create:·true7746 ······create:·true
7747 ······mode:·o-rwx7747 ······mode:·o-rwx
7748 ······state:·present7748 ······state:·present
7749 ····when:·syscalls_found·|·length·==·07749 ····when:·syscalls_found·|·length·==·0
7750 ··when:7750 ··when:
7751 ··-·'"audit"·in·ansible_facts.packages' 
7752 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]7751 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 7752 ··-·'"audit"·in·ansible_facts.packages'
7753 ··tags:7753 ··tags:
7754 ··-·DISA-STIG-RHEL-08-0305507754 ··-·DISA-STIG-RHEL-08-030550
7755 ··-·NIST-800-171-3.1.77755 ··-·NIST-800-171-3.1.7
7756 ··-·NIST-800-53-AC-6(9)7756 ··-·NIST-800-53-AC-6(9)
7757 ··-·NIST-800-53-AU-12(c)7757 ··-·NIST-800-53-AU-12(c)
7758 ··-·NIST-800-53-AU-2(d)7758 ··-·NIST-800-53-AU-2(d)
7759 ··-·NIST-800-53-CM-6(a)7759 ··-·NIST-800-53-CM-6(a)
Offset 7761, 15 lines modifiedOffset 7761, 15 lines modified
7761 ··-·low_complexity7761 ··-·low_complexity
7762 ··-·low_disruption7762 ··-·low_disruption
7763 ··-·medium_severity7763 ··-·medium_severity
7764 ··-·no_reboot_needed7764 ··-·no_reboot_needed
7765 ··-·restrict_strategy7765 ··-·restrict_strategy
7766 Remediation_Shell_script_⇲7766 Remediation_Shell_script_⇲
7767 #·Remediation·is·applicable·only·in·certain·platforms7767 #·Remediation·is·applicable·only·in·certain·platforms
7768 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then7768 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
7769 ACTION_ARCH_FILTERS="-a·always,exit"7769 ACTION_ARCH_FILTERS="-a·always,exit"
7770 OTHER_FILTERS="-F·path=/usr/bin/sudo·-F·perm=x"7770 OTHER_FILTERS="-F·path=/usr/bin/sudo·-F·perm=x"
7771 AUID_FILTERS="-F·auid>=1000·-F·auid!=unset"7771 AUID_FILTERS="-F·auid>=1000·-F·auid!=unset"
7772 SYSCALL=""7772 SYSCALL=""
7773 KEY="privileged"7773 KEY="privileged"
7774 SYSCALL_GROUPING=""7774 SYSCALL_GROUPING=""
1.95 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-anssi_bp28_minimal.html
    
Offset 14553, 16 lines modifiedOffset 14553, 16 lines modified
00038d80:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>00038d80:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>
00038d90:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi00038d90:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi
00038da0:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.00038da0:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.
00038db0:·3635·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··65</strong></p><00038db0:·3635·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··65</strong></p><
00038dc0:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d00038dc0:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d
00038dd0:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··00038dd0:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··
00038de0:·2020·2020·2020·2020·2020·2020·2020·2020··················00038de0:·2020·2020·2020·2020·2020·2020·2020·2020··················
00038df0:·2020·2861·7320·6f66·2032·3032·342d·3031····(as·of·2024-0100038df0:·2020·2861·7320·6f66·2032·3032·352d·3032····(as·of·2025-02
00038e00:·2d31·3429·0a20·2020·2020·2020·2020·2020··-14).···········00038e00:·2d31·3529·0a20·2020·2020·2020·2020·2020··-15).···········
00038e10:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><00038e10:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><
00038e20:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o00038e20:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o
00038e30:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><00038e30:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><
00038e40:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="00038e40:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="
00038e50:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr00038e50:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr
00038e60:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr00038e60:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr
00038e70:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst00038e70:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst
588 B
html2text {}
    
Offset 72, 15 lines modifiedOffset 72, 15 lines modified
72 ····*·cpe:/o:redhat:enterprise_linux:8.772 ····*·cpe:/o:redhat:enterprise_linux:8.7
73 ····*·cpe:/o:redhat:enterprise_linux:8.873 ····*·cpe:/o:redhat:enterprise_linux:8.8
74 ····*·cpe:/o:redhat:enterprise_linux:8.974 ····*·cpe:/o:redhat:enterprise_linux:8.9
75 ····*·cpe:/o:redhat:enterprise_linux:875 ····*·cpe:/o:redhat:enterprise_linux:8
76 ····*·cpe:/o:centos:centos:876 ····*·cpe:/o:centos:centos:8
77 *****·Revision·History·*****77 *****·Revision·History·*****
78 Current·version:·0.1.6578 Current·version:·0.1.65
79 ····*·draft·(as·of·2024-01-14)79 ····*·draft·(as·of·2025-02-15)
80 *****·Table·of·Contents·*****80 *****·Table·of·Contents·*****
81 ···1.·System_Settings81 ···1.·System_Settings
82 ·········1.·Installing_and_Maintaining_Software82 ·········1.·Installing_and_Maintaining_Software
83 ·········2.·Account_and_Access_Control83 ·········2.·Account_and_Access_Control
84 ·········3.·Configure_Syslog84 ·········3.·Configure_Syslog
85 ·········4.·File_Permissions_and_Masks85 ·········4.·File_Permissions_and_Masks
86 ···2.·Services86 ···2.·Services
836 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-cis.html
    
Offset 14546, 16 lines modifiedOffset 14546, 16 lines modified
00038d10:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>00038d10:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>
00038d20:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi00038d20:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi
00038d30:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.00038d30:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.
00038d40:·3635·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··65</strong></p><00038d40:·3635·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··65</strong></p><
00038d50:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d00038d50:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d
00038d60:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··00038d60:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··
00038d70:·2020·2020·2020·2020·2020·2020·2020·2020··················00038d70:·2020·2020·2020·2020·2020·2020·2020·2020··················
00038d80:·2020·2861·7320·6f66·2032·3032·342d·3031····(as·of·2024-0100038d80:·2020·2861·7320·6f66·2032·3032·352d·3032····(as·of·2025-02
00038d90:·2d31·3429·0a20·2020·2020·2020·2020·2020··-14).···········00038d90:·2d31·3529·0a20·2020·2020·2020·2020·2020··-15).···········
00038da0:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><00038da0:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><
00038db0:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o00038db0:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o
00038dc0:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><00038dc0:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><
00038dd0:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="00038dd0:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="
00038de0:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr00038de0:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr
00038df0:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr00038df0:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr
00038e00:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst00038e00:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst
Offset 62460, 23 lines modifiedOffset 62460, 23 lines modified
000f3fb0:·6571·7569·7265·640a·2020·2d20·7265·7374··equired.··-·rest000f3fb0:·6571·7569·7265·640a·2020·2d20·7265·7374··equired.··-·rest
000f3fc0:·7269·6374·5f73·7472·6174·6567·790a·0a2d··rict_strategy..-000f3fc0:·7269·6374·5f73·7472·6174·6567·790a·0a2d··rict_strategy..-
000f3fd0:·206e·616d·653a·2053·6574·2061·7263·6869···name:·Set·archi000f3fd0:·206e·616d·653a·2053·6574·2061·7263·6869···name:·Set·archi
000f3fe0:·7465·6374·7572·6520·666f·7220·6175·6469··tecture·for·audi000f3fe0:·7465·6374·7572·6520·666f·7220·6175·6469··tecture·for·audi
000f3ff0:·7420·6368·6d6f·6420·7461·736b·730a·2020··t·chmod·tasks.··000f3ff0:·7420·6368·6d6f·6420·7461·736b·730a·2020··t·chmod·tasks.··
000f4000:·7365·745f·6661·6374·3a0a·2020·2020·6175··set_fact:.····au000f4000:·7365·745f·6661·6374·3a0a·2020·2020·6175··set_fact:.····au
000f4010:·6469·745f·6172·6368·3a20·6236·340a·2020··dit_arch:·b64.··000f4010:·6469·745f·6172·6368·3a20·6236·340a·2020··dit_arch:·b64.··
000f4020:·7768·656e·3a0a·2020·2d20·2722·6175·6469··when:.··-·'"audi000f4020:·7768·656e·3a0a·2020·2d20·616e·7369·626c··when:.··-·ansibl
000f4030:·7422·2069·6e20·616e·7369·626c·655f·6661··t"·in·ansible_fa 
000f4040:·6374·732e·7061·636b·6167·6573·270a·2020··cts.packages'.·· 
000f4050:·2d20·616e·7369·626c·655f·7669·7274·7561··-·ansible_virtua 
000f4060:·6c69·7a61·7469·6f6e·5f74·7970·6520·6e6f··lization_type·no 
000f4070:·7420·696e·205b·2264·6f63·6b65·7222·2c20··t·in·["docker",· 
000f4080:·226c·7863·222c·2022·6f70·656e·767a·222c··"lxc",·"openvz", 
000f4090:·2022·706f·646d·616e·222c·2022·636f·6e74···"podman",·"cont000f4030:·655f·7669·7274·7561·6c69·7a61·7469·6f6e··e_virtualization
 000f4040:·5f74·7970·6520·6e6f·7420·696e·205b·2264··_type·not·in·["d
 000f4050:·6f63·6b65·7222·2c20·226c·7863·222c·2022··ocker",·"lxc",·"
 000f4060:·6f70·656e·767a·222c·2022·706f·646d·616e··openvz",·"podman
 000f4070:·222c·2022·636f·6e74·6169·6e65·7222·5d0a··",·"container"].
 000f4080:·2020·2d20·2722·6175·6469·7422·2069·6e20····-·'"audit"·in·
 000f4090:·616e·7369·626c·655f·6661·6374·732e·7061··ansible_facts.pa
000f40a0:·6169·6e65·7222·5d0a·2020·2d20·616e·7369··ainer"].··-·ansi000f40a0:·636b·6167·6573·270a·2020·2d20·616e·7369··ckages'.··-·ansi
000f40b0:·626c·655f·6172·6368·6974·6563·7475·7265··ble_architecture000f40b0:·626c·655f·6172·6368·6974·6563·7475·7265··ble_architecture
000f40c0:·203d·3d20·2261·6172·6368·3634·2220·6f72···==·"aarch64"·or000f40c0:·203d·3d20·2261·6172·6368·3634·2220·6f72···==·"aarch64"·or
000f40d0:·2061·6e73·6962·6c65·5f61·7263·6869·7465···ansible_archite000f40d0:·2061·6e73·6962·6c65·5f61·7263·6869·7465···ansible_archite
000f40e0:·6374·7572·6520·3d3d·2022·7070·6336·3422··cture·==·"ppc64"000f40e0:·6374·7572·6520·3d3d·2022·7070·6336·3422··cture·==·"ppc64"
000f40f0:·206f·7220·616e·7369·626c·655f·6172·6368···or·ansible_arch000f40f0:·206f·7220·616e·7369·626c·655f·6172·6368···or·ansible_arch
000f4100:·6974·6563·7475·7265·0a20·2020·203d·3d20··itecture.····==·000f4100:·6974·6563·7475·7265·0a20·2020·203d·3d20··itecture.····==·
000f4110:·2270·7063·3634·6c65·2220·6f72·2061·6e73··"ppc64le"·or·ans000f4110:·2270·7063·3634·6c65·2220·6f72·2061·6e73··"ppc64le"·or·ans
Offset 62783, 23 lines modifiedOffset 62783, 23 lines modified
000f53e0:·2d46·206b·6579·3d70·6572·6d5f·6d6f·640a··-F·key=perm_mod.000f53e0:·2d46·206b·6579·3d70·6572·6d5f·6d6f·640a··-F·key=perm_mod.
000f53f0:·2020·2020·2020·6372·6561·7465·3a20·7472········create:·tr000f53f0:·2020·2020·2020·6372·6561·7465·3a20·7472········create:·tr
000f5400:·7565·0a20·2020·2020·206d·6f64·653a·206f··ue.······mode:·o000f5400:·7565·0a20·2020·2020·206d·6f64·653a·206f··ue.······mode:·o
000f5410:·2d72·7778·0a20·2020·2020·2073·7461·7465··-rwx.······state000f5410:·2d72·7778·0a20·2020·2020·2073·7461·7465··-rwx.······state
000f5420:·3a20·7072·6573·656e·740a·2020·2020·7768··:·present.····wh000f5420:·3a20·7072·6573·656e·740a·2020·2020·7768··:·present.····wh
000f5430:·656e·3a20·7379·7363·616c·6c73·5f66·6f75··en:·syscalls_fou000f5430:·656e·3a20·7379·7363·616c·6c73·5f66·6f75··en:·syscalls_fou
000f5440:·6e64·207c·206c·656e·6774·6820·3d3d·2030··nd·|·length·==·0000f5440:·6e64·207c·206c·656e·6774·6820·3d3d·2030··nd·|·length·==·0
000f5450:·0a20·2077·6865·6e3a·0a20·202d·2027·2261··.··when:.··-·'"a000f5450:·0a20·2077·6865·6e3a·0a20·202d·2061·6e73··.··when:.··-·ans
000f5460:·7564·6974·2220·696e·2061·6e73·6962·6c65··udit"·in·ansible 
000f5470:·5f66·6163·7473·2e70·6163·6b61·6765·7327··_facts.packages' 
000f5480:·0a20·202d·2061·6e73·6962·6c65·5f76·6972··.··-·ansible_vir 
000f5490:·7475·616c·697a·6174·696f·6e5f·7479·7065··tualization_type 
000f54a0:·206e·6f74·2069·6e20·5b22·646f·636b·6572···not·in·["docker 
000f54b0:·222c·2022·6c78·6322·2c20·226f·7065·6e76··",·"lxc",·"openv 
000f54c0:·7a22·2c20·2270·6f64·6d61·6e22·2c20·2263··z",·"podman",·"c 
000f54d0:·6f6e·7461·696e·6572·225d·0a20·2074·6167··ontainer"].··tag000f5460:·6962·6c65·5f76·6972·7475·616c·697a·6174··ible_virtualizat
 000f5470:·696f·6e5f·7479·7065·206e·6f74·2069·6e20··ion_type·not·in·
 000f5480:·5b22·646f·636b·6572·222c·2022·6c78·6322··["docker",·"lxc"
 000f5490:·2c20·226f·7065·6e76·7a22·2c20·2270·6f64··,·"openvz",·"pod
 000f54a0:·6d61·6e22·2c20·2263·6f6e·7461·696e·6572··man",·"container
 000f54b0:·225d·0a20·202d·2027·2261·7564·6974·2220··"].··-·'"audit"·
 000f54c0:·696e·2061·6e73·6962·6c65·5f66·6163·7473··in·ansible_facts
 000f54d0:·2e70·6163·6b61·6765·7327·0a20·2074·6167··.packages'.··tag
000f54e0:·733a·0a20·202d·2043·4a49·532d·352e·342e··s:.··-·CJIS-5.4.000f54e0:·733a·0a20·202d·2043·4a49·532d·352e·342e··s:.··-·CJIS-5.4.
000f54f0:·312e·310a·2020·2d20·4449·5341·2d53·5449··1.1.··-·DISA-STI000f54f0:·312e·310a·2020·2d20·4449·5341·2d53·5449··1.1.··-·DISA-STI
000f5500:·472d·5248·454c·2d30·382d·3033·3034·3930··G-RHEL-08-030490000f5500:·472d·5248·454c·2d30·382d·3033·3034·3930··G-RHEL-08-030490
000f5510:·0a20·202d·204e·4953·542d·3830·302d·3137··.··-·NIST-800-17000f5510:·0a20·202d·204e·4953·542d·3830·302d·3137··.··-·NIST-800-17
000f5520:·312d·332e·312e·370a·2020·2d20·4e49·5354··1-3.1.7.··-·NIST000f5520:·312d·332e·312e·370a·2020·2d20·4e49·5354··1-3.1.7.··-·NIST
000f5530:·2d38·3030·2d35·332d·4155·2d31·3228·6329··-800-53-AU-12(c)000f5530:·2d38·3030·2d35·332d·4155·2d31·3228·6329··-800-53-AU-12(c)
000f5540:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53000f5540:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
Offset 63095, 23 lines modifiedOffset 63095, 23 lines modified
000f6760:·3d70·6572·6d5f·6d6f·640a·2020·2020·2020··=perm_mod.······000f6760:·3d70·6572·6d5f·6d6f·640a·2020·2020·2020··=perm_mod.······
000f6770:·6372·6561·7465·3a20·7472·7565·0a20·2020··create:·true.···000f6770:·6372·6561·7465·3a20·7472·7565·0a20·2020··create:·true.···
000f6780:·2020·206d·6f64·653a·206f·2d72·7778·0a20·····mode:·o-rwx.·000f6780:·2020·206d·6f64·653a·206f·2d72·7778·0a20·····mode:·o-rwx.·
000f6790:·2020·2020·2073·7461·7465·3a20·7072·6573·······state:·pres000f6790:·2020·2020·2073·7461·7465·3a20·7072·6573·······state:·pres
000f67a0:·656e·740a·2020·2020·7768·656e·3a20·7379··ent.····when:·sy000f67a0:·656e·740a·2020·2020·7768·656e·3a20·7379··ent.····when:·sy
000f67b0:·7363·616c·6c73·5f66·6f75·6e64·207c·206c··scalls_found·|·l000f67b0:·7363·616c·6c73·5f66·6f75·6e64·207c·206c··scalls_found·|·l
000f67c0:·656e·6774·6820·3d3d·2030·0a20·2077·6865··ength·==·0.··whe000f67c0:·656e·6774·6820·3d3d·2030·0a20·2077·6865··ength·==·0.··whe
000f67d0:·6e3a·0a20·202d·2027·2261·7564·6974·2220··n:.··-·'"audit"· 
000f67e0:·696e·2061·6e73·6962·6c65·5f66·6163·7473··in·ansible_facts 
000f67f0:·2e70·6163·6b61·6765·7327·0a20·202d·2061··.packages'.··-·a 
000f6800:·6e73·6962·6c65·5f76·6972·7475·616c·697a··nsible_virtualiz 
000f6810:·6174·696f·6e5f·7479·7065·206e·6f74·2069··ation_type·not·i 
000f6820:·6e20·5b22·646f·636b·6572·222c·2022·6c78··n·["docker",·"lx 
000f6830:·6322·2c20·226f·7065·6e76·7a22·2c20·2270··c",·"openvz",·"p 
000f6840:·6f64·6d61·6e22·2c20·2263·6f6e·7461·696e··odman",·"contain000f67d0:·6e3a·0a20·202d·2061·6e73·6962·6c65·5f76··n:.··-·ansible_v
 000f67e0:·6972·7475·616c·697a·6174·696f·6e5f·7479··irtualization_ty
 000f67f0:·7065·206e·6f74·2069·6e20·5b22·646f·636b··pe·not·in·["dock
 000f6800:·6572·222c·2022·6c78·6322·2c20·226f·7065··er",·"lxc",·"ope
 000f6810:·6e76·7a22·2c20·2270·6f64·6d61·6e22·2c20··nvz",·"podman",·
 000f6820:·2263·6f6e·7461·696e·6572·225d·0a20·202d··"container"].··-
 000f6830:·2027·2261·7564·6974·2220·696e·2061·6e73···'"audit"·in·ans
 000f6840:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa
000f6850:·6572·225d·0a20·202d·2061·7564·6974·5f61··er"].··-·audit_a000f6850:·6765·7327·0a20·202d·2061·7564·6974·5f61··ges'.··-·audit_a
000f6860:·7263·6820·3d3d·2022·6236·3422·0a20·2074··rch·==·"b64".··t000f6860:·7263·6820·3d3d·2022·6236·3422·0a20·2074··rch·==·"b64".··t
000f6870:·6167·733a·0a20·202d·2043·4a49·532d·352e··ags:.··-·CJIS-5.000f6870:·6167·733a·0a20·202d·2043·4a49·532d·352e··ags:.··-·CJIS-5.
000f6880:·342e·312e·310a·2020·2d20·4449·5341·2d53··4.1.1.··-·DISA-S000f6880:·342e·312e·310a·2020·2d20·4449·5341·2d53··4.1.1.··-·DISA-S
000f6890:·5449·472d·5248·454c·2d30·382d·3033·3034··TIG-RHEL-08-0304000f6890:·5449·472d·5248·454c·2d30·382d·3033·3034··TIG-RHEL-08-0304
000f68a0:·3930·0a20·202d·204e·4953·542d·3830·302d··90.··-·NIST-800-000f68a0:·3930·0a20·202d·204e·4953·542d·3830·302d··90.··-·NIST-800-
000f68b0:·3137·312d·332e·312e·370a·2020·2d20·4e49··171-3.1.7.··-·NI000f68b0:·3137·312d·332e·312e·370a·2020·2d20·4e49··171-3.1.7.··-·NI
000f68c0:·5354·2d38·3030·2d35·332d·4155·2d31·3228··ST-800-53-AU-12(000f68c0:·5354·2d38·3030·2d35·332d·4155·2d31·3228··ST-800-53-AU-12(
Offset 63145, 20 lines modifiedOffset 63145, 20 lines modified
000f6a80:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co000f6a80:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
000f6a90:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"000f6a90:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
000f6aa0:·2069·643d·2269·646d·3235·3339·3022·3e3c···id="idm25390"><000f6aa0:·2069·643d·2269·646d·3235·3339·3022·3e3c···id="idm25390"><
000f6ab0:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme000f6ab0:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme
000f6ac0:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli000f6ac0:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli
000f6ad0:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce000f6ad0:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce
000f6ae0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.000f6ae0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.
000f6af0:·6966·2072·706d·202d·2d71·7569·6574·202d··if·rpm·--quiet·- 
000f6b00:·7120·6175·6469·7420·2661·6d70·3b26·616d··q·audit·&amp;&am 
000f6b10:·703b·205b·2021·202d·6620·2f2e·646f·636b··p;·[·!·-f·/.dock000f6af0:·6966·205b·2021·202d·6620·2f2e·646f·636b··if·[·!·-f·/.dock
000f6b20:·6572·656e·7620·5d20·2661·6d70·3b26·616d··erenv·]·&amp;&am000f6b00:·6572·656e·7620·5d20·2661·6d70·3b26·616d··erenv·]·&amp;&am
000f6b30:·703b·205b·2021·202d·6620·2f72·756e·2f2e··p;·[·!·-f·/run/.000f6b10:·703b·205b·2021·202d·6620·2f72·756e·2f2e··p;·[·!·-f·/run/.
000f6b40:·636f·6e74·6169·6e65·7265·6e76·205d·3b20··containerenv·];·000f6b20:·636f·6e74·6169·6e65·7265·6e76·205d·2026··containerenv·]·&
 000f6b30:·616d·703b·2661·6d70·3b20·7270·6d20·2d2d··amp;&amp;·rpm·--
 000f6b40:·7175·6965·7420·2d71·2061·7564·6974·3b20··quiet·-q·audit;·
000f6b50:·7468·656e·0a0a·2320·4669·7273·7420·7065··then..#·First·pe000f6b50:·7468·656e·0a0a·2320·4669·7273·7420·7065··then..#·First·pe
000f6b60:·7266·6f72·6d20·7468·6520·7265·6d65·6469··rform·the·remedi000f6b60:·7266·6f72·6d20·7468·6520·7265·6d65·6469··rform·the·remedi
000f6b70:·6174·696f·6e20·6f66·2074·6865·2073·7973··ation·of·the·sys000f6b70:·6174·696f·6e20·6f66·2074·6865·2073·7973··ation·of·the·sys
Max diff block lines reached; 651862/661445 bytes (98.55%) of diff not shown.
190 KB
html2text {}
    
Offset 70, 15 lines modifiedOffset 70, 15 lines modified
70 ····*·cpe:/o:redhat:enterprise_linux:8.770 ····*·cpe:/o:redhat:enterprise_linux:8.7
71 ····*·cpe:/o:redhat:enterprise_linux:8.871 ····*·cpe:/o:redhat:enterprise_linux:8.8
72 ····*·cpe:/o:redhat:enterprise_linux:8.972 ····*·cpe:/o:redhat:enterprise_linux:8.9
73 ····*·cpe:/o:redhat:enterprise_linux:873 ····*·cpe:/o:redhat:enterprise_linux:8
74 ····*·cpe:/o:centos:centos:874 ····*·cpe:/o:centos:centos:8
75 *****·Revision·History·*****75 *****·Revision·History·*****
76 Current·version:·0.1.6576 Current·version:·0.1.65
77 ····*·draft·(as·of·2024-01-14)77 ····*·draft·(as·of·2025-02-15)
78 *****·Table·of·Contents·*****78 *****·Table·of·Contents·*****
79 ···1.·System_Settings79 ···1.·System_Settings
80 ·········1.·Installing_and_Maintaining_Software80 ·········1.·Installing_and_Maintaining_Software
81 ·········2.·Account_and_Access_Control81 ·········2.·Account_and_Access_Control
82 ·········3.·System_Accounting_with_auditd82 ·········3.·System_Accounting_with_auditd
83 ·········4.·GRUB2_bootloader_configuration83 ·········4.·GRUB2_bootloader_configuration
84 ·········5.·Configure_Syslog84 ·········5.·Configure_Syslog
Offset 8266, 16 lines modifiedOffset 8266, 16 lines modified
8266 ··-·reboot_required8266 ··-·reboot_required
8267 ··-·restrict_strategy8267 ··-·restrict_strategy
  
8268 -·name:·Set·architecture·for·audit·chmod·tasks8268 -·name:·Set·architecture·for·audit·chmod·tasks
8269 ··set_fact:8269 ··set_fact:
8270 ····audit_arch:·b648270 ····audit_arch:·b64
8271 ··when:8271 ··when:
8272 ··-·'"audit"·in·ansible_facts.packages' 
8273 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8272 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 8273 ··-·'"audit"·in·ansible_facts.packages'
8274 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture8274 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
8275 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"8275 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
8276 ··tags:8276 ··tags:
8277 ··-·CJIS-5.4.1.18277 ··-·CJIS-5.4.1.1
8278 ··-·DISA-STIG-RHEL-08-0304908278 ··-·DISA-STIG-RHEL-08-030490
8279 ··-·NIST-800-171-3.1.78279 ··-·NIST-800-171-3.1.7
8280 ··-·NIST-800-53-AU-12(c)8280 ··-·NIST-800-53-AU-12(c)
Offset 8412, 16 lines modifiedOffset 8412, 16 lines modified
8412 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10008412 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
8413 ········-F·auid!=unset·-F·key=perm_mod8413 ········-F·auid!=unset·-F·key=perm_mod
8414 ······create:·true8414 ······create:·true
8415 ······mode:·o-rwx8415 ······mode:·o-rwx
8416 ······state:·present8416 ······state:·present
8417 ····when:·syscalls_found·|·length·==·08417 ····when:·syscalls_found·|·length·==·0
8418 ··when:8418 ··when:
8419 ··-·'"audit"·in·ansible_facts.packages' 
8420 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8419 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 8420 ··-·'"audit"·in·ansible_facts.packages'
8421 ··tags:8421 ··tags:
8422 ··-·CJIS-5.4.1.18422 ··-·CJIS-5.4.1.1
8423 ··-·DISA-STIG-RHEL-08-0304908423 ··-·DISA-STIG-RHEL-08-030490
8424 ··-·NIST-800-171-3.1.78424 ··-·NIST-800-171-3.1.7
8425 ··-·NIST-800-53-AU-12(c)8425 ··-·NIST-800-53-AU-12(c)
8426 ··-·NIST-800-53-AU-2(d)8426 ··-·NIST-800-53-AU-2(d)
8427 ··-·NIST-800-53-CM-6(a)8427 ··-·NIST-800-53-CM-6(a)
Offset 8556, 16 lines modifiedOffset 8556, 16 lines modified
8556 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10008556 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
8557 ········-F·auid!=unset·-F·key=perm_mod8557 ········-F·auid!=unset·-F·key=perm_mod
8558 ······create:·true8558 ······create:·true
8559 ······mode:·o-rwx8559 ······mode:·o-rwx
8560 ······state:·present8560 ······state:·present
8561 ····when:·syscalls_found·|·length·==·08561 ····when:·syscalls_found·|·length·==·0
8562 ··when:8562 ··when:
8563 ··-·'"audit"·in·ansible_facts.packages' 
8564 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8563 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 8564 ··-·'"audit"·in·ansible_facts.packages'
8565 ··-·audit_arch·==·"b64"8565 ··-·audit_arch·==·"b64"
8566 ··tags:8566 ··tags:
8567 ··-·CJIS-5.4.1.18567 ··-·CJIS-5.4.1.1
8568 ··-·DISA-STIG-RHEL-08-0304908568 ··-·DISA-STIG-RHEL-08-030490
8569 ··-·NIST-800-171-3.1.78569 ··-·NIST-800-171-3.1.7
8570 ··-·NIST-800-53-AU-12(c)8570 ··-·NIST-800-53-AU-12(c)
8571 ··-·NIST-800-53-AU-2(d)8571 ··-·NIST-800-53-AU-2(d)
Offset 8575, 15 lines modifiedOffset 8575, 15 lines modified
8575 ··-·low_complexity8575 ··-·low_complexity
8576 ··-·low_disruption8576 ··-·low_disruption
8577 ··-·medium_severity8577 ··-·medium_severity
8578 ··-·reboot_required8578 ··-·reboot_required
8579 ··-·restrict_strategy8579 ··-·restrict_strategy
8580 Remediation_Shell_script_⇲8580 Remediation_Shell_script_⇲
8581 #·Remediation·is·applicable·only·in·certain·platforms8581 #·Remediation·is·applicable·only·in·certain·platforms
8582 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then8582 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
8583 #·First·perform·the·remediation·of·the·syscall·rule8583 #·First·perform·the·remediation·of·the·syscall·rule
8584 #·Retrieve·hardware·architecture·of·the·underlying·system8584 #·Retrieve·hardware·architecture·of·the·underlying·system
8585 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")8585 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
8586 for·ARCH·in·"${RULE_ARCHS[@]}"8586 for·ARCH·in·"${RULE_ARCHS[@]}"
8587 do8587 do
Offset 8944, 16 lines modifiedOffset 8944, 16 lines modified
8944 ··-·reboot_required8944 ··-·reboot_required
8945 ··-·restrict_strategy8945 ··-·restrict_strategy
  
8946 -·name:·Set·architecture·for·audit·chown·tasks8946 -·name:·Set·architecture·for·audit·chown·tasks
8947 ··set_fact:8947 ··set_fact:
8948 ····audit_arch:·b648948 ····audit_arch:·b64
8949 ··when:8949 ··when:
8950 ··-·'"audit"·in·ansible_facts.packages' 
8951 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8950 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 8951 ··-·'"audit"·in·ansible_facts.packages'
8952 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture8952 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
8953 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"8953 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
8954 ··tags:8954 ··tags:
8955 ··-·CJIS-5.4.1.18955 ··-·CJIS-5.4.1.1
8956 ··-·DISA-STIG-RHEL-08-0304808956 ··-·DISA-STIG-RHEL-08-030480
8957 ··-·NIST-800-171-3.1.78957 ··-·NIST-800-171-3.1.7
8958 ··-·NIST-800-53-AU-12(c)8958 ··-·NIST-800-53-AU-12(c)
Offset 9092, 16 lines modifiedOffset 9092, 16 lines modified
9092 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10009092 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
9093 ········-F·auid!=unset·-F·key=perm_mod9093 ········-F·auid!=unset·-F·key=perm_mod
9094 ······create:·true9094 ······create:·true
9095 ······mode:·o-rwx9095 ······mode:·o-rwx
9096 ······state:·present9096 ······state:·present
9097 ····when:·syscalls_found·|·length·==·09097 ····when:·syscalls_found·|·length·==·0
9098 ··when:9098 ··when:
9099 ··-·'"audit"·in·ansible_facts.packages' 
9100 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]9099 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 9100 ··-·'"audit"·in·ansible_facts.packages'
9101 ··tags:9101 ··tags:
9102 ··-·CJIS-5.4.1.19102 ··-·CJIS-5.4.1.1
9103 ··-·DISA-STIG-RHEL-08-0304809103 ··-·DISA-STIG-RHEL-08-030480
9104 ··-·NIST-800-171-3.1.79104 ··-·NIST-800-171-3.1.7
9105 ··-·NIST-800-53-AU-12(c)9105 ··-·NIST-800-53-AU-12(c)
9106 ··-·NIST-800-53-AU-2(d)9106 ··-·NIST-800-53-AU-2(d)
9107 ··-·NIST-800-53-CM-6(a)9107 ··-·NIST-800-53-CM-6(a)
Offset 9238, 16 lines modifiedOffset 9238, 16 lines modified
9238 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10009238 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
9239 ········-F·auid!=unset·-F·key=perm_mod9239 ········-F·auid!=unset·-F·key=perm_mod
9240 ······create:·true9240 ······create:·true
9241 ······mode:·o-rwx9241 ······mode:·o-rwx
9242 ······state:·present9242 ······state:·present
Max diff block lines reached; 189972/194456 bytes (97.69%) of diff not shown.
91.1 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-cis_server_l1.html
    
Offset 14547, 15 lines modifiedOffset 14547, 15 lines modified
00038d20:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur00038d20:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur
00038d30:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s00038d30:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s
00038d40:·7472·6f6e·673e·302e·312e·3635·3c2f·7374··trong>0.1.65</st00038d40:·7472·6f6e·673e·302e·312e·3635·3c2f·7374··trong>0.1.65</st
00038d50:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li00038d50:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li
00038d60:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</00038d60:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</
00038d70:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········00038d70:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········
00038d80:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·00038d80:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·
00038d90:·6f66·2032·3032·342d·3031·2d31·3429·0a20··of·2024-01-14).·00038d90:·6f66·2032·3032·352d·3032·2d31·3529·0a20··of·2025-02-15).·
00038da0:·2020·2020·2020·2020·2020·2020·2020·203c·················<00038da0:·2020·2020·2020·2020·2020·2020·2020·203c·················<
00038db0:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><00038db0:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><
00038dc0:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont00038dc0:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont
00038dd0:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li00038dd0:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li
00038de0:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf00038de0:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf
00038df0:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.00038df0:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.
00038e00:·636f·6e74·656e·745f·6772·6f75·705f·7379··content_group_sy00038e00:·636f·6e74·656e·745f·6772·6f75·705f·7379··content_group_sy
Offset 59536, 22 lines modifiedOffset 59536, 22 lines modified
000e88f0:·6e61·6d65·3a20·5465·7374·2066·6f72·2065··name:·Test·for·e000e88f0:·6e61·6d65·3a20·5465·7374·2066·6f72·2065··name:·Test·for·e
000e8900:·7869·7374·656e·6365·202f·626f·6f74·2f67··xistence·/boot/g000e8900:·7869·7374·656e·6365·202f·626f·6f74·2f67··xistence·/boot/g
000e8910:·7275·6232·2f67·7275·622e·6366·670a·2020··rub2/grub.cfg.··000e8910:·7275·6232·2f67·7275·622e·6366·670a·2020··rub2/grub.cfg.··
000e8920:·7374·6174·3a0a·2020·2020·7061·7468·3a20··stat:.····path:·000e8920:·7374·6174·3a0a·2020·2020·7061·7468·3a20··stat:.····path:·
000e8930:·2f62·6f6f·742f·6772·7562·322f·6772·7562··/boot/grub2/grub000e8930:·2f62·6f6f·742f·6772·7562·322f·6772·7562··/boot/grub2/grub
000e8940:·2e63·6667·0a20·2072·6567·6973·7465·723a··.cfg.··register:000e8940:·2e63·6667·0a20·2072·6567·6973·7465·723a··.cfg.··register:
000e8950:·2066·696c·655f·6578·6973·7473·0a20·2077···file_exists.··w000e8950:·2066·696c·655f·6578·6973·7473·0a20·2077···file_exists.··w
000e8960:·6865·6e3a·0a20·202d·2027·2267·7275·6232··hen:.··-·'"grub2000e8960:·6865·6e3a·0a20·202d·2027·222f·626f·6f74··hen:.··-·'"/boot
000e8970:·2d63·6f6d·6d6f·6e22·2069·6e20·616e·7369··-common"·in·ansi 
000e8980:·626c·655f·6661·6374·732e·7061·636b·6167··ble_facts.packag 
000e8990:·6573·270a·2020·2d20·2722·2f62·6f6f·742f··es'.··-·'"/boot/ 
000e89a0:·6566·6922·206e·6f74·2069·6e20·616e·7369··efi"·not·in·ansi 
000e89b0:·626c·655f·6d6f·756e·7473·207c·206d·6170··ble_mounts·|·map 
000e89c0:·2861·7474·7269·6275·7465·3d22·6d6f·756e··(attribute="moun 
000e89d0:·7422·2920·7c20·6c69·7374·270a·2020·2d20··t")·|·list'.··-·000e8970:·2f65·6669·2220·6e6f·7420·696e·2061·6e73··/efi"·not·in·ans
 000e8980:·6962·6c65·5f6d·6f75·6e74·7320·7c20·6d61··ible_mounts·|·ma
 000e8990:·7028·6174·7472·6962·7574·653d·226d·6f75··p(attribute="mou
 000e89a0:·6e74·2229·207c·206c·6973·7427·0a20·202d··nt")·|·list'.··-
 000e89b0:·2027·2267·7275·6232·2d63·6f6d·6d6f·6e22···'"grub2-common"
 000e89c0:·2069·6e20·616e·7369·626c·655f·6661·6374···in·ansible_fact
 000e89d0:·732e·7061·636b·6167·6573·270a·2020·2d20··s.packages'.··-·
000e89e0:·616e·7369·626c·655f·7669·7274·7561·6c69··ansible_virtuali000e89e0:·616e·7369·626c·655f·7669·7274·7561·6c69··ansible_virtuali
000e89f0:·7a61·7469·6f6e·5f74·7970·6520·6e6f·7420··zation_type·not·000e89f0:·7a61·7469·6f6e·5f74·7970·6520·6e6f·7420··zation_type·not·
000e8a00:·696e·205b·2264·6f63·6b65·7222·2c20·226c··in·["docker",·"l000e8a00:·696e·205b·2264·6f63·6b65·7222·2c20·226c··in·["docker",·"l
000e8a10:·7863·222c·2022·6f70·656e·767a·222c·2022··xc",·"openvz",·"000e8a10:·7863·222c·2022·6f70·656e·767a·222c·2022··xc",·"openvz",·"
000e8a20:·706f·646d·616e·222c·2022·636f·6e74·6169··podman",·"contai000e8a20:·706f·646d·616e·222c·2022·636f·6e74·6169··podman",·"contai
000e8a30:·6e65·7222·5d0a·2020·7461·6773·3a0a·2020··ner"].··tags:.··000e8a30:·6e65·7222·5d0a·2020·7461·6773·3a0a·2020··ner"].··tags:.··
000e8a40:·2d20·434a·4953·2d35·2e35·2e32·2e32·0a20··-·CJIS-5.5.2.2.·000e8a40:·2d20·434a·4953·2d35·2e35·2e32·2e32·0a20··-·CJIS-5.5.2.2.·
Offset 59572, 22 lines modifiedOffset 59572, 22 lines modified
000e8b30:·206e·616d·653a·2045·6e73·7572·6520·6772···name:·Ensure·gr000e8b30:·206e·616d·653a·2045·6e73·7572·6520·6772···name:·Ensure·gr
000e8b40:·6f75·7020·6f77·6e65·7220·3020·6f6e·202f··oup·owner·0·on·/000e8b40:·6f75·7020·6f77·6e65·7220·3020·6f6e·202f··oup·owner·0·on·/
000e8b50:·626f·6f74·2f67·7275·6232·2f67·7275·622e··boot/grub2/grub.000e8b50:·626f·6f74·2f67·7275·6232·2f67·7275·622e··boot/grub2/grub.
000e8b60:·6366·670a·2020·6669·6c65·3a0a·2020·2020··cfg.··file:.····000e8b60:·6366·670a·2020·6669·6c65·3a0a·2020·2020··cfg.··file:.····
000e8b70:·7061·7468·3a20·2f62·6f6f·742f·6772·7562··path:·/boot/grub000e8b70:·7061·7468·3a20·2f62·6f6f·742f·6772·7562··path:·/boot/grub
000e8b80:·322f·6772·7562·2e63·6667·0a20·2020·2067··2/grub.cfg.····g000e8b80:·322f·6772·7562·2e63·6667·0a20·2020·2067··2/grub.cfg.····g
000e8b90:·726f·7570·3a20·2730·270a·2020·7768·656e··roup:·'0'.··when000e8b90:·726f·7570·3a20·2730·270a·2020·7768·656e··roup:·'0'.··when
000e8ba0:·3a0a·2020·2d20·2722·6772·7562·322d·636f··:.··-·'"grub2-co 
000e8bb0:·6d6d·6f6e·2220·696e·2061·6e73·6962·6c65··mmon"·in·ansible 
000e8bc0:·5f66·6163·7473·2e70·6163·6b61·6765·7327··_facts.packages' 
000e8bd0:·0a20·202d·2027·222f·626f·6f74·2f65·6669··.··-·'"/boot/efi 
000e8be0:·2220·6e6f·7420·696e·2061·6e73·6962·6c65··"·not·in·ansible 
000e8bf0:·5f6d·6f75·6e74·7320·7c20·6d61·7028·6174··_mounts·|·map(at 
000e8c00:·7472·6962·7574·653d·226d·6f75·6e74·2229··tribute="mount") 
000e8c10:·207c·206c·6973·7427·0a20·202d·2061·6e73···|·list'.··-·ans000e8ba0:·3a0a·2020·2d20·2722·2f62·6f6f·742f·6566··:.··-·'"/boot/ef
 000e8bb0:·6922·206e·6f74·2069·6e20·616e·7369·626c··i"·not·in·ansibl
 000e8bc0:·655f·6d6f·756e·7473·207c·206d·6170·2861··e_mounts·|·map(a
 000e8bd0:·7474·7269·6275·7465·3d22·6d6f·756e·7422··ttribute="mount"
 000e8be0:·2920·7c20·6c69·7374·270a·2020·2d20·2722··)·|·list'.··-·'"
 000e8bf0:·6772·7562·322d·636f·6d6d·6f6e·2220·696e··grub2-common"·in
 000e8c00:·2061·6e73·6962·6c65·5f66·6163·7473·2e70···ansible_facts.p
 000e8c10:·6163·6b61·6765·7327·0a20·202d·2061·6e73··ackages'.··-·ans
000e8c20:·6962·6c65·5f76·6972·7475·616c·697a·6174··ible_virtualizat000e8c20:·6962·6c65·5f76·6972·7475·616c·697a·6174··ible_virtualizat
000e8c30:·696f·6e5f·7479·7065·206e·6f74·2069·6e20··ion_type·not·in·000e8c30:·696f·6e5f·7479·7065·206e·6f74·2069·6e20··ion_type·not·in·
000e8c40:·5b22·646f·636b·6572·222c·2022·6c78·6322··["docker",·"lxc"000e8c40:·5b22·646f·636b·6572·222c·2022·6c78·6322··["docker",·"lxc"
000e8c50:·2c20·226f·7065·6e76·7a22·2c20·2270·6f64··,·"openvz",·"pod000e8c50:·2c20·226f·7065·6e76·7a22·2c20·2270·6f64··,·"openvz",·"pod
000e8c60:·6d61·6e22·2c20·2263·6f6e·7461·696e·6572··man",·"container000e8c60:·6d61·6e22·2c20·2263·6f6e·7461·696e·6572··man",·"container
000e8c70:·225d·0a20·202d·2066·696c·655f·6578·6973··"].··-·file_exis000e8c70:·225d·0a20·202d·2066·696c·655f·6578·6973··"].··-·file_exis
000e8c80:·7473·2e73·7461·7420·6973·2064·6566·696e··ts.stat·is·defin000e8c80:·7473·2e73·7461·7420·6973·2064·6566·696e··ts.stat·is·defin
Offset 59637, 19 lines modifiedOffset 59637, 19 lines modified
000e8f40:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str000e8f40:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
000e8f50:·6174·6567·793a·3c2f·7468·3e3c·7464·3e63··ategy:</th><td>c000e8f50:·6174·6567·793a·3c2f·7468·3e3c·7464·3e63··ategy:</th><td>c
000e8f60:·6f6e·6669·6775·7265·3c2f·7464·3e3c·2f74··onfigure</td></t000e8f60:·6f6e·6669·6775·7265·3c2f·7464·3e3c·2f74··onfigure</td></t
000e8f70:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><000e8f70:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
000e8f80:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati000e8f80:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati
000e8f90:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable000e8f90:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable
000e8fa0:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain000e8fa0:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain
000e8fb0:·2070·6c61·7466·6f72·6d73·0a69·6620·7270···platforms.if·rp000e8fb0:·2070·6c61·7466·6f72·6d73·0a69·6620·5b20···platforms.if·[·
000e8fc0:·6d20·2d2d·7175·6965·7420·2d71·2067·7275··m·--quiet·-q·gru 
000e8fd0:·6232·2d63·6f6d·6d6f·6e20·2661·6d70·3b26··b2-common·&amp;& 
000e8fe0:·616d·703b·205b·2021·202d·6620·2f73·7973··amp;·[·!·-f·/sys 
000e8ff0:·2f66·6972·6d77·6172·652f·6566·6920·5d20··/firmware/efi·]·000e8fc0:·2120·2d66·202f·7379·732f·6669·726d·7761··!·-f·/sys/firmwa
 000e8fd0:·7265·2f65·6669·205d·2026·616d·703b·2661··re/efi·]·&amp;&a
 000e8fe0:·6d70·3b20·7270·6d20·2d2d·7175·6965·7420··mp;·rpm·--quiet·
 000e8ff0:·2d71·2067·7275·6232·2d63·6f6d·6d6f·6e20··-q·grub2-common·
000e9000:·2661·6d70·3b26·616d·703b·207b·205b·2021··&amp;&amp;·{·[·!000e9000:·2661·6d70·3b26·616d·703b·207b·205b·2021··&amp;&amp;·{·[·!
000e9010:·202d·6620·2f2e·646f·636b·6572·656e·7620···-f·/.dockerenv·000e9010:·202d·6620·2f2e·646f·636b·6572·656e·7620···-f·/.dockerenv·
000e9020:·5d20·2661·6d70·3b26·616d·703b·205b·2021··]·&amp;&amp;·[·!000e9020:·5d20·2661·6d70·3b26·616d·703b·205b·2021··]·&amp;&amp;·[·!
000e9030:·202d·6620·2f72·756e·2f2e·636f·6e74·6169···-f·/run/.contai000e9030:·202d·6620·2f72·756e·2f2e·636f·6e74·6169···-f·/run/.contai
000e9040:·6e65·7265·6e76·205d·3b20·7d3b·2074·6865··nerenv·];·};·the000e9040:·6e65·7265·6e76·205d·3b20·7d3b·2074·6865··nerenv·];·};·the
000e9050:·6e0a·0a63·6867·7270·2030·202f·626f·6f74··n..chgrp·0·/boot000e9050:·6e0a·0a63·6867·7270·2030·202f·626f·6f74··n..chgrp·0·/boot
000e9060:·2f67·7275·6232·2f67·7275·622e·6366·670a··/grub2/grub.cfg.000e9060:·2f67·7275·6232·2f67·7275·622e·6366·670a··/grub2/grub.cfg.
Offset 60140, 21 lines modifiedOffset 60140, 21 lines modified
000eaeb0:·2066·6f72·2065·7869·7374·656e·6365·202f···for·existence·/000eaeb0:·2066·6f72·2065·7869·7374·656e·6365·202f···for·existence·/
000eaec0:·626f·6f74·2f67·7275·6232·2f75·7365·722e··boot/grub2/user.000eaec0:·626f·6f74·2f67·7275·6232·2f75·7365·722e··boot/grub2/user.
000eaed0:·6366·670a·2020·7374·6174·3a0a·2020·2020··cfg.··stat:.····000eaed0:·6366·670a·2020·7374·6174·3a0a·2020·2020··cfg.··stat:.····
000eaee0:·7061·7468·3a20·2f62·6f6f·742f·6772·7562··path:·/boot/grub000eaee0:·7061·7468·3a20·2f62·6f6f·742f·6772·7562··path:·/boot/grub
000eaef0:·322f·7573·6572·2e63·6667·0a20·2072·6567··2/user.cfg.··reg000eaef0:·322f·7573·6572·2e63·6667·0a20·2072·6567··2/user.cfg.··reg
000eaf00:·6973·7465·723a·2066·696c·655f·6578·6973··ister:·file_exis000eaf00:·6973·7465·723a·2066·696c·655f·6578·6973··ister:·file_exis
000eaf10:·7473·0a20·2077·6865·6e3a·0a20·202d·2027··ts.··when:.··-·'000eaf10:·7473·0a20·2077·6865·6e3a·0a20·202d·2027··ts.··when:.··-·'
000eaf20:·2267·7275·6232·2d63·6f6d·6d6f·6e22·2069··"grub2-common"·i 
000eaf30:·6e20·616e·7369·626c·655f·6661·6374·732e··n·ansible_facts. 
000eaf40:·7061·636b·6167·6573·270a·2020·2d20·2722··packages'.··-·'" 
000eaf50:·2f62·6f6f·742f·6566·6922·206e·6f74·2069··/boot/efi"·not·i 
000eaf60:·6e20·616e·7369·626c·655f·6d6f·756e·7473··n·ansible_mounts 
000eaf70:·207c·206d·6170·2861·7474·7269·6275·7465···|·map(attribute 
000eaf80:·3d22·6d6f·756e·7422·2920·7c20·6c69·7374··="mount")·|·list000eaf20:·222f·626f·6f74·2f65·6669·2220·6e6f·7420··"/boot/efi"·not·
 000eaf30:·696e·2061·6e73·6962·6c65·5f6d·6f75·6e74··in·ansible_mount
 000eaf40:·7320·7c20·6d61·7028·6174·7472·6962·7574··s·|·map(attribut
 000eaf50:·653d·226d·6f75·6e74·2229·207c·206c·6973··e="mount")·|·lis
 000eaf60:·7427·0a20·202d·2027·2267·7275·6232·2d63··t'.··-·'"grub2-c
 000eaf70:·6f6d·6d6f·6e22·2069·6e20·616e·7369·626c··ommon"·in·ansibl
 000eaf80:·655f·6661·6374·732e·7061·636b·6167·6573··e_facts.packages
000eaf90:·270a·2020·2d20·616e·7369·626c·655f·7669··'.··-·ansible_vi000eaf90:·270a·2020·2d20·616e·7369·626c·655f·7669··'.··-·ansible_vi
000eafa0:·7274·7561·6c69·7a61·7469·6f6e·5f74·7970··rtualization_typ000eafa0:·7274·7561·6c69·7a61·7469·6f6e·5f74·7970··rtualization_typ
000eafb0:·6520·6e6f·7420·696e·205b·2264·6f63·6b65··e·not·in·["docke000eafb0:·6520·6e6f·7420·696e·205b·2264·6f63·6b65··e·not·in·["docke
000eafc0:·7222·2c20·226c·7863·222c·2022·6f70·656e··r",·"lxc",·"open000eafc0:·7222·2c20·226c·7863·222c·2022·6f70·656e··r",·"lxc",·"open
000eafd0:·767a·222c·2022·706f·646d·616e·222c·2022··vz",·"podman",·"000eafd0:·767a·222c·2022·706f·646d·616e·222c·2022··vz",·"podman",·"
000eafe0:·636f·6e74·6169·6e65·7222·5d0a·2020·7461··container"].··ta000eafe0:·636f·6e74·6169·6e65·7222·5d0a·2020·7461··container"].··ta
000eaff0:·6773·3a0a·2020·2d20·434a·4953·2d35·2e35··gs:.··-·CJIS-5.5000eaff0:·6773·3a0a·2020·2d20·434a·4953·2d35·2e35··gs:.··-·CJIS-5.5
Offset 60175, 22 lines modifiedOffset 60175, 22 lines modified
000eb0e0:·6564·0a0a·2d20·6e61·6d65·3a20·456e·7375··ed..-·name:·Ensu000eb0e0:·6564·0a0a·2d20·6e61·6d65·3a20·456e·7375··ed..-·name:·Ensu
Max diff block lines reached; 61526/70652 bytes (87.08%) of diff not shown.
22.0 KB
html2text {}
    
Offset 70, 15 lines modifiedOffset 70, 15 lines modified
70 ····*·cpe:/o:redhat:enterprise_linux:8.770 ····*·cpe:/o:redhat:enterprise_linux:8.7
71 ····*·cpe:/o:redhat:enterprise_linux:8.871 ····*·cpe:/o:redhat:enterprise_linux:8.8
72 ····*·cpe:/o:redhat:enterprise_linux:8.972 ····*·cpe:/o:redhat:enterprise_linux:8.9
73 ····*·cpe:/o:redhat:enterprise_linux:873 ····*·cpe:/o:redhat:enterprise_linux:8
74 ····*·cpe:/o:centos:centos:874 ····*·cpe:/o:centos:centos:8
75 *****·Revision·History·*****75 *****·Revision·History·*****
76 Current·version:·0.1.6576 Current·version:·0.1.65
77 ····*·draft·(as·of·2024-01-14)77 ····*·draft·(as·of·2025-02-15)
78 *****·Table·of·Contents·*****78 *****·Table·of·Contents·*****
79 ···1.·System_Settings79 ···1.·System_Settings
80 ·········1.·Installing_and_Maintaining_Software80 ·········1.·Installing_and_Maintaining_Software
81 ·········2.·Account_and_Access_Control81 ·········2.·Account_and_Access_Control
82 ·········3.·GRUB2_bootloader_configuration82 ·········3.·GRUB2_bootloader_configuration
83 ·········4.·Configure_Syslog83 ·········4.·Configure_Syslog
84 ·········5.·Network_Configuration_and_Firewalls84 ·········5.·Network_Configuration_and_Firewalls
Offset 8118, 16 lines modifiedOffset 8118, 16 lines modified
8118 ··-·no_reboot_needed8118 ··-·no_reboot_needed
  
8119 -·name:·Test·for·existence·/boot/grub2/grub.cfg8119 -·name:·Test·for·existence·/boot/grub2/grub.cfg
8120 ··stat:8120 ··stat:
8121 ····path:·/boot/grub2/grub.cfg8121 ····path:·/boot/grub2/grub.cfg
8122 ··register:·file_exists8122 ··register:·file_exists
8123 ··when:8123 ··when:
8124 ··-·'"grub2-common"·in·ansible_facts.packages' 
8125 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'8124 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 8125 ··-·'"grub2-common"·in·ansible_facts.packages'
8126 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8126 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
8127 ··tags:8127 ··tags:
8128 ··-·CJIS-5.5.2.28128 ··-·CJIS-5.5.2.2
8129 ··-·NIST-800-171-3.4.58129 ··-·NIST-800-171-3.4.5
8130 ··-·NIST-800-53-AC-6(1)8130 ··-·NIST-800-53-AC-6(1)
8131 ··-·NIST-800-53-CM-6(a)8131 ··-·NIST-800-53-CM-6(a)
8132 ··-·PCI-DSS-Req-7.18132 ··-·PCI-DSS-Req-7.1
Offset 8139, 16 lines modifiedOffset 8139, 16 lines modified
8139 ··-·no_reboot_needed8139 ··-·no_reboot_needed
  
8140 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg8140 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
8141 ··file:8141 ··file:
8142 ····path:·/boot/grub2/grub.cfg8142 ····path:·/boot/grub2/grub.cfg
8143 ····group:·'0'8143 ····group:·'0'
8144 ··when:8144 ··when:
8145 ··-·'"grub2-common"·in·ansible_facts.packages' 
8146 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'8145 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 8146 ··-·'"grub2-common"·in·ansible_facts.packages'
8147 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8147 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
8148 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists8148 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists
8149 ··tags:8149 ··tags:
8150 ··-·CJIS-5.5.2.28150 ··-·CJIS-5.5.2.2
8151 ··-·NIST-800-171-3.4.58151 ··-·NIST-800-171-3.4.5
8152 ··-·NIST-800-53-AC-6(1)8152 ··-·NIST-800-53-AC-6(1)
8153 ··-·NIST-800-53-CM-6(a)8153 ··-·NIST-800-53-CM-6(a)
Offset 8160, 15 lines modifiedOffset 8160, 15 lines modified
8160 ··-·medium_severity8160 ··-·medium_severity
8161 ··-·no_reboot_needed8161 ··-·no_reboot_needed
8162 Remediation_Shell_script_⇲8162 Remediation_Shell_script_⇲
8163 Complexity:·low8163 Complexity:·low
8164 Disruption:·low8164 Disruption:·low
8165 Strategy:···configure8165 Strategy:···configure
8166 #·Remediation·is·applicable·only·in·certain·platforms8166 #·Remediation·is·applicable·only·in·certain·platforms
8167 if·rpm·--quiet·-q·grub2-common·&&·[·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then8167 if·[·!·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
8168 chgrp·0·/boot/grub2/grub.cfg8168 chgrp·0·/boot/grub2/grub.cfg
  
8169 else8169 else
8170 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'8170 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
8171 fi8171 fi
8172 ***·Rule  ·Verify·/boot/grub2/user.cfg·Group·Ownership·  [ref]·***8172 ***·Rule  ·Verify·/boot/grub2/user.cfg·Group·Ownership·  [ref]·***
Offset 8199, 16 lines modifiedOffset 8199, 16 lines modified
8199 ··-·no_reboot_needed8199 ··-·no_reboot_needed
  
8200 -·name:·Test·for·existence·/boot/grub2/user.cfg8200 -·name:·Test·for·existence·/boot/grub2/user.cfg
8201 ··stat:8201 ··stat:
8202 ····path:·/boot/grub2/user.cfg8202 ····path:·/boot/grub2/user.cfg
8203 ··register:·file_exists8203 ··register:·file_exists
8204 ··when:8204 ··when:
8205 ··-·'"grub2-common"·in·ansible_facts.packages' 
8206 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'8205 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 8206 ··-·'"grub2-common"·in·ansible_facts.packages'
8207 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8207 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
8208 ··tags:8208 ··tags:
8209 ··-·CJIS-5.5.2.28209 ··-·CJIS-5.5.2.2
8210 ··-·NIST-800-171-3.4.58210 ··-·NIST-800-171-3.4.5
8211 ··-·NIST-800-53-AC-6(1)8211 ··-·NIST-800-53-AC-6(1)
8212 ··-·NIST-800-53-CM-6(a)8212 ··-·NIST-800-53-CM-6(a)
8213 ··-·PCI-DSS-Req-7.18213 ··-·PCI-DSS-Req-7.1
Offset 8220, 16 lines modifiedOffset 8220, 16 lines modified
8220 ··-·no_reboot_needed8220 ··-·no_reboot_needed
  
8221 -·name:·Ensure·group·owner·0·on·/boot/grub2/user.cfg8221 -·name:·Ensure·group·owner·0·on·/boot/grub2/user.cfg
8222 ··file:8222 ··file:
8223 ····path:·/boot/grub2/user.cfg8223 ····path:·/boot/grub2/user.cfg
8224 ····group:·'0'8224 ····group:·'0'
8225 ··when:8225 ··when:
8226 ··-·'"grub2-common"·in·ansible_facts.packages' 
8227 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'8226 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 8227 ··-·'"grub2-common"·in·ansible_facts.packages'
8228 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8228 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
8229 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists8229 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists
8230 ··tags:8230 ··tags:
8231 ··-·CJIS-5.5.2.28231 ··-·CJIS-5.5.2.2
8232 ··-·NIST-800-171-3.4.58232 ··-·NIST-800-171-3.4.5
8233 ··-·NIST-800-53-AC-6(1)8233 ··-·NIST-800-53-AC-6(1)
8234 ··-·NIST-800-53-CM-6(a)8234 ··-·NIST-800-53-CM-6(a)
Offset 8241, 15 lines modifiedOffset 8241, 15 lines modified
8241 ··-·medium_severity8241 ··-·medium_severity
8242 ··-·no_reboot_needed8242 ··-·no_reboot_needed
8243 Remediation_Shell_script_⇲8243 Remediation_Shell_script_⇲
8244 Complexity:·low8244 Complexity:·low
8245 Disruption:·low8245 Disruption:·low
8246 Strategy:···configure8246 Strategy:···configure
8247 #·Remediation·is·applicable·only·in·certain·platforms8247 #·Remediation·is·applicable·only·in·certain·platforms
8248 if·rpm·--quiet·-q·grub2-common·&&·[·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then8248 if·[·!·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
8249 chgrp·0·/boot/grub2/user.cfg8249 chgrp·0·/boot/grub2/user.cfg
  
8250 else8250 else
8251 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'8251 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
8252 fi8252 fi
8253 ***·Rule  ·Verify·/boot/grub2/grub.cfg·User·Ownership·  [ref]·***8253 ***·Rule  ·Verify·/boot/grub2/grub.cfg·User·Ownership·  [ref]·***
Offset 8280, 16 lines modifiedOffset 8280, 16 lines modified
8280 ··-·no_reboot_needed8280 ··-·no_reboot_needed
  
8281 -·name:·Test·for·existence·/boot/grub2/grub.cfg8281 -·name:·Test·for·existence·/boot/grub2/grub.cfg
8282 ··stat:8282 ··stat:
8283 ····path:·/boot/grub2/grub.cfg8283 ····path:·/boot/grub2/grub.cfg
8284 ··register:·file_exists8284 ··register:·file_exists
8285 ··when:8285 ··when:
Max diff block lines reached; 18000/22459 bytes (80.15%) of diff not shown.
91.5 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-cis_workstation_l1.html
    
Offset 14548, 16 lines modifiedOffset 14548, 16 lines modified
00038d30:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p00038d30:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p
00038d40:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version00038d40:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version
00038d50:·3a20·3c73·7472·6f6e·673e·302e·312e·3635··:·<strong>0.1.6500038d50:·3a20·3c73·7472·6f6e·673e·302e·312e·3635··:·<strong>0.1.65
00038d60:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul00038d60:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul
00038d70:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra00038d70:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra
00038d80:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····00038d80:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····
00038d90:·2020·2020·2020·2020·2020·2020·2020·2020··················00038d90:·2020·2020·2020·2020·2020·2020·2020·2020··················
00038da0:·2861·7320·6f66·2032·3032·342d·3031·2d31··(as·of·2024-01-100038da0:·2861·7320·6f66·2032·3032·352d·3032·2d31··(as·of·2025-02-1
00038db0:·3429·0a20·2020·2020·2020·2020·2020·2020··4).·············00038db0:·3529·0a20·2020·2020·2020·2020·2020·2020··5).·············
00038dc0:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d00038dc0:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d
00038dd0:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·00038dd0:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·
00038de0:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol00038de0:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol
00038df0:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x00038df0:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x
00038e00:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj00038e00:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj
00038e10:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou00038e10:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou
00038e20:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System00038e20:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System
Offset 59532, 22 lines modifiedOffset 59532, 22 lines modified
000e88b0:·206e·616d·653a·2054·6573·7420·666f·7220···name:·Test·for·000e88b0:·206e·616d·653a·2054·6573·7420·666f·7220···name:·Test·for·
000e88c0:·6578·6973·7465·6e63·6520·2f62·6f6f·742f··existence·/boot/000e88c0:·6578·6973·7465·6e63·6520·2f62·6f6f·742f··existence·/boot/
000e88d0:·6772·7562·322f·6772·7562·2e63·6667·0a20··grub2/grub.cfg.·000e88d0:·6772·7562·322f·6772·7562·2e63·6667·0a20··grub2/grub.cfg.·
000e88e0:·2073·7461·743a·0a20·2020·2070·6174·683a···stat:.····path:000e88e0:·2073·7461·743a·0a20·2020·2070·6174·683a···stat:.····path:
000e88f0:·202f·626f·6f74·2f67·7275·6232·2f67·7275···/boot/grub2/gru000e88f0:·202f·626f·6f74·2f67·7275·6232·2f67·7275···/boot/grub2/gru
000e8900:·622e·6366·670a·2020·7265·6769·7374·6572··b.cfg.··register000e8900:·622e·6366·670a·2020·7265·6769·7374·6572··b.cfg.··register
000e8910:·3a20·6669·6c65·5f65·7869·7374·730a·2020··:·file_exists.··000e8910:·3a20·6669·6c65·5f65·7869·7374·730a·2020··:·file_exists.··
000e8920:·7768·656e·3a0a·2020·2d20·2722·6772·7562··when:.··-·'"grub000e8920:·7768·656e·3a0a·2020·2d20·2722·2f62·6f6f··when:.··-·'"/boo
000e8930:·322d·636f·6d6d·6f6e·2220·696e·2061·6e73··2-common"·in·ans 
000e8940:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa 
000e8950:·6765·7327·0a20·202d·2027·222f·626f·6f74··ges'.··-·'"/boot 
000e8960:·2f65·6669·2220·6e6f·7420·696e·2061·6e73··/efi"·not·in·ans 
000e8970:·6962·6c65·5f6d·6f75·6e74·7320·7c20·6d61··ible_mounts·|·ma 
000e8980:·7028·6174·7472·6962·7574·653d·226d·6f75··p(attribute="mou 
000e8990:·6e74·2229·207c·206c·6973·7427·0a20·202d··nt")·|·list'.··-000e8930:·742f·6566·6922·206e·6f74·2069·6e20·616e··t/efi"·not·in·an
 000e8940:·7369·626c·655f·6d6f·756e·7473·207c·206d··sible_mounts·|·m
 000e8950:·6170·2861·7474·7269·6275·7465·3d22·6d6f··ap(attribute="mo
 000e8960:·756e·7422·2920·7c20·6c69·7374·270a·2020··unt")·|·list'.··
 000e8970:·2d20·2722·6772·7562·322d·636f·6d6d·6f6e··-·'"grub2-common
 000e8980:·2220·696e·2061·6e73·6962·6c65·5f66·6163··"·in·ansible_fac
 000e8990:·7473·2e70·6163·6b61·6765·7327·0a20·202d··ts.packages'.··-
000e89a0:·2061·6e73·6962·6c65·5f76·6972·7475·616c···ansible_virtual000e89a0:·2061·6e73·6962·6c65·5f76·6972·7475·616c···ansible_virtual
000e89b0:·697a·6174·696f·6e5f·7479·7065·206e·6f74··ization_type·not000e89b0:·697a·6174·696f·6e5f·7479·7065·206e·6f74··ization_type·not
000e89c0:·2069·6e20·5b22·646f·636b·6572·222c·2022···in·["docker",·"000e89c0:·2069·6e20·5b22·646f·636b·6572·222c·2022···in·["docker",·"
000e89d0:·6c78·6322·2c20·226f·7065·6e76·7a22·2c20··lxc",·"openvz",·000e89d0:·6c78·6322·2c20·226f·7065·6e76·7a22·2c20··lxc",·"openvz",·
000e89e0:·2270·6f64·6d61·6e22·2c20·2263·6f6e·7461··"podman",·"conta000e89e0:·2270·6f64·6d61·6e22·2c20·2263·6f6e·7461··"podman",·"conta
000e89f0:·696e·6572·225d·0a20·2074·6167·733a·0a20··iner"].··tags:.·000e89f0:·696e·6572·225d·0a20·2074·6167·733a·0a20··iner"].··tags:.·
000e8a00:·202d·2043·4a49·532d·352e·352e·322e·320a···-·CJIS-5.5.2.2.000e8a00:·202d·2043·4a49·532d·352e·352e·322e·320a···-·CJIS-5.5.2.2.
Offset 59568, 22 lines modifiedOffset 59568, 22 lines modified
000e8af0:·2d20·6e61·6d65·3a20·456e·7375·7265·2067··-·name:·Ensure·g000e8af0:·2d20·6e61·6d65·3a20·456e·7375·7265·2067··-·name:·Ensure·g
000e8b00:·726f·7570·206f·776e·6572·2030·206f·6e20··roup·owner·0·on·000e8b00:·726f·7570·206f·776e·6572·2030·206f·6e20··roup·owner·0·on·
000e8b10:·2f62·6f6f·742f·6772·7562·322f·6772·7562··/boot/grub2/grub000e8b10:·2f62·6f6f·742f·6772·7562·322f·6772·7562··/boot/grub2/grub
000e8b20:·2e63·6667·0a20·2066·696c·653a·0a20·2020··.cfg.··file:.···000e8b20:·2e63·6667·0a20·2066·696c·653a·0a20·2020··.cfg.··file:.···
000e8b30:·2070·6174·683a·202f·626f·6f74·2f67·7275···path:·/boot/gru000e8b30:·2070·6174·683a·202f·626f·6f74·2f67·7275···path:·/boot/gru
000e8b40:·6232·2f67·7275·622e·6366·670a·2020·2020··b2/grub.cfg.····000e8b40:·6232·2f67·7275·622e·6366·670a·2020·2020··b2/grub.cfg.····
000e8b50:·6772·6f75·703a·2027·3027·0a20·2077·6865··group:·'0'.··whe000e8b50:·6772·6f75·703a·2027·3027·0a20·2077·6865··group:·'0'.··whe
000e8b60:·6e3a·0a20·202d·2027·2267·7275·6232·2d63··n:.··-·'"grub2-c000e8b60:·6e3a·0a20·202d·2027·222f·626f·6f74·2f65··n:.··-·'"/boot/e
000e8b70:·6f6d·6d6f·6e22·2069·6e20·616e·7369·626c··ommon"·in·ansibl 
000e8b80:·655f·6661·6374·732e·7061·636b·6167·6573··e_facts.packages 
000e8b90:·270a·2020·2d20·2722·2f62·6f6f·742f·6566··'.··-·'"/boot/ef 
000e8ba0:·6922·206e·6f74·2069·6e20·616e·7369·626c··i"·not·in·ansibl 
000e8bb0:·655f·6d6f·756e·7473·207c·206d·6170·2861··e_mounts·|·map(a 
000e8bc0:·7474·7269·6275·7465·3d22·6d6f·756e·7422··ttribute="mount" 
000e8bd0:·2920·7c20·6c69·7374·270a·2020·2d20·616e··)·|·list'.··-·an000e8b70:·6669·2220·6e6f·7420·696e·2061·6e73·6962··fi"·not·in·ansib
 000e8b80:·6c65·5f6d·6f75·6e74·7320·7c20·6d61·7028··le_mounts·|·map(
 000e8b90:·6174·7472·6962·7574·653d·226d·6f75·6e74··attribute="mount
 000e8ba0:·2229·207c·206c·6973·7427·0a20·202d·2027··")·|·list'.··-·'
 000e8bb0:·2267·7275·6232·2d63·6f6d·6d6f·6e22·2069··"grub2-common"·i
 000e8bc0:·6e20·616e·7369·626c·655f·6661·6374·732e··n·ansible_facts.
 000e8bd0:·7061·636b·6167·6573·270a·2020·2d20·616e··packages'.··-·an
000e8be0:·7369·626c·655f·7669·7274·7561·6c69·7a61··sible_virtualiza000e8be0:·7369·626c·655f·7669·7274·7561·6c69·7a61··sible_virtualiza
000e8bf0:·7469·6f6e·5f74·7970·6520·6e6f·7420·696e··tion_type·not·in000e8bf0:·7469·6f6e·5f74·7970·6520·6e6f·7420·696e··tion_type·not·in
000e8c00:·205b·2264·6f63·6b65·7222·2c20·226c·7863···["docker",·"lxc000e8c00:·205b·2264·6f63·6b65·7222·2c20·226c·7863···["docker",·"lxc
000e8c10:·222c·2022·6f70·656e·767a·222c·2022·706f··",·"openvz",·"po000e8c10:·222c·2022·6f70·656e·767a·222c·2022·706f··",·"openvz",·"po
000e8c20:·646d·616e·222c·2022·636f·6e74·6169·6e65··dman",·"containe000e8c20:·646d·616e·222c·2022·636f·6e74·6169·6e65··dman",·"containe
000e8c30:·7222·5d0a·2020·2d20·6669·6c65·5f65·7869··r"].··-·file_exi000e8c30:·7222·5d0a·2020·2d20·6669·6c65·5f65·7869··r"].··-·file_exi
000e8c40:·7374·732e·7374·6174·2069·7320·6465·6669··sts.stat·is·defi000e8c40:·7374·732e·7374·6174·2069·7320·6465·6669··sts.stat·is·defi
Offset 59633, 19 lines modifiedOffset 59633, 19 lines modified
000e8f00:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St000e8f00:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
000e8f10:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>000e8f10:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
000e8f20:·636f·6e66·6967·7572·653c·2f74·643e·3c2f··configure</td></000e8f20:·636f·6e66·6967·7572·653c·2f74·643e·3c2f··configure</td></
000e8f30:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>000e8f30:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
000e8f40:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat000e8f40:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat
000e8f50:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl000e8f50:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl
000e8f60:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai000e8f60:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai
000e8f70:·6e20·706c·6174·666f·726d·730a·6966·2072··n·platforms.if·r000e8f70:·6e20·706c·6174·666f·726d·730a·6966·205b··n·platforms.if·[
000e8f80:·706d·202d·2d71·7569·6574·202d·7120·6772··pm·--quiet·-q·gr 
000e8f90:·7562·322d·636f·6d6d·6f6e·2026·616d·703b··ub2-common·&amp; 
000e8fa0:·2661·6d70·3b20·5b20·2120·2d66·202f·7379··&amp;·[·!·-f·/sy 
000e8fb0:·732f·6669·726d·7761·7265·2f65·6669·205d··s/firmware/efi·]000e8f80:·2021·202d·6620·2f73·7973·2f66·6972·6d77···!·-f·/sys/firmw
 000e8f90:·6172·652f·6566·6920·5d20·2661·6d70·3b26··are/efi·]·&amp;&
 000e8fa0:·616d·703b·2072·706d·202d·2d71·7569·6574··amp;·rpm·--quiet
 000e8fb0:·202d·7120·6772·7562·322d·636f·6d6d·6f6e···-q·grub2-common
000e8fc0:·2026·616d·703b·2661·6d70·3b20·7b20·5b20···&amp;&amp;·{·[·000e8fc0:·2026·616d·703b·2661·6d70·3b20·7b20·5b20···&amp;&amp;·{·[·
000e8fd0:·2120·2d66·202f·2e64·6f63·6b65·7265·6e76··!·-f·/.dockerenv000e8fd0:·2120·2d66·202f·2e64·6f63·6b65·7265·6e76··!·-f·/.dockerenv
000e8fe0:·205d·2026·616d·703b·2661·6d70·3b20·5b20···]·&amp;&amp;·[·000e8fe0:·205d·2026·616d·703b·2661·6d70·3b20·5b20···]·&amp;&amp;·[·
000e8ff0:·2120·2d66·202f·7275·6e2f·2e63·6f6e·7461··!·-f·/run/.conta000e8ff0:·2120·2d66·202f·7275·6e2f·2e63·6f6e·7461··!·-f·/run/.conta
000e9000:·696e·6572·656e·7620·5d3b·207d·3b20·7468··inerenv·];·};·th000e9000:·696e·6572·656e·7620·5d3b·207d·3b20·7468··inerenv·];·};·th
000e9010:·656e·0a0a·6368·6772·7020·3020·2f62·6f6f··en..chgrp·0·/boo000e9010:·656e·0a0a·6368·6772·7020·3020·2f62·6f6f··en..chgrp·0·/boo
000e9020:·742f·6772·7562·322f·6772·7562·2e63·6667··t/grub2/grub.cfg000e9020:·742f·6772·7562·322f·6772·7562·2e63·6667··t/grub2/grub.cfg
Offset 60136, 22 lines modifiedOffset 60136, 22 lines modified
000eae70:·7420·666f·7220·6578·6973·7465·6e63·6520··t·for·existence·000eae70:·7420·666f·7220·6578·6973·7465·6e63·6520··t·for·existence·
000eae80:·2f62·6f6f·742f·6772·7562·322f·7573·6572··/boot/grub2/user000eae80:·2f62·6f6f·742f·6772·7562·322f·7573·6572··/boot/grub2/user
000eae90:·2e63·6667·0a20·2073·7461·743a·0a20·2020··.cfg.··stat:.···000eae90:·2e63·6667·0a20·2073·7461·743a·0a20·2020··.cfg.··stat:.···
000eaea0:·2070·6174·683a·202f·626f·6f74·2f67·7275···path:·/boot/gru000eaea0:·2070·6174·683a·202f·626f·6f74·2f67·7275···path:·/boot/gru
000eaeb0:·6232·2f75·7365·722e·6366·670a·2020·7265··b2/user.cfg.··re000eaeb0:·6232·2f75·7365·722e·6366·670a·2020·7265··b2/user.cfg.··re
000eaec0:·6769·7374·6572·3a20·6669·6c65·5f65·7869··gister:·file_exi000eaec0:·6769·7374·6572·3a20·6669·6c65·5f65·7869··gister:·file_exi
000eaed0:·7374·730a·2020·7768·656e·3a0a·2020·2d20··sts.··when:.··-·000eaed0:·7374·730a·2020·7768·656e·3a0a·2020·2d20··sts.··when:.··-·
000eaee0:·2722·6772·7562·322d·636f·6d6d·6f6e·2220··'"grub2-common"· 
000eaef0:·696e·2061·6e73·6962·6c65·5f66·6163·7473··in·ansible_facts 
000eaf00:·2e70·6163·6b61·6765·7327·0a20·202d·2027··.packages'.··-·' 
000eaf10:·222f·626f·6f74·2f65·6669·2220·6e6f·7420··"/boot/efi"·not· 
000eaf20:·696e·2061·6e73·6962·6c65·5f6d·6f75·6e74··in·ansible_mount 
000eaf30:·7320·7c20·6d61·7028·6174·7472·6962·7574··s·|·map(attribut 
000eaf40:·653d·226d·6f75·6e74·2229·207c·206c·6973··e="mount")·|·lis000eaee0:·2722·2f62·6f6f·742f·6566·6922·206e·6f74··'"/boot/efi"·not
 000eaef0:·2069·6e20·616e·7369·626c·655f·6d6f·756e···in·ansible_moun
 000eaf00:·7473·207c·206d·6170·2861·7474·7269·6275··ts·|·map(attribu
 000eaf10:·7465·3d22·6d6f·756e·7422·2920·7c20·6c69··te="mount")·|·li
 000eaf20:·7374·270a·2020·2d20·2722·6772·7562·322d··st'.··-·'"grub2-
 000eaf30:·636f·6d6d·6f6e·2220·696e·2061·6e73·6962··common"·in·ansib
 000eaf40:·6c65·5f66·6163·7473·2e70·6163·6b61·6765··le_facts.package
000eaf50:·7427·0a20·202d·2061·6e73·6962·6c65·5f76··t'.··-·ansible_v000eaf50:·7327·0a20·202d·2061·6e73·6962·6c65·5f76··s'.··-·ansible_v
000eaf60:·6972·7475·616c·697a·6174·696f·6e5f·7479··irtualization_ty000eaf60:·6972·7475·616c·697a·6174·696f·6e5f·7479··irtualization_ty
000eaf70:·7065·206e·6f74·2069·6e20·5b22·646f·636b··pe·not·in·["dock000eaf70:·7065·206e·6f74·2069·6e20·5b22·646f·636b··pe·not·in·["dock
000eaf80:·6572·222c·2022·6c78·6322·2c20·226f·7065··er",·"lxc",·"ope000eaf80:·6572·222c·2022·6c78·6322·2c20·226f·7065··er",·"lxc",·"ope
000eaf90:·6e76·7a22·2c20·2270·6f64·6d61·6e22·2c20··nvz",·"podman",·000eaf90:·6e76·7a22·2c20·2270·6f64·6d61·6e22·2c20··nvz",·"podman",·
000eafa0:·2263·6f6e·7461·696e·6572·225d·0a20·2074··"container"].··t000eafa0:·2263·6f6e·7461·696e·6572·225d·0a20·2074··"container"].··t
000eafb0:·6167·733a·0a20·202d·2043·4a49·532d·352e··ags:.··-·CJIS-5.000eafb0:·6167·733a·0a20·202d·2043·4a49·532d·352e··ags:.··-·CJIS-5.
000eafc0:·352e·322e·320a·2020·2d20·4e49·5354·2d38··5.2.2.··-·NIST-8000eafc0:·352e·322e·320a·2020·2d20·4e49·5354·2d38··5.2.2.··-·NIST-8
Offset 60171, 22 lines modifiedOffset 60171, 22 lines modified
Max diff block lines reached; 61802/71066 bytes (86.96%) of diff not shown.
22.0 KB
html2text {}
    
Offset 71, 15 lines modifiedOffset 71, 15 lines modified
71 ····*·cpe:/o:redhat:enterprise_linux:8.771 ····*·cpe:/o:redhat:enterprise_linux:8.7
72 ····*·cpe:/o:redhat:enterprise_linux:8.872 ····*·cpe:/o:redhat:enterprise_linux:8.8
73 ····*·cpe:/o:redhat:enterprise_linux:8.973 ····*·cpe:/o:redhat:enterprise_linux:8.9
74 ····*·cpe:/o:redhat:enterprise_linux:874 ····*·cpe:/o:redhat:enterprise_linux:8
75 ····*·cpe:/o:centos:centos:875 ····*·cpe:/o:centos:centos:8
76 *****·Revision·History·*****76 *****·Revision·History·*****
77 Current·version:·0.1.6577 Current·version:·0.1.65
78 ····*·draft·(as·of·2024-01-14)78 ····*·draft·(as·of·2025-02-15)
79 *****·Table·of·Contents·*****79 *****·Table·of·Contents·*****
80 ···1.·System_Settings80 ···1.·System_Settings
81 ·········1.·Installing_and_Maintaining_Software81 ·········1.·Installing_and_Maintaining_Software
82 ·········2.·Account_and_Access_Control82 ·········2.·Account_and_Access_Control
83 ·········3.·GRUB2_bootloader_configuration83 ·········3.·GRUB2_bootloader_configuration
84 ·········4.·Configure_Syslog84 ·········4.·Configure_Syslog
85 ·········5.·Network_Configuration_and_Firewalls85 ·········5.·Network_Configuration_and_Firewalls
Offset 8118, 16 lines modifiedOffset 8118, 16 lines modified
8118 ··-·no_reboot_needed8118 ··-·no_reboot_needed
  
8119 -·name:·Test·for·existence·/boot/grub2/grub.cfg8119 -·name:·Test·for·existence·/boot/grub2/grub.cfg
8120 ··stat:8120 ··stat:
8121 ····path:·/boot/grub2/grub.cfg8121 ····path:·/boot/grub2/grub.cfg
8122 ··register:·file_exists8122 ··register:·file_exists
8123 ··when:8123 ··when:
8124 ··-·'"grub2-common"·in·ansible_facts.packages' 
8125 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'8124 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 8125 ··-·'"grub2-common"·in·ansible_facts.packages'
8126 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8126 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
8127 ··tags:8127 ··tags:
8128 ··-·CJIS-5.5.2.28128 ··-·CJIS-5.5.2.2
8129 ··-·NIST-800-171-3.4.58129 ··-·NIST-800-171-3.4.5
8130 ··-·NIST-800-53-AC-6(1)8130 ··-·NIST-800-53-AC-6(1)
8131 ··-·NIST-800-53-CM-6(a)8131 ··-·NIST-800-53-CM-6(a)
8132 ··-·PCI-DSS-Req-7.18132 ··-·PCI-DSS-Req-7.1
Offset 8139, 16 lines modifiedOffset 8139, 16 lines modified
8139 ··-·no_reboot_needed8139 ··-·no_reboot_needed
  
8140 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg8140 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
8141 ··file:8141 ··file:
8142 ····path:·/boot/grub2/grub.cfg8142 ····path:·/boot/grub2/grub.cfg
8143 ····group:·'0'8143 ····group:·'0'
8144 ··when:8144 ··when:
8145 ··-·'"grub2-common"·in·ansible_facts.packages' 
8146 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'8145 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 8146 ··-·'"grub2-common"·in·ansible_facts.packages'
8147 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8147 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
8148 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists8148 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists
8149 ··tags:8149 ··tags:
8150 ··-·CJIS-5.5.2.28150 ··-·CJIS-5.5.2.2
8151 ··-·NIST-800-171-3.4.58151 ··-·NIST-800-171-3.4.5
8152 ··-·NIST-800-53-AC-6(1)8152 ··-·NIST-800-53-AC-6(1)
8153 ··-·NIST-800-53-CM-6(a)8153 ··-·NIST-800-53-CM-6(a)
Offset 8160, 15 lines modifiedOffset 8160, 15 lines modified
8160 ··-·medium_severity8160 ··-·medium_severity
8161 ··-·no_reboot_needed8161 ··-·no_reboot_needed
8162 Remediation_Shell_script_⇲8162 Remediation_Shell_script_⇲
8163 Complexity:·low8163 Complexity:·low
8164 Disruption:·low8164 Disruption:·low
8165 Strategy:···configure8165 Strategy:···configure
8166 #·Remediation·is·applicable·only·in·certain·platforms8166 #·Remediation·is·applicable·only·in·certain·platforms
8167 if·rpm·--quiet·-q·grub2-common·&&·[·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then8167 if·[·!·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
8168 chgrp·0·/boot/grub2/grub.cfg8168 chgrp·0·/boot/grub2/grub.cfg
  
8169 else8169 else
8170 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'8170 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
8171 fi8171 fi
8172 ***·Rule  ·Verify·/boot/grub2/user.cfg·Group·Ownership·  [ref]·***8172 ***·Rule  ·Verify·/boot/grub2/user.cfg·Group·Ownership·  [ref]·***
Offset 8199, 16 lines modifiedOffset 8199, 16 lines modified
8199 ··-·no_reboot_needed8199 ··-·no_reboot_needed
  
8200 -·name:·Test·for·existence·/boot/grub2/user.cfg8200 -·name:·Test·for·existence·/boot/grub2/user.cfg
8201 ··stat:8201 ··stat:
8202 ····path:·/boot/grub2/user.cfg8202 ····path:·/boot/grub2/user.cfg
8203 ··register:·file_exists8203 ··register:·file_exists
8204 ··when:8204 ··when:
8205 ··-·'"grub2-common"·in·ansible_facts.packages' 
8206 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'8205 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 8206 ··-·'"grub2-common"·in·ansible_facts.packages'
8207 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8207 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
8208 ··tags:8208 ··tags:
8209 ··-·CJIS-5.5.2.28209 ··-·CJIS-5.5.2.2
8210 ··-·NIST-800-171-3.4.58210 ··-·NIST-800-171-3.4.5
8211 ··-·NIST-800-53-AC-6(1)8211 ··-·NIST-800-53-AC-6(1)
8212 ··-·NIST-800-53-CM-6(a)8212 ··-·NIST-800-53-CM-6(a)
8213 ··-·PCI-DSS-Req-7.18213 ··-·PCI-DSS-Req-7.1
Offset 8220, 16 lines modifiedOffset 8220, 16 lines modified
8220 ··-·no_reboot_needed8220 ··-·no_reboot_needed
  
8221 -·name:·Ensure·group·owner·0·on·/boot/grub2/user.cfg8221 -·name:·Ensure·group·owner·0·on·/boot/grub2/user.cfg
8222 ··file:8222 ··file:
8223 ····path:·/boot/grub2/user.cfg8223 ····path:·/boot/grub2/user.cfg
8224 ····group:·'0'8224 ····group:·'0'
8225 ··when:8225 ··when:
8226 ··-·'"grub2-common"·in·ansible_facts.packages' 
8227 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'8226 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 8227 ··-·'"grub2-common"·in·ansible_facts.packages'
8228 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8228 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
8229 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists8229 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists
8230 ··tags:8230 ··tags:
8231 ··-·CJIS-5.5.2.28231 ··-·CJIS-5.5.2.2
8232 ··-·NIST-800-171-3.4.58232 ··-·NIST-800-171-3.4.5
8233 ··-·NIST-800-53-AC-6(1)8233 ··-·NIST-800-53-AC-6(1)
8234 ··-·NIST-800-53-CM-6(a)8234 ··-·NIST-800-53-CM-6(a)
Offset 8241, 15 lines modifiedOffset 8241, 15 lines modified
8241 ··-·medium_severity8241 ··-·medium_severity
8242 ··-·no_reboot_needed8242 ··-·no_reboot_needed
8243 Remediation_Shell_script_⇲8243 Remediation_Shell_script_⇲
8244 Complexity:·low8244 Complexity:·low
8245 Disruption:·low8245 Disruption:·low
8246 Strategy:···configure8246 Strategy:···configure
8247 #·Remediation·is·applicable·only·in·certain·platforms8247 #·Remediation·is·applicable·only·in·certain·platforms
8248 if·rpm·--quiet·-q·grub2-common·&&·[·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then8248 if·[·!·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
8249 chgrp·0·/boot/grub2/user.cfg8249 chgrp·0·/boot/grub2/user.cfg
  
8250 else8250 else
8251 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'8251 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
8252 fi8252 fi
8253 ***·Rule  ·Verify·/boot/grub2/grub.cfg·User·Ownership·  [ref]·***8253 ***·Rule  ·Verify·/boot/grub2/grub.cfg·User·Ownership·  [ref]·***
Offset 8280, 16 lines modifiedOffset 8280, 16 lines modified
8280 ··-·no_reboot_needed8280 ··-·no_reboot_needed
  
8281 -·name:·Test·for·existence·/boot/grub2/grub.cfg8281 -·name:·Test·for·existence·/boot/grub2/grub.cfg
8282 ··stat:8282 ··stat:
8283 ····path:·/boot/grub2/grub.cfg8283 ····path:·/boot/grub2/grub.cfg
8284 ··register:·file_exists8284 ··register:·file_exists
8285 ··when:8285 ··when:
Max diff block lines reached; 18000/22459 bytes (80.15%) of diff not shown.
837 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-cis_workstation_l2.html
    
Offset 14548, 16 lines modifiedOffset 14548, 16 lines modified
00038d30:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p00038d30:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p
00038d40:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version00038d40:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version
00038d50:·3a20·3c73·7472·6f6e·673e·302e·312e·3635··:·<strong>0.1.6500038d50:·3a20·3c73·7472·6f6e·673e·302e·312e·3635··:·<strong>0.1.65
00038d60:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul00038d60:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul
00038d70:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra00038d70:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra
00038d80:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····00038d80:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····
00038d90:·2020·2020·2020·2020·2020·2020·2020·2020··················00038d90:·2020·2020·2020·2020·2020·2020·2020·2020··················
00038da0:·2861·7320·6f66·2032·3032·342d·3031·2d31··(as·of·2024-01-100038da0:·2861·7320·6f66·2032·3032·352d·3032·2d31··(as·of·2025-02-1
00038db0:·3429·0a20·2020·2020·2020·2020·2020·2020··4).·············00038db0:·3529·0a20·2020·2020·2020·2020·2020·2020··5).·············
00038dc0:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d00038dc0:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d
00038dd0:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·00038dd0:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·
00038de0:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol00038de0:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol
00038df0:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x00038df0:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x
00038e00:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj00038e00:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj
00038e10:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou00038e10:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou
00038e20:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System00038e20:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System
Offset 62457, 23 lines modifiedOffset 62457, 23 lines modified
000f3f80:·640a·2020·2d20·7265·7374·7269·6374·5f73··d.··-·restrict_s000f3f80:·640a·2020·2d20·7265·7374·7269·6374·5f73··d.··-·restrict_s
000f3f90:·7472·6174·6567·790a·0a2d·206e·616d·653a··trategy..-·name:000f3f90:·7472·6174·6567·790a·0a2d·206e·616d·653a··trategy..-·name:
000f3fa0:·2053·6574·2061·7263·6869·7465·6374·7572···Set·architectur000f3fa0:·2053·6574·2061·7263·6869·7465·6374·7572···Set·architectur
000f3fb0:·6520·666f·7220·6175·6469·7420·6368·6d6f··e·for·audit·chmo000f3fb0:·6520·666f·7220·6175·6469·7420·6368·6d6f··e·for·audit·chmo
000f3fc0:·6420·7461·736b·730a·2020·7365·745f·6661··d·tasks.··set_fa000f3fc0:·6420·7461·736b·730a·2020·7365·745f·6661··d·tasks.··set_fa
000f3fd0:·6374·3a0a·2020·2020·6175·6469·745f·6172··ct:.····audit_ar000f3fd0:·6374·3a0a·2020·2020·6175·6469·745f·6172··ct:.····audit_ar
000f3fe0:·6368·3a20·6236·340a·2020·7768·656e·3a0a··ch:·b64.··when:.000f3fe0:·6368·3a20·6236·340a·2020·7768·656e·3a0a··ch:·b64.··when:.
000f3ff0:·2020·2d20·2722·6175·6469·7422·2069·6e20····-·'"audit"·in· 
000f4000:·616e·7369·626c·655f·6661·6374·732e·7061··ansible_facts.pa 
000f4010:·636b·6167·6573·270a·2020·2d20·616e·7369··ckages'.··-·ansi 
000f4020:·626c·655f·7669·7274·7561·6c69·7a61·7469··ble_virtualizati 
000f4030:·6f6e·5f74·7970·6520·6e6f·7420·696e·205b··on_type·not·in·[ 
000f4040:·2264·6f63·6b65·7222·2c20·226c·7863·222c··"docker",·"lxc", 
000f4050:·2022·6f70·656e·767a·222c·2022·706f·646d···"openvz",·"podm 
000f4060:·616e·222c·2022·636f·6e74·6169·6e65·7222··an",·"container"000f3ff0:·2020·2d20·616e·7369·626c·655f·7669·7274····-·ansible_virt
 000f4000:·7561·6c69·7a61·7469·6f6e·5f74·7970·6520··ualization_type·
 000f4010:·6e6f·7420·696e·205b·2264·6f63·6b65·7222··not·in·["docker"
 000f4020:·2c20·226c·7863·222c·2022·6f70·656e·767a··,·"lxc",·"openvz
 000f4030:·222c·2022·706f·646d·616e·222c·2022·636f··",·"podman",·"co
 000f4040:·6e74·6169·6e65·7222·5d0a·2020·2d20·2722··ntainer"].··-·'"
 000f4050:·6175·6469·7422·2069·6e20·616e·7369·626c··audit"·in·ansibl
 000f4060:·655f·6661·6374·732e·7061·636b·6167·6573··e_facts.packages
000f4070:·5d0a·2020·2d20·616e·7369·626c·655f·6172··].··-·ansible_ar000f4070:·270a·2020·2d20·616e·7369·626c·655f·6172··'.··-·ansible_ar
000f4080:·6368·6974·6563·7475·7265·203d·3d20·2261··chitecture·==·"a000f4080:·6368·6974·6563·7475·7265·203d·3d20·2261··chitecture·==·"a
000f4090:·6172·6368·3634·2220·6f72·2061·6e73·6962··arch64"·or·ansib000f4090:·6172·6368·3634·2220·6f72·2061·6e73·6962··arch64"·or·ansib
000f40a0:·6c65·5f61·7263·6869·7465·6374·7572·6520··le_architecture·000f40a0:·6c65·5f61·7263·6869·7465·6374·7572·6520··le_architecture·
000f40b0:·3d3d·2022·7070·6336·3422·206f·7220·616e··==·"ppc64"·or·an000f40b0:·3d3d·2022·7070·6336·3422·206f·7220·616e··==·"ppc64"·or·an
000f40c0:·7369·626c·655f·6172·6368·6974·6563·7475··sible_architectu000f40c0:·7369·626c·655f·6172·6368·6974·6563·7475··sible_architectu
000f40d0:·7265·0a20·2020·203d·3d20·2270·7063·3634··re.····==·"ppc64000f40d0:·7265·0a20·2020·203d·3d20·2270·7063·3634··re.····==·"ppc64
000f40e0:·6c65·2220·6f72·2061·6e73·6962·6c65·5f61··le"·or·ansible_a000f40e0:·6c65·2220·6f72·2061·6e73·6962·6c65·5f61··le"·or·ansible_a
Offset 62780, 23 lines modifiedOffset 62780, 23 lines modified
000f53b0:·3d70·6572·6d5f·6d6f·640a·2020·2020·2020··=perm_mod.······000f53b0:·3d70·6572·6d5f·6d6f·640a·2020·2020·2020··=perm_mod.······
000f53c0:·6372·6561·7465·3a20·7472·7565·0a20·2020··create:·true.···000f53c0:·6372·6561·7465·3a20·7472·7565·0a20·2020··create:·true.···
000f53d0:·2020·206d·6f64·653a·206f·2d72·7778·0a20·····mode:·o-rwx.·000f53d0:·2020·206d·6f64·653a·206f·2d72·7778·0a20·····mode:·o-rwx.·
000f53e0:·2020·2020·2073·7461·7465·3a20·7072·6573·······state:·pres000f53e0:·2020·2020·2073·7461·7465·3a20·7072·6573·······state:·pres
000f53f0:·656e·740a·2020·2020·7768·656e·3a20·7379··ent.····when:·sy000f53f0:·656e·740a·2020·2020·7768·656e·3a20·7379··ent.····when:·sy
000f5400:·7363·616c·6c73·5f66·6f75·6e64·207c·206c··scalls_found·|·l000f5400:·7363·616c·6c73·5f66·6f75·6e64·207c·206c··scalls_found·|·l
000f5410:·656e·6774·6820·3d3d·2030·0a20·2077·6865··ength·==·0.··whe000f5410:·656e·6774·6820·3d3d·2030·0a20·2077·6865··ength·==·0.··whe
000f5420:·6e3a·0a20·202d·2027·2261·7564·6974·2220··n:.··-·'"audit"· 
000f5430:·696e·2061·6e73·6962·6c65·5f66·6163·7473··in·ansible_facts 
000f5440:·2e70·6163·6b61·6765·7327·0a20·202d·2061··.packages'.··-·a 
000f5450:·6e73·6962·6c65·5f76·6972·7475·616c·697a··nsible_virtualiz 
000f5460:·6174·696f·6e5f·7479·7065·206e·6f74·2069··ation_type·not·i 
000f5470:·6e20·5b22·646f·636b·6572·222c·2022·6c78··n·["docker",·"lx 
000f5480:·6322·2c20·226f·7065·6e76·7a22·2c20·2270··c",·"openvz",·"p 
000f5490:·6f64·6d61·6e22·2c20·2263·6f6e·7461·696e··odman",·"contain000f5420:·6e3a·0a20·202d·2061·6e73·6962·6c65·5f76··n:.··-·ansible_v
 000f5430:·6972·7475·616c·697a·6174·696f·6e5f·7479··irtualization_ty
 000f5440:·7065·206e·6f74·2069·6e20·5b22·646f·636b··pe·not·in·["dock
 000f5450:·6572·222c·2022·6c78·6322·2c20·226f·7065··er",·"lxc",·"ope
 000f5460:·6e76·7a22·2c20·2270·6f64·6d61·6e22·2c20··nvz",·"podman",·
 000f5470:·2263·6f6e·7461·696e·6572·225d·0a20·202d··"container"].··-
 000f5480:·2027·2261·7564·6974·2220·696e·2061·6e73···'"audit"·in·ans
 000f5490:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa
000f54a0:·6572·225d·0a20·2074·6167·733a·0a20·202d··er"].··tags:.··-000f54a0:·6765·7327·0a20·2074·6167·733a·0a20·202d··ges'.··tags:.··-
000f54b0:·2043·4a49·532d·352e·342e·312e·310a·2020···CJIS-5.4.1.1.··000f54b0:·2043·4a49·532d·352e·342e·312e·310a·2020···CJIS-5.4.1.1.··
000f54c0:·2d20·4449·5341·2d53·5449·472d·5248·454c··-·DISA-STIG-RHEL000f54c0:·2d20·4449·5341·2d53·5449·472d·5248·454c··-·DISA-STIG-RHEL
000f54d0:·2d30·382d·3033·3034·3930·0a20·202d·204e··-08-030490.··-·N000f54d0:·2d30·382d·3033·3034·3930·0a20·202d·204e··-08-030490.··-·N
000f54e0:·4953·542d·3830·302d·3137·312d·332e·312e··IST-800-171-3.1.000f54e0:·4953·542d·3830·302d·3137·312d·332e·312e··IST-800-171-3.1.
000f54f0:·370a·2020·2d20·4e49·5354·2d38·3030·2d35··7.··-·NIST-800-5000f54f0:·370a·2020·2d20·4e49·5354·2d38·3030·2d35··7.··-·NIST-800-5
000f5500:·332d·4155·2d31·3228·6329·0a20·202d·204e··3-AU-12(c).··-·N000f5500:·332d·4155·2d31·3228·6329·0a20·202d·204e··3-AU-12(c).··-·N
000f5510:·4953·542d·3830·302d·3533·2d41·552d·3228··IST-800-53-AU-2(000f5510:·4953·542d·3830·302d·3533·2d41·552d·3228··IST-800-53-AU-2(
Offset 63092, 22 lines modifiedOffset 63092, 22 lines modified
000f6730:·6d6f·640a·2020·2020·2020·6372·6561·7465··mod.······create000f6730:·6d6f·640a·2020·2020·2020·6372·6561·7465··mod.······create
000f6740:·3a20·7472·7565·0a20·2020·2020·206d·6f64··:·true.······mod000f6740:·3a20·7472·7565·0a20·2020·2020·206d·6f64··:·true.······mod
000f6750:·653a·206f·2d72·7778·0a20·2020·2020·2073··e:·o-rwx.······s000f6750:·653a·206f·2d72·7778·0a20·2020·2020·2073··e:·o-rwx.······s
000f6760:·7461·7465·3a20·7072·6573·656e·740a·2020··tate:·present.··000f6760:·7461·7465·3a20·7072·6573·656e·740a·2020··tate:·present.··
000f6770:·2020·7768·656e·3a20·7379·7363·616c·6c73····when:·syscalls000f6770:·2020·7768·656e·3a20·7379·7363·616c·6c73····when:·syscalls
000f6780:·5f66·6f75·6e64·207c·206c·656e·6774·6820··_found·|·length·000f6780:·5f66·6f75·6e64·207c·206c·656e·6774·6820··_found·|·length·
000f6790:·3d3d·2030·0a20·2077·6865·6e3a·0a20·202d··==·0.··when:.··-000f6790:·3d3d·2030·0a20·2077·6865·6e3a·0a20·202d··==·0.··when:.··-
000f67a0:·2027·2261·7564·6974·2220·696e·2061·6e73···'"audit"·in·ans 
000f67b0:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa 
000f67c0:·6765·7327·0a20·202d·2061·6e73·6962·6c65··ges'.··-·ansible 
000f67d0:·5f76·6972·7475·616c·697a·6174·696f·6e5f··_virtualization_ 
000f67e0:·7479·7065·206e·6f74·2069·6e20·5b22·646f··type·not·in·["do 
000f67f0:·636b·6572·222c·2022·6c78·6322·2c20·226f··cker",·"lxc",·"o 
000f6800:·7065·6e76·7a22·2c20·2270·6f64·6d61·6e22··penvz",·"podman" 
000f6810:·2c20·2263·6f6e·7461·696e·6572·225d·0a20··,·"container"].·000f67a0:·2061·6e73·6962·6c65·5f76·6972·7475·616c···ansible_virtual
 000f67b0:·697a·6174·696f·6e5f·7479·7065·206e·6f74··ization_type·not
 000f67c0:·2069·6e20·5b22·646f·636b·6572·222c·2022···in·["docker",·"
 000f67d0:·6c78·6322·2c20·226f·7065·6e76·7a22·2c20··lxc",·"openvz",·
 000f67e0:·2270·6f64·6d61·6e22·2c20·2263·6f6e·7461··"podman",·"conta
 000f67f0:·696e·6572·225d·0a20·202d·2027·2261·7564··iner"].··-·'"aud
 000f6800:·6974·2220·696e·2061·6e73·6962·6c65·5f66··it"·in·ansible_f
 000f6810:·6163·7473·2e70·6163·6b61·6765·7327·0a20··acts.packages'.·
000f6820:·202d·2061·7564·6974·5f61·7263·6820·3d3d···-·audit_arch·==000f6820:·202d·2061·7564·6974·5f61·7263·6820·3d3d···-·audit_arch·==
000f6830:·2022·6236·3422·0a20·2074·6167·733a·0a20···"b64".··tags:.·000f6830:·2022·6236·3422·0a20·2074·6167·733a·0a20···"b64".··tags:.·
000f6840:·202d·2043·4a49·532d·352e·342e·312e·310a···-·CJIS-5.4.1.1.000f6840:·202d·2043·4a49·532d·352e·342e·312e·310a···-·CJIS-5.4.1.1.
000f6850:·2020·2d20·4449·5341·2d53·5449·472d·5248····-·DISA-STIG-RH000f6850:·2020·2d20·4449·5341·2d53·5449·472d·5248····-·DISA-STIG-RH
000f6860:·454c·2d30·382d·3033·3034·3930·0a20·202d··EL-08-030490.··-000f6860:·454c·2d30·382d·3033·3034·3930·0a20·202d··EL-08-030490.··-
000f6870:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.000f6870:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.
000f6880:·312e·370a·2020·2d20·4e49·5354·2d38·3030··1.7.··-·NIST-800000f6880:·312e·370a·2020·2d20·4e49·5354·2d38·3030··1.7.··-·NIST-800
Offset 63141, 21 lines modifiedOffset 63141, 21 lines modified
000f6a40:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class000f6a40:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
000f6a50:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse000f6a50:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
000f6a60:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i000f6a60:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
000f6a70:·646d·3235·3339·3022·3e3c·7072·653e·3c63··dm25390"><pre><c000f6a70:·646d·3235·3339·3022·3e3c·7072·653e·3c63··dm25390"><pre><c
000f6a80:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio000f6a80:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio
000f6a90:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·000f6a90:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·
000f6aa0:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·000f6aa0:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·
000f6ab0:·706c·6174·666f·726d·730a·6966·2072·706d··platforms.if·rpm000f6ab0:·706c·6174·666f·726d·730a·6966·205b·2021··platforms.if·[·!
000f6ac0:·202d·2d71·7569·6574·202d·7120·6175·6469···--quiet·-q·audi 
000f6ad0:·7420·2661·6d70·3b26·616d·703b·205b·2021··t·&amp;&amp;·[·! 
000f6ae0:·202d·6620·2f2e·646f·636b·6572·656e·7620···-f·/.dockerenv·000f6ac0:·202d·6620·2f2e·646f·636b·6572·656e·7620···-f·/.dockerenv·
000f6af0:·5d20·2661·6d70·3b26·616d·703b·205b·2021··]·&amp;&amp;·[·!000f6ad0:·5d20·2661·6d70·3b26·616d·703b·205b·2021··]·&amp;&amp;·[·!
000f6b00:·202d·6620·2f72·756e·2f2e·636f·6e74·6169···-f·/run/.contai000f6ae0:·202d·6620·2f72·756e·2f2e·636f·6e74·6169···-f·/run/.contai
000f6b10:·6e65·7265·6e76·205d·3b20·7468·656e·0a0a··nerenv·];·then..000f6af0:·6e65·7265·6e76·205d·2026·616d·703b·2661··nerenv·]·&amp;&a
 000f6b00:·6d70·3b20·7270·6d20·2d2d·7175·6965·7420··mp;·rpm·--quiet·
 000f6b10:·2d71·2061·7564·6974·3b20·7468·656e·0a0a··-q·audit;·then..
000f6b20:·2320·4669·7273·7420·7065·7266·6f72·6d20··#·First·perform·000f6b20:·2320·4669·7273·7420·7065·7266·6f72·6d20··#·First·perform·
000f6b30:·7468·6520·7265·6d65·6469·6174·696f·6e20··the·remediation·000f6b30:·7468·6520·7265·6d65·6469·6174·696f·6e20··the·remediation·
Max diff block lines reached; 652897/662411 bytes (98.56%) of diff not shown.
190 KB
html2text {}
    
Offset 71, 15 lines modifiedOffset 71, 15 lines modified
71 ····*·cpe:/o:redhat:enterprise_linux:8.771 ····*·cpe:/o:redhat:enterprise_linux:8.7
72 ····*·cpe:/o:redhat:enterprise_linux:8.872 ····*·cpe:/o:redhat:enterprise_linux:8.8
73 ····*·cpe:/o:redhat:enterprise_linux:8.973 ····*·cpe:/o:redhat:enterprise_linux:8.9
74 ····*·cpe:/o:redhat:enterprise_linux:874 ····*·cpe:/o:redhat:enterprise_linux:8
75 ····*·cpe:/o:centos:centos:875 ····*·cpe:/o:centos:centos:8
76 *****·Revision·History·*****76 *****·Revision·History·*****
77 Current·version:·0.1.6577 Current·version:·0.1.65
78 ····*·draft·(as·of·2024-01-14)78 ····*·draft·(as·of·2025-02-15)
79 *****·Table·of·Contents·*****79 *****·Table·of·Contents·*****
80 ···1.·System_Settings80 ···1.·System_Settings
81 ·········1.·Installing_and_Maintaining_Software81 ·········1.·Installing_and_Maintaining_Software
82 ·········2.·Account_and_Access_Control82 ·········2.·Account_and_Access_Control
83 ·········3.·System_Accounting_with_auditd83 ·········3.·System_Accounting_with_auditd
84 ·········4.·GRUB2_bootloader_configuration84 ·········4.·GRUB2_bootloader_configuration
85 ·········5.·Configure_Syslog85 ·········5.·Configure_Syslog
Offset 8266, 16 lines modifiedOffset 8266, 16 lines modified
8266 ··-·reboot_required8266 ··-·reboot_required
8267 ··-·restrict_strategy8267 ··-·restrict_strategy
  
8268 -·name:·Set·architecture·for·audit·chmod·tasks8268 -·name:·Set·architecture·for·audit·chmod·tasks
8269 ··set_fact:8269 ··set_fact:
8270 ····audit_arch:·b648270 ····audit_arch:·b64
8271 ··when:8271 ··when:
8272 ··-·'"audit"·in·ansible_facts.packages' 
8273 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8272 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 8273 ··-·'"audit"·in·ansible_facts.packages'
8274 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture8274 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
8275 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"8275 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
8276 ··tags:8276 ··tags:
8277 ··-·CJIS-5.4.1.18277 ··-·CJIS-5.4.1.1
8278 ··-·DISA-STIG-RHEL-08-0304908278 ··-·DISA-STIG-RHEL-08-030490
8279 ··-·NIST-800-171-3.1.78279 ··-·NIST-800-171-3.1.7
8280 ··-·NIST-800-53-AU-12(c)8280 ··-·NIST-800-53-AU-12(c)
Offset 8412, 16 lines modifiedOffset 8412, 16 lines modified
8412 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10008412 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
8413 ········-F·auid!=unset·-F·key=perm_mod8413 ········-F·auid!=unset·-F·key=perm_mod
8414 ······create:·true8414 ······create:·true
8415 ······mode:·o-rwx8415 ······mode:·o-rwx
8416 ······state:·present8416 ······state:·present
8417 ····when:·syscalls_found·|·length·==·08417 ····when:·syscalls_found·|·length·==·0
8418 ··when:8418 ··when:
8419 ··-·'"audit"·in·ansible_facts.packages' 
8420 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8419 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 8420 ··-·'"audit"·in·ansible_facts.packages'
8421 ··tags:8421 ··tags:
8422 ··-·CJIS-5.4.1.18422 ··-·CJIS-5.4.1.1
8423 ··-·DISA-STIG-RHEL-08-0304908423 ··-·DISA-STIG-RHEL-08-030490
8424 ··-·NIST-800-171-3.1.78424 ··-·NIST-800-171-3.1.7
8425 ··-·NIST-800-53-AU-12(c)8425 ··-·NIST-800-53-AU-12(c)
8426 ··-·NIST-800-53-AU-2(d)8426 ··-·NIST-800-53-AU-2(d)
8427 ··-·NIST-800-53-CM-6(a)8427 ··-·NIST-800-53-CM-6(a)
Offset 8556, 16 lines modifiedOffset 8556, 16 lines modified
8556 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10008556 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
8557 ········-F·auid!=unset·-F·key=perm_mod8557 ········-F·auid!=unset·-F·key=perm_mod
8558 ······create:·true8558 ······create:·true
8559 ······mode:·o-rwx8559 ······mode:·o-rwx
8560 ······state:·present8560 ······state:·present
8561 ····when:·syscalls_found·|·length·==·08561 ····when:·syscalls_found·|·length·==·0
8562 ··when:8562 ··when:
8563 ··-·'"audit"·in·ansible_facts.packages' 
8564 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8563 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 8564 ··-·'"audit"·in·ansible_facts.packages'
8565 ··-·audit_arch·==·"b64"8565 ··-·audit_arch·==·"b64"
8566 ··tags:8566 ··tags:
8567 ··-·CJIS-5.4.1.18567 ··-·CJIS-5.4.1.1
8568 ··-·DISA-STIG-RHEL-08-0304908568 ··-·DISA-STIG-RHEL-08-030490
8569 ··-·NIST-800-171-3.1.78569 ··-·NIST-800-171-3.1.7
8570 ··-·NIST-800-53-AU-12(c)8570 ··-·NIST-800-53-AU-12(c)
8571 ··-·NIST-800-53-AU-2(d)8571 ··-·NIST-800-53-AU-2(d)
Offset 8575, 15 lines modifiedOffset 8575, 15 lines modified
8575 ··-·low_complexity8575 ··-·low_complexity
8576 ··-·low_disruption8576 ··-·low_disruption
8577 ··-·medium_severity8577 ··-·medium_severity
8578 ··-·reboot_required8578 ··-·reboot_required
8579 ··-·restrict_strategy8579 ··-·restrict_strategy
8580 Remediation_Shell_script_⇲8580 Remediation_Shell_script_⇲
8581 #·Remediation·is·applicable·only·in·certain·platforms8581 #·Remediation·is·applicable·only·in·certain·platforms
8582 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then8582 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
8583 #·First·perform·the·remediation·of·the·syscall·rule8583 #·First·perform·the·remediation·of·the·syscall·rule
8584 #·Retrieve·hardware·architecture·of·the·underlying·system8584 #·Retrieve·hardware·architecture·of·the·underlying·system
8585 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")8585 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
8586 for·ARCH·in·"${RULE_ARCHS[@]}"8586 for·ARCH·in·"${RULE_ARCHS[@]}"
8587 do8587 do
Offset 8944, 16 lines modifiedOffset 8944, 16 lines modified
8944 ··-·reboot_required8944 ··-·reboot_required
8945 ··-·restrict_strategy8945 ··-·restrict_strategy
  
8946 -·name:·Set·architecture·for·audit·chown·tasks8946 -·name:·Set·architecture·for·audit·chown·tasks
8947 ··set_fact:8947 ··set_fact:
8948 ····audit_arch:·b648948 ····audit_arch:·b64
8949 ··when:8949 ··when:
8950 ··-·'"audit"·in·ansible_facts.packages' 
8951 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8950 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 8951 ··-·'"audit"·in·ansible_facts.packages'
8952 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture8952 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
8953 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"8953 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
8954 ··tags:8954 ··tags:
8955 ··-·CJIS-5.4.1.18955 ··-·CJIS-5.4.1.1
8956 ··-·DISA-STIG-RHEL-08-0304808956 ··-·DISA-STIG-RHEL-08-030480
8957 ··-·NIST-800-171-3.1.78957 ··-·NIST-800-171-3.1.7
8958 ··-·NIST-800-53-AU-12(c)8958 ··-·NIST-800-53-AU-12(c)
Offset 9092, 16 lines modifiedOffset 9092, 16 lines modified
9092 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10009092 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
9093 ········-F·auid!=unset·-F·key=perm_mod9093 ········-F·auid!=unset·-F·key=perm_mod
9094 ······create:·true9094 ······create:·true
9095 ······mode:·o-rwx9095 ······mode:·o-rwx
9096 ······state:·present9096 ······state:·present
9097 ····when:·syscalls_found·|·length·==·09097 ····when:·syscalls_found·|·length·==·0
9098 ··when:9098 ··when:
9099 ··-·'"audit"·in·ansible_facts.packages' 
9100 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]9099 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 9100 ··-·'"audit"·in·ansible_facts.packages'
9101 ··tags:9101 ··tags:
9102 ··-·CJIS-5.4.1.19102 ··-·CJIS-5.4.1.1
9103 ··-·DISA-STIG-RHEL-08-0304809103 ··-·DISA-STIG-RHEL-08-030480
9104 ··-·NIST-800-171-3.1.79104 ··-·NIST-800-171-3.1.7
9105 ··-·NIST-800-53-AU-12(c)9105 ··-·NIST-800-53-AU-12(c)
9106 ··-·NIST-800-53-AU-2(d)9106 ··-·NIST-800-53-AU-2(d)
9107 ··-·NIST-800-53-CM-6(a)9107 ··-·NIST-800-53-CM-6(a)
Offset 9238, 16 lines modifiedOffset 9238, 16 lines modified
9238 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10009238 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
9239 ········-F·auid!=unset·-F·key=perm_mod9239 ········-F·auid!=unset·-F·key=perm_mod
9240 ······create:·true9240 ······create:·true
9241 ······mode:·o-rwx9241 ······mode:·o-rwx
9242 ······state:·present9242 ······state:·present
Max diff block lines reached; 189972/194456 bytes (97.69%) of diff not shown.
533 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-cjis.html
    
Offset 14541, 15 lines modifiedOffset 14541, 15 lines modified
00038cc0:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren00038cc0:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren
00038cd0:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro00038cd0:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro
00038ce0:·6e67·3e30·2e31·2e36·353c·2f73·7472·6f6e··ng>0.1.65</stron00038ce0:·6e67·3e30·2e31·2e36·353c·2f73·7472·6f6e··ng>0.1.65</stron
00038cf0:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s00038cf0:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s
00038d00:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str00038d00:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str
00038d10:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········00038d10:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········
00038d20:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·00038d20:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·
00038d30:·3230·3234·2d30·312d·3134·290a·2020·2020··2024-01-14).····00038d30:·3230·3235·2d30·322d·3135·290a·2020·2020··2025-02-15).····
00038d40:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li00038d40:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li
00038d50:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>00038d50:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>
00038d60:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content00038d60:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content
00038d70:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a00038d70:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a
00038d80:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or00038d80:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or
00038d90:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con00038d90:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con
00038da0:·7465·6e74·5f67·726f·7570·5f73·7973·7465··tent_group_syste00038da0:·7465·6e74·5f67·726f·7570·5f73·7973·7465··tent_group_syste
Offset 41827, 23 lines modifiedOffset 41827, 23 lines modified
000a3620:·7265·640a·2020·2d20·7265·7374·7269·6374··red.··-·restrict000a3620:·7265·640a·2020·2d20·7265·7374·7269·6374··red.··-·restrict
000a3630:·5f73·7472·6174·6567·790a·0a2d·206e·616d··_strategy..-·nam000a3630:·5f73·7472·6174·6567·790a·0a2d·206e·616d··_strategy..-·nam
000a3640:·653a·2053·6574·2061·7263·6869·7465·6374··e:·Set·architect000a3640:·653a·2053·6574·2061·7263·6869·7465·6374··e:·Set·architect
000a3650:·7572·6520·666f·7220·6175·6469·7420·6368··ure·for·audit·ch000a3650:·7572·6520·666f·7220·6175·6469·7420·6368··ure·for·audit·ch
000a3660:·6d6f·6420·7461·736b·730a·2020·7365·745f··mod·tasks.··set_000a3660:·6d6f·6420·7461·736b·730a·2020·7365·745f··mod·tasks.··set_
000a3670:·6661·6374·3a0a·2020·2020·6175·6469·745f··fact:.····audit_000a3670:·6661·6374·3a0a·2020·2020·6175·6469·745f··fact:.····audit_
000a3680:·6172·6368·3a20·6236·340a·2020·7768·656e··arch:·b64.··when000a3680:·6172·6368·3a20·6236·340a·2020·7768·656e··arch:·b64.··when
000a3690:·3a0a·2020·2d20·2722·6175·6469·7422·2069··:.··-·'"audit"·i 
000a36a0:·6e20·616e·7369·626c·655f·6661·6374·732e··n·ansible_facts. 
000a36b0:·7061·636b·6167·6573·270a·2020·2d20·616e··packages'.··-·an 
000a36c0:·7369·626c·655f·7669·7274·7561·6c69·7a61··sible_virtualiza 
000a36d0:·7469·6f6e·5f74·7970·6520·6e6f·7420·696e··tion_type·not·in 
000a36e0:·205b·2264·6f63·6b65·7222·2c20·226c·7863···["docker",·"lxc 
000a36f0:·222c·2022·6f70·656e·767a·222c·2022·706f··",·"openvz",·"po 
000a3700:·646d·616e·222c·2022·636f·6e74·6169·6e65··dman",·"containe000a3690:·3a0a·2020·2d20·616e·7369·626c·655f·7669··:.··-·ansible_vi
 000a36a0:·7274·7561·6c69·7a61·7469·6f6e·5f74·7970··rtualization_typ
 000a36b0:·6520·6e6f·7420·696e·205b·2264·6f63·6b65··e·not·in·["docke
 000a36c0:·7222·2c20·226c·7863·222c·2022·6f70·656e··r",·"lxc",·"open
 000a36d0:·767a·222c·2022·706f·646d·616e·222c·2022··vz",·"podman",·"
 000a36e0:·636f·6e74·6169·6e65·7222·5d0a·2020·2d20··container"].··-·
 000a36f0:·2722·6175·6469·7422·2069·6e20·616e·7369··'"audit"·in·ansi
 000a3700:·626c·655f·6661·6374·732e·7061·636b·6167··ble_facts.packag
000a3710:·7222·5d0a·2020·2d20·616e·7369·626c·655f··r"].··-·ansible_000a3710:·6573·270a·2020·2d20·616e·7369·626c·655f··es'.··-·ansible_
000a3720:·6172·6368·6974·6563·7475·7265·203d·3d20··architecture·==·000a3720:·6172·6368·6974·6563·7475·7265·203d·3d20··architecture·==·
000a3730:·2261·6172·6368·3634·2220·6f72·2061·6e73··"aarch64"·or·ans000a3730:·2261·6172·6368·3634·2220·6f72·2061·6e73··"aarch64"·or·ans
000a3740:·6962·6c65·5f61·7263·6869·7465·6374·7572··ible_architectur000a3740:·6962·6c65·5f61·7263·6869·7465·6374·7572··ible_architectur
000a3750:·6520·3d3d·2022·7070·6336·3422·206f·7220··e·==·"ppc64"·or·000a3750:·6520·3d3d·2022·7070·6336·3422·206f·7220··e·==·"ppc64"·or·
000a3760:·616e·7369·626c·655f·6172·6368·6974·6563··ansible_architec000a3760:·616e·7369·626c·655f·6172·6368·6974·6563··ansible_architec
000a3770:·7475·7265·0a20·2020·203d·3d20·2270·7063··ture.····==·"ppc000a3770:·7475·7265·0a20·2020·203d·3d20·2270·7063··ture.····==·"ppc
000a3780:·3634·6c65·2220·6f72·2061·6e73·6962·6c65··64le"·or·ansible000a3780:·3634·6c65·2220·6f72·2061·6e73·6962·6c65··64le"·or·ansible
Offset 42150, 23 lines modifiedOffset 42150, 23 lines modified
000a4a50:·6579·3d70·6572·6d5f·6d6f·640a·2020·2020··ey=perm_mod.····000a4a50:·6579·3d70·6572·6d5f·6d6f·640a·2020·2020··ey=perm_mod.····
000a4a60:·2020·6372·6561·7465·3a20·7472·7565·0a20····create:·true.·000a4a60:·2020·6372·6561·7465·3a20·7472·7565·0a20····create:·true.·
000a4a70:·2020·2020·206d·6f64·653a·206f·2d72·7778·······mode:·o-rwx000a4a70:·2020·2020·206d·6f64·653a·206f·2d72·7778·······mode:·o-rwx
000a4a80:·0a20·2020·2020·2073·7461·7465·3a20·7072··.······state:·pr000a4a80:·0a20·2020·2020·2073·7461·7465·3a20·7072··.······state:·pr
000a4a90:·6573·656e·740a·2020·2020·7768·656e·3a20··esent.····when:·000a4a90:·6573·656e·740a·2020·2020·7768·656e·3a20··esent.····when:·
000a4aa0:·7379·7363·616c·6c73·5f66·6f75·6e64·207c··syscalls_found·|000a4aa0:·7379·7363·616c·6c73·5f66·6f75·6e64·207c··syscalls_found·|
000a4ab0:·206c·656e·6774·6820·3d3d·2030·0a20·2077···length·==·0.··w000a4ab0:·206c·656e·6774·6820·3d3d·2030·0a20·2077···length·==·0.··w
000a4ac0:·6865·6e3a·0a20·202d·2027·2261·7564·6974··hen:.··-·'"audit000a4ac0:·6865·6e3a·0a20·202d·2061·6e73·6962·6c65··hen:.··-·ansible
000a4ad0:·2220·696e·2061·6e73·6962·6c65·5f66·6163··"·in·ansible_fac 
000a4ae0:·7473·2e70·6163·6b61·6765·7327·0a20·202d··ts.packages'.··- 
000a4af0:·2061·6e73·6962·6c65·5f76·6972·7475·616c···ansible_virtual 
000a4b00:·697a·6174·696f·6e5f·7479·7065·206e·6f74··ization_type·not 
000a4b10:·2069·6e20·5b22·646f·636b·6572·222c·2022···in·["docker",·" 
000a4b20:·6c78·6322·2c20·226f·7065·6e76·7a22·2c20··lxc",·"openvz",· 
000a4b30:·2270·6f64·6d61·6e22·2c20·2263·6f6e·7461··"podman",·"conta000a4ad0:·5f76·6972·7475·616c·697a·6174·696f·6e5f··_virtualization_
 000a4ae0:·7479·7065·206e·6f74·2069·6e20·5b22·646f··type·not·in·["do
 000a4af0:·636b·6572·222c·2022·6c78·6322·2c20·226f··cker",·"lxc",·"o
 000a4b00:·7065·6e76·7a22·2c20·2270·6f64·6d61·6e22··penvz",·"podman"
 000a4b10:·2c20·2263·6f6e·7461·696e·6572·225d·0a20··,·"container"].·
 000a4b20:·202d·2027·2261·7564·6974·2220·696e·2061···-·'"audit"·in·a
 000a4b30:·6e73·6962·6c65·5f66·6163·7473·2e70·6163··nsible_facts.pac
000a4b40:·696e·6572·225d·0a20·2074·6167·733a·0a20··iner"].··tags:.·000a4b40:·6b61·6765·7327·0a20·2074·6167·733a·0a20··kages'.··tags:.·
000a4b50:·202d·2043·4a49·532d·352e·342e·312e·310a···-·CJIS-5.4.1.1.000a4b50:·202d·2043·4a49·532d·352e·342e·312e·310a···-·CJIS-5.4.1.1.
000a4b60:·2020·2d20·4449·5341·2d53·5449·472d·5248····-·DISA-STIG-RH000a4b60:·2020·2d20·4449·5341·2d53·5449·472d·5248····-·DISA-STIG-RH
000a4b70:·454c·2d30·382d·3033·3034·3930·0a20·202d··EL-08-030490.··-000a4b70:·454c·2d30·382d·3033·3034·3930·0a20·202d··EL-08-030490.··-
000a4b80:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.000a4b80:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.
000a4b90:·312e·370a·2020·2d20·4e49·5354·2d38·3030··1.7.··-·NIST-800000a4b90:·312e·370a·2020·2d20·4e49·5354·2d38·3030··1.7.··-·NIST-800
000a4ba0:·2d35·332d·4155·2d31·3228·6329·0a20·202d··-53-AU-12(c).··-000a4ba0:·2d35·332d·4155·2d31·3228·6329·0a20·202d··-53-AU-12(c).··-
000a4bb0:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-000a4bb0:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-
Offset 42462, 22 lines modifiedOffset 42462, 22 lines modified
000a5dd0:·6d5f·6d6f·640a·2020·2020·2020·6372·6561··m_mod.······crea000a5dd0:·6d5f·6d6f·640a·2020·2020·2020·6372·6561··m_mod.······crea
000a5de0:·7465·3a20·7472·7565·0a20·2020·2020·206d··te:·true.······m000a5de0:·7465·3a20·7472·7565·0a20·2020·2020·206d··te:·true.······m
000a5df0:·6f64·653a·206f·2d72·7778·0a20·2020·2020··ode:·o-rwx.·····000a5df0:·6f64·653a·206f·2d72·7778·0a20·2020·2020··ode:·o-rwx.·····
000a5e00:·2073·7461·7465·3a20·7072·6573·656e·740a···state:·present.000a5e00:·2073·7461·7465·3a20·7072·6573·656e·740a···state:·present.
000a5e10:·2020·2020·7768·656e·3a20·7379·7363·616c······when:·syscal000a5e10:·2020·2020·7768·656e·3a20·7379·7363·616c······when:·syscal
000a5e20:·6c73·5f66·6f75·6e64·207c·206c·656e·6774··ls_found·|·lengt000a5e20:·6c73·5f66·6f75·6e64·207c·206c·656e·6774··ls_found·|·lengt
000a5e30:·6820·3d3d·2030·0a20·2077·6865·6e3a·0a20··h·==·0.··when:.·000a5e30:·6820·3d3d·2030·0a20·2077·6865·6e3a·0a20··h·==·0.··when:.·
000a5e40:·202d·2027·2261·7564·6974·2220·696e·2061···-·'"audit"·in·a 
000a5e50:·6e73·6962·6c65·5f66·6163·7473·2e70·6163··nsible_facts.pac 
000a5e60:·6b61·6765·7327·0a20·202d·2061·6e73·6962··kages'.··-·ansib 
000a5e70:·6c65·5f76·6972·7475·616c·697a·6174·696f··le_virtualizatio 
000a5e80:·6e5f·7479·7065·206e·6f74·2069·6e20·5b22··n_type·not·in·[" 
000a5e90:·646f·636b·6572·222c·2022·6c78·6322·2c20··docker",·"lxc",· 
000a5ea0:·226f·7065·6e76·7a22·2c20·2270·6f64·6d61··"openvz",·"podma 
000a5eb0:·6e22·2c20·2263·6f6e·7461·696e·6572·225d··n",·"container"]000a5e40:·202d·2061·6e73·6962·6c65·5f76·6972·7475···-·ansible_virtu
 000a5e50:·616c·697a·6174·696f·6e5f·7479·7065·206e··alization_type·n
 000a5e60:·6f74·2069·6e20·5b22·646f·636b·6572·222c··ot·in·["docker",
 000a5e70:·2022·6c78·6322·2c20·226f·7065·6e76·7a22···"lxc",·"openvz"
 000a5e80:·2c20·2270·6f64·6d61·6e22·2c20·2263·6f6e··,·"podman",·"con
 000a5e90:·7461·696e·6572·225d·0a20·202d·2027·2261··tainer"].··-·'"a
 000a5ea0:·7564·6974·2220·696e·2061·6e73·6962·6c65··udit"·in·ansible
 000a5eb0:·5f66·6163·7473·2e70·6163·6b61·6765·7327··_facts.packages'
000a5ec0:·0a20·202d·2061·7564·6974·5f61·7263·6820··.··-·audit_arch·000a5ec0:·0a20·202d·2061·7564·6974·5f61·7263·6820··.··-·audit_arch·
000a5ed0:·3d3d·2022·6236·3422·0a20·2074·6167·733a··==·"b64".··tags:000a5ed0:·3d3d·2022·6236·3422·0a20·2074·6167·733a··==·"b64".··tags:
000a5ee0:·0a20·202d·2043·4a49·532d·352e·342e·312e··.··-·CJIS-5.4.1.000a5ee0:·0a20·202d·2043·4a49·532d·352e·342e·312e··.··-·CJIS-5.4.1.
000a5ef0:·310a·2020·2d20·4449·5341·2d53·5449·472d··1.··-·DISA-STIG-000a5ef0:·310a·2020·2d20·4449·5341·2d53·5449·472d··1.··-·DISA-STIG-
000a5f00:·5248·454c·2d30·382d·3033·3034·3930·0a20··RHEL-08-030490.·000a5f00:·5248·454c·2d30·382d·3033·3034·3930·0a20··RHEL-08-030490.·
000a5f10:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-000a5f10:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-
000a5f20:·332e·312e·370a·2020·2d20·4e49·5354·2d38··3.1.7.··-·NIST-8000a5f20:·332e·312e·370a·2020·2d20·4e49·5354·2d38··3.1.7.··-·NIST-8
Offset 42511, 21 lines modifiedOffset 42511, 21 lines modified
000a60e0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla000a60e0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
000a60f0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap000a60f0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
000a6100:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=000a6100:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
000a6110:·2269·646d·3235·3339·3022·3e3c·7072·653e··"idm25390"><pre>000a6110:·2269·646d·3235·3339·3022·3e3c·7072·653e··"idm25390"><pre>
000a6120:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat000a6120:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat
000a6130:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl000a6130:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl
000a6140:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai000a6140:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai
000a6150:·6e20·706c·6174·666f·726d·730a·6966·2072··n·platforms.if·r000a6150:·6e20·706c·6174·666f·726d·730a·6966·205b··n·platforms.if·[
000a6160:·706d·202d·2d71·7569·6574·202d·7120·6175··pm·--quiet·-q·au 
000a6170:·6469·7420·2661·6d70·3b26·616d·703b·205b··dit·&amp;&amp;·[ 
000a6180:·2021·202d·6620·2f2e·646f·636b·6572·656e···!·-f·/.dockeren000a6160:·2021·202d·6620·2f2e·646f·636b·6572·656e···!·-f·/.dockeren
000a6190:·7620·5d20·2661·6d70·3b26·616d·703b·205b··v·]·&amp;&amp;·[000a6170:·7620·5d20·2661·6d70·3b26·616d·703b·205b··v·]·&amp;&amp;·[
000a61a0:·2021·202d·6620·2f72·756e·2f2e·636f·6e74···!·-f·/run/.cont000a6180:·2021·202d·6620·2f72·756e·2f2e·636f·6e74···!·-f·/run/.cont
000a61b0:·6169·6e65·7265·6e76·205d·3b20·7468·656e··ainerenv·];·then000a6190:·6169·6e65·7265·6e76·205d·2026·616d·703b··ainerenv·]·&amp;
 000a61a0:·2661·6d70·3b20·7270·6d20·2d2d·7175·6965··&amp;·rpm·--quie
 000a61b0:·7420·2d71·2061·7564·6974·3b20·7468·656e··t·-q·audit;·then
000a61c0:·0a0a·2320·4669·7273·7420·7065·7266·6f72··..#·First·perfor000a61c0:·0a0a·2320·4669·7273·7420·7065·7266·6f72··..#·First·perfor
000a61d0:·6d20·7468·6520·7265·6d65·6469·6174·696f··m·the·remediatio000a61d0:·6d20·7468·6520·7265·6d65·6469·6174·696f··m·the·remediatio
000a61e0:·6e20·6f66·2074·6865·2073·7973·6361·6c6c··n·of·the·syscall000a61e0:·6e20·6f66·2074·6865·2073·7973·6361·6c6c··n·of·the·syscall
000a61f0:·2072·756c·650a·2320·5265·7472·6965·7665···rule.#·Retrieve000a61f0:·2072·756c·650a·2320·5265·7472·6965·7665···rule.#·Retrieve
Max diff block lines reached; 407127/416641 bytes (97.72%) of diff not shown.
126 KB
html2text {}
    
Offset 69, 15 lines modifiedOffset 69, 15 lines modified
69 ····*·cpe:/o:redhat:enterprise_linux:8.769 ····*·cpe:/o:redhat:enterprise_linux:8.7
70 ····*·cpe:/o:redhat:enterprise_linux:8.870 ····*·cpe:/o:redhat:enterprise_linux:8.8
71 ····*·cpe:/o:redhat:enterprise_linux:8.971 ····*·cpe:/o:redhat:enterprise_linux:8.9
72 ····*·cpe:/o:redhat:enterprise_linux:872 ····*·cpe:/o:redhat:enterprise_linux:8
73 ····*·cpe:/o:centos:centos:873 ····*·cpe:/o:centos:centos:8
74 *****·Revision·History·*****74 *****·Revision·History·*****
75 Current·version:·0.1.6575 Current·version:·0.1.65
76 ····*·draft·(as·of·2024-01-14)76 ····*·draft·(as·of·2025-02-15)
77 *****·Table·of·Contents·*****77 *****·Table·of·Contents·*****
78 ···1.·System_Settings78 ···1.·System_Settings
79 ·········1.·Installing_and_Maintaining_Software79 ·········1.·Installing_and_Maintaining_Software
80 ·········2.·Account_and_Access_Control80 ·········2.·Account_and_Access_Control
81 ·········3.·System_Accounting_with_auditd81 ·········3.·System_Accounting_with_auditd
82 ·········4.·GRUB2_bootloader_configuration82 ·········4.·GRUB2_bootloader_configuration
83 ·········5.·Network_Configuration_and_Firewalls83 ·········5.·Network_Configuration_and_Firewalls
Offset 4422, 16 lines modifiedOffset 4422, 16 lines modified
4422 ··-·reboot_required4422 ··-·reboot_required
4423 ··-·restrict_strategy4423 ··-·restrict_strategy
  
4424 -·name:·Set·architecture·for·audit·chmod·tasks4424 -·name:·Set·architecture·for·audit·chmod·tasks
4425 ··set_fact:4425 ··set_fact:
4426 ····audit_arch:·b644426 ····audit_arch:·b64
4427 ··when:4427 ··when:
4428 ··-·'"audit"·in·ansible_facts.packages' 
4429 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4428 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4429 ··-·'"audit"·in·ansible_facts.packages'
4430 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture4430 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
4431 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"4431 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
4432 ··tags:4432 ··tags:
4433 ··-·CJIS-5.4.1.14433 ··-·CJIS-5.4.1.1
4434 ··-·DISA-STIG-RHEL-08-0304904434 ··-·DISA-STIG-RHEL-08-030490
4435 ··-·NIST-800-171-3.1.74435 ··-·NIST-800-171-3.1.7
4436 ··-·NIST-800-53-AU-12(c)4436 ··-·NIST-800-53-AU-12(c)
Offset 4568, 16 lines modifiedOffset 4568, 16 lines modified
4568 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10004568 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
4569 ········-F·auid!=unset·-F·key=perm_mod4569 ········-F·auid!=unset·-F·key=perm_mod
4570 ······create:·true4570 ······create:·true
4571 ······mode:·o-rwx4571 ······mode:·o-rwx
4572 ······state:·present4572 ······state:·present
4573 ····when:·syscalls_found·|·length·==·04573 ····when:·syscalls_found·|·length·==·0
4574 ··when:4574 ··when:
4575 ··-·'"audit"·in·ansible_facts.packages' 
4576 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4575 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4576 ··-·'"audit"·in·ansible_facts.packages'
4577 ··tags:4577 ··tags:
4578 ··-·CJIS-5.4.1.14578 ··-·CJIS-5.4.1.1
4579 ··-·DISA-STIG-RHEL-08-0304904579 ··-·DISA-STIG-RHEL-08-030490
4580 ··-·NIST-800-171-3.1.74580 ··-·NIST-800-171-3.1.7
4581 ··-·NIST-800-53-AU-12(c)4581 ··-·NIST-800-53-AU-12(c)
4582 ··-·NIST-800-53-AU-2(d)4582 ··-·NIST-800-53-AU-2(d)
4583 ··-·NIST-800-53-CM-6(a)4583 ··-·NIST-800-53-CM-6(a)
Offset 4712, 16 lines modifiedOffset 4712, 16 lines modified
4712 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10004712 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
4713 ········-F·auid!=unset·-F·key=perm_mod4713 ········-F·auid!=unset·-F·key=perm_mod
4714 ······create:·true4714 ······create:·true
4715 ······mode:·o-rwx4715 ······mode:·o-rwx
4716 ······state:·present4716 ······state:·present
4717 ····when:·syscalls_found·|·length·==·04717 ····when:·syscalls_found·|·length·==·0
4718 ··when:4718 ··when:
4719 ··-·'"audit"·in·ansible_facts.packages' 
4720 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4719 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4720 ··-·'"audit"·in·ansible_facts.packages'
4721 ··-·audit_arch·==·"b64"4721 ··-·audit_arch·==·"b64"
4722 ··tags:4722 ··tags:
4723 ··-·CJIS-5.4.1.14723 ··-·CJIS-5.4.1.1
4724 ··-·DISA-STIG-RHEL-08-0304904724 ··-·DISA-STIG-RHEL-08-030490
4725 ··-·NIST-800-171-3.1.74725 ··-·NIST-800-171-3.1.7
4726 ··-·NIST-800-53-AU-12(c)4726 ··-·NIST-800-53-AU-12(c)
4727 ··-·NIST-800-53-AU-2(d)4727 ··-·NIST-800-53-AU-2(d)
Offset 4731, 15 lines modifiedOffset 4731, 15 lines modified
4731 ··-·low_complexity4731 ··-·low_complexity
4732 ··-·low_disruption4732 ··-·low_disruption
4733 ··-·medium_severity4733 ··-·medium_severity
4734 ··-·reboot_required4734 ··-·reboot_required
4735 ··-·restrict_strategy4735 ··-·restrict_strategy
4736 Remediation_Shell_script_⇲4736 Remediation_Shell_script_⇲
4737 #·Remediation·is·applicable·only·in·certain·platforms4737 #·Remediation·is·applicable·only·in·certain·platforms
4738 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then4738 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
4739 #·First·perform·the·remediation·of·the·syscall·rule4739 #·First·perform·the·remediation·of·the·syscall·rule
4740 #·Retrieve·hardware·architecture·of·the·underlying·system4740 #·Retrieve·hardware·architecture·of·the·underlying·system
4741 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")4741 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
4742 for·ARCH·in·"${RULE_ARCHS[@]}"4742 for·ARCH·in·"${RULE_ARCHS[@]}"
4743 do4743 do
Offset 5100, 16 lines modifiedOffset 5100, 16 lines modified
5100 ··-·reboot_required5100 ··-·reboot_required
5101 ··-·restrict_strategy5101 ··-·restrict_strategy
  
5102 -·name:·Set·architecture·for·audit·chown·tasks5102 -·name:·Set·architecture·for·audit·chown·tasks
5103 ··set_fact:5103 ··set_fact:
5104 ····audit_arch:·b645104 ····audit_arch:·b64
5105 ··when:5105 ··when:
5106 ··-·'"audit"·in·ansible_facts.packages' 
5107 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5106 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5107 ··-·'"audit"·in·ansible_facts.packages'
5108 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture5108 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
5109 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"5109 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
5110 ··tags:5110 ··tags:
5111 ··-·CJIS-5.4.1.15111 ··-·CJIS-5.4.1.1
5112 ··-·DISA-STIG-RHEL-08-0304805112 ··-·DISA-STIG-RHEL-08-030480
5113 ··-·NIST-800-171-3.1.75113 ··-·NIST-800-171-3.1.7
5114 ··-·NIST-800-53-AU-12(c)5114 ··-·NIST-800-53-AU-12(c)
Offset 5248, 16 lines modifiedOffset 5248, 16 lines modified
5248 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10005248 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
5249 ········-F·auid!=unset·-F·key=perm_mod5249 ········-F·auid!=unset·-F·key=perm_mod
5250 ······create:·true5250 ······create:·true
5251 ······mode:·o-rwx5251 ······mode:·o-rwx
5252 ······state:·present5252 ······state:·present
5253 ····when:·syscalls_found·|·length·==·05253 ····when:·syscalls_found·|·length·==·0
5254 ··when:5254 ··when:
5255 ··-·'"audit"·in·ansible_facts.packages' 
5256 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5255 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5256 ··-·'"audit"·in·ansible_facts.packages'
5257 ··tags:5257 ··tags:
5258 ··-·CJIS-5.4.1.15258 ··-·CJIS-5.4.1.1
5259 ··-·DISA-STIG-RHEL-08-0304805259 ··-·DISA-STIG-RHEL-08-030480
5260 ··-·NIST-800-171-3.1.75260 ··-·NIST-800-171-3.1.7
5261 ··-·NIST-800-53-AU-12(c)5261 ··-·NIST-800-53-AU-12(c)
5262 ··-·NIST-800-53-AU-2(d)5262 ··-·NIST-800-53-AU-2(d)
5263 ··-·NIST-800-53-CM-6(a)5263 ··-·NIST-800-53-CM-6(a)
Offset 5394, 16 lines modifiedOffset 5394, 16 lines modified
5394 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10005394 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
5395 ········-F·auid!=unset·-F·key=perm_mod5395 ········-F·auid!=unset·-F·key=perm_mod
5396 ······create:·true5396 ······create:·true
5397 ······mode:·o-rwx5397 ······mode:·o-rwx
5398 ······state:·present5398 ······state:·present
Max diff block lines reached; 124518/129021 bytes (96.51%) of diff not shown.
32.1 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-cui.html
    
Offset 14581, 16 lines modifiedOffset 14581, 16 lines modified
00038f40:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h00038f40:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h
00038f50:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver00038f50:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver
00038f60:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.00038f60:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.
00038f70:·312e·3635·3c2f·7374·726f·6e67·3e3c·2f70··1.65</strong></p00038f70:·312e·3635·3c2f·7374·726f·6e67·3e3c·2f70··1.65</strong></p
00038f80:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong00038f80:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong
00038f90:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.00038f90:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.
00038fa0:·2020·2020·2020·2020·2020·2020·2020·2020··················00038fa0:·2020·2020·2020·2020·2020·2020·2020·2020··················
00038fb0:·2020·2020·2861·7320·6f66·2032·3032·342d······(as·of·2024-00038fb0:·2020·2020·2861·7320·6f66·2032·3032·352d······(as·of·2025-
00038fc0:·3031·2d31·3429·0a20·2020·2020·2020·2020··01-14).·········00038fc0:·3032·2d31·3529·0a20·2020·2020·2020·2020··02-15).·········
00038fd0:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul00038fd0:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul
00038fe0:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table00038fe0:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table
00038ff0:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h200038ff0:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h2
00039000:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href00039000:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href
00039010:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg00039010:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg
00039020:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_00039020:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_
00039030:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy00039030:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy
Offset 58501, 23 lines modifiedOffset 58501, 23 lines modified
000e4840:·6567·6578·703a·205e·5c73·2a66·6c75·7368··egexp:·^\s*flush000e4840:·6567·6578·703a·205e·5c73·2a66·6c75·7368··egexp:·^\s*flush
000e4850:·5c73·2a3d·5c73·2a2e·2a24·0a20·2020·206c··\s*=\s*.*$.····l000e4850:·5c73·2a3d·5c73·2a2e·2a24·0a20·2020·206c··\s*=\s*.*$.····l
000e4860:·696e·653a·2066·6c75·7368·203d·207b·7b20··ine:·flush·=·{{·000e4860:·696e·653a·2066·6c75·7368·203d·207b·7b20··ine:·flush·=·{{·
000e4870:·7661·725f·6175·6469·7464·5f66·6c75·7368··var_auditd_flush000e4870:·7661·725f·6175·6469·7464·5f66·6c75·7368··var_auditd_flush
000e4880:·207d·7d0a·2020·2020·7374·6174·653a·2070···}}.····state:·p000e4880:·207d·7d0a·2020·2020·7374·6174·653a·2070···}}.····state:·p
000e4890:·7265·7365·6e74·0a20·2020·2063·7265·6174··resent.····creat000e4890:·7265·7365·6e74·0a20·2020·2063·7265·6174··resent.····creat
000e48a0:·653a·2074·7275·650a·2020·7768·656e·3a0a··e:·true.··when:.000e48a0:·653a·2074·7275·650a·2020·7768·656e·3a0a··e:·true.··when:.
000e48b0:·2020·2d20·2722·6175·6469·7422·2069·6e20····-·'"audit"·in· 
000e48c0:·616e·7369·626c·655f·6661·6374·732e·7061··ansible_facts.pa 
000e48d0:·636b·6167·6573·270a·2020·2d20·616e·7369··ckages'.··-·ansi 
000e48e0:·626c·655f·7669·7274·7561·6c69·7a61·7469··ble_virtualizati 
000e48f0:·6f6e·5f74·7970·6520·6e6f·7420·696e·205b··on_type·not·in·[ 
000e4900:·2264·6f63·6b65·7222·2c20·226c·7863·222c··"docker",·"lxc", 
000e4910:·2022·6f70·656e·767a·222c·2022·706f·646d···"openvz",·"podm 
000e4920:·616e·222c·2022·636f·6e74·6169·6e65·7222··an",·"container"000e48b0:·2020·2d20·616e·7369·626c·655f·7669·7274····-·ansible_virt
 000e48c0:·7561·6c69·7a61·7469·6f6e·5f74·7970·6520··ualization_type·
 000e48d0:·6e6f·7420·696e·205b·2264·6f63·6b65·7222··not·in·["docker"
 000e48e0:·2c20·226c·7863·222c·2022·6f70·656e·767a··,·"lxc",·"openvz
 000e48f0:·222c·2022·706f·646d·616e·222c·2022·636f··",·"podman",·"co
 000e4900:·6e74·6169·6e65·7222·5d0a·2020·2d20·2722··ntainer"].··-·'"
 000e4910:·6175·6469·7422·2069·6e20·616e·7369·626c··audit"·in·ansibl
 000e4920:·655f·6661·6374·732e·7061·636b·6167·6573··e_facts.packages
000e4930:·5d0a·2020·7461·6773·3a0a·2020·2d20·4e49··].··tags:.··-·NI000e4930:·270a·2020·7461·6773·3a0a·2020·2d20·4e49··'.··tags:.··-·NI
000e4940:·5354·2d38·3030·2d31·3731·2d33·2e33·2e31··ST-800-171-3.3.1000e4940:·5354·2d38·3030·2d31·3731·2d33·2e33·2e31··ST-800-171-3.3.1
000e4950:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53000e4950:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
000e4960:·2d41·552d·3131·0a20·202d·204e·4953·542d··-AU-11.··-·NIST-000e4960:·2d41·552d·3131·0a20·202d·204e·4953·542d··-AU-11.··-·NIST-
000e4970:·3830·302d·3533·2d43·4d2d·3628·6129·0a20··800-53-CM-6(a).·000e4970:·3830·302d·3533·2d43·4d2d·3628·6129·0a20··800-53-CM-6(a).·
000e4980:·202d·2061·7564·6974·645f·6461·7461·5f72···-·auditd_data_r000e4980:·202d·2061·7564·6974·645f·6461·7461·5f72···-·auditd_data_r
000e4990:·6574·656e·7469·6f6e·5f66·6c75·7368·0a20··etention_flush.·000e4990:·6574·656e·7469·6f6e·5f66·6c75·7368·0a20··etention_flush.·
000e49a0:·202d·206c·6f77·5f63·6f6d·706c·6578·6974···-·low_complexit000e49a0:·202d·206c·6f77·5f63·6f6d·706c·6578·6974···-·low_complexit
Offset 58543, 20 lines modifiedOffset 58543, 20 lines modified
000e4ae0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col000e4ae0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
000e4af0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·000e4af0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
000e4b00:·6964·3d22·6964·6d33·3832·3436·223e·3c70··id="idm38246"><p000e4b00:·6964·3d22·6964·6d33·3832·3436·223e·3c70··id="idm38246"><p
000e4b10:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed000e4b10:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed
000e4b20:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic000e4b20:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic
000e4b30:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer000e4b30:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer
000e4b40:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i000e4b40:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i
000e4b50:·6620·7270·6d20·2d2d·7175·6965·7420·2d71··f·rpm·--quiet·-q 
000e4b60:·2061·7564·6974·2026·616d·703b·2661·6d70···audit·&amp;&amp 
000e4b70:·3b20·5b20·2120·2d66·202f·2e64·6f63·6b65··;·[·!·-f·/.docke000e4b50:·6620·5b20·2120·2d66·202f·2e64·6f63·6b65··f·[·!·-f·/.docke
000e4b80:·7265·6e76·205d·2026·616d·703b·2661·6d70··renv·]·&amp;&amp000e4b60:·7265·6e76·205d·2026·616d·703b·2661·6d70··renv·]·&amp;&amp
000e4b90:·3b20·5b20·2120·2d66·202f·7275·6e2f·2e63··;·[·!·-f·/run/.c000e4b70:·3b20·5b20·2120·2d66·202f·7275·6e2f·2e63··;·[·!·-f·/run/.c
000e4ba0:·6f6e·7461·696e·6572·656e·7620·5d3b·2074··ontainerenv·];·t000e4b80:·6f6e·7461·696e·6572·656e·7620·5d20·2661··ontainerenv·]·&a
 000e4b90:·6d70·3b26·616d·703b·2072·706d·202d·2d71··mp;&amp;·rpm·--q
 000e4ba0:·7569·6574·202d·7120·6175·6469·743b·2074··uiet·-q·audit;·t
000e4bb0:·6865·6e0a·0a76·6172·5f61·7564·6974·645f··hen..var_auditd_000e4bb0:·6865·6e0a·0a76·6172·5f61·7564·6974·645f··hen..var_auditd_
000e4bc0:·666c·7573·683d·273c·6162·6272·2074·6974··flush='<abbr·tit000e4bc0:·666c·7573·683d·273c·6162·6272·2074·6974··flush='<abbr·tit
000e4bd0:·6c65·3d22·6672·6f6d·2050·726f·6669·6c65··le="from·Profile000e4bd0:·6c65·3d22·6672·6f6d·2050·726f·6669·6c65··le="from·Profile
000e4be0:·2f72·6566·696e·652d·7661·6c75·653a·2078··/refine-value:·x000e4be0:·2f72·6566·696e·652d·7661·6c75·653a·2078··/refine-value:·x
000e4bf0:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj000e4bf0:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj
000e4c00:·6563·742e·636f·6e74·656e·745f·7661·6c75··ect.content_valu000e4c00:·6563·742e·636f·6e74·656e·745f·7661·6c75··ect.content_valu
000e4c10:·655f·7661·725f·6175·6469·7464·5f66·6c75··e_var_auditd_flu000e4c10:·655f·7661·725f·6175·6469·7464·5f66·6c75··e_var_auditd_flu
Offset 59012, 23 lines modifiedOffset 59012, 23 lines modified
000e6830:·6175·6469·742f·6175·6469·7464·2e63·6f6e··audit/auditd.con000e6830:·6175·6469·742f·6175·6469·7464·2e63·6f6e··audit/auditd.con
000e6840:·660a·2020·2020·2020·6372·6561·7465·3a20··f.······create:·000e6840:·660a·2020·2020·2020·6372·6561·7465·3a20··f.······create:·
000e6850:·7472·7565·0a20·2020·2020·2072·6567·6578··true.······regex000e6850:·7472·7565·0a20·2020·2020·2072·6567·6578··true.······regex
000e6860:·703a·2028·3f69·295e·5c73·2a66·7265·715c··p:·(?i)^\s*freq\000e6860:·703a·2028·3f69·295e·5c73·2a66·7265·715c··p:·(?i)^\s*freq\
000e6870:·732a·3d5c·732a·0a20·2020·2020·206c·696e··s*=\s*.······lin000e6870:·732a·3d5c·732a·0a20·2020·2020·206c·696e··s*=\s*.······lin
000e6880:·653a·2066·7265·7120·3d20·3530·0a20·2020··e:·freq·=·50.···000e6880:·653a·2066·7265·7120·3d20·3530·0a20·2020··e:·freq·=·50.···
000e6890:·2020·2073·7461·7465·3a20·7072·6573·656e·····state:·presen000e6890:·2020·2073·7461·7465·3a20·7072·6573·656e·····state:·presen
000e68a0:·740a·2020·7768·656e·3a0a·2020·2d20·2722··t.··when:.··-·'"000e68a0:·740a·2020·7768·656e·3a0a·2020·2d20·616e··t.··when:.··-·an
000e68b0:·6175·6469·7422·2069·6e20·616e·7369·626c··audit"·in·ansibl 
000e68c0:·655f·6661·6374·732e·7061·636b·6167·6573··e_facts.packages 
000e68d0:·270a·2020·2d20·616e·7369·626c·655f·7669··'.··-·ansible_vi 
000e68e0:·7274·7561·6c69·7a61·7469·6f6e·5f74·7970··rtualization_typ 
000e68f0:·6520·6e6f·7420·696e·205b·2264·6f63·6b65··e·not·in·["docke 
000e6900:·7222·2c20·226c·7863·222c·2022·6f70·656e··r",·"lxc",·"open 
000e6910:·767a·222c·2022·706f·646d·616e·222c·2022··vz",·"podman",·" 
000e6920:·636f·6e74·6169·6e65·7222·5d0a·2020·7461··container"].··ta000e68b0:·7369·626c·655f·7669·7274·7561·6c69·7a61··sible_virtualiza
 000e68c0:·7469·6f6e·5f74·7970·6520·6e6f·7420·696e··tion_type·not·in
 000e68d0:·205b·2264·6f63·6b65·7222·2c20·226c·7863···["docker",·"lxc
 000e68e0:·222c·2022·6f70·656e·767a·222c·2022·706f··",·"openvz",·"po
 000e68f0:·646d·616e·222c·2022·636f·6e74·6169·6e65··dman",·"containe
 000e6900:·7222·5d0a·2020·2d20·2722·6175·6469·7422··r"].··-·'"audit"
 000e6910:·2069·6e20·616e·7369·626c·655f·6661·6374···in·ansible_fact
 000e6920:·732e·7061·636b·6167·6573·270a·2020·7461··s.packages'.··ta
000e6930:·6773·3a0a·2020·2d20·4e49·5354·2d38·3030··gs:.··-·NIST-800000e6930:·6773·3a0a·2020·2d20·4e49·5354·2d38·3030··gs:.··-·NIST-800
000e6940:·2d35·332d·434d·2d36·0a20·202d·2061·7564··-53-CM-6.··-·aud000e6940:·2d35·332d·434d·2d36·0a20·202d·2061·7564··-53-CM-6.··-·aud
000e6950:·6974·645f·6672·6571·0a20·202d·206c·6f77··itd_freq.··-·low000e6950:·6974·645f·6672·6571·0a20·202d·206c·6f77··itd_freq.··-·low
000e6960:·5f63·6f6d·706c·6578·6974·790a·2020·2d20··_complexity.··-·000e6960:·5f63·6f6d·706c·6578·6974·790a·2020·2d20··_complexity.··-·
000e6970:·6c6f·775f·6469·7372·7570·7469·6f6e·0a20··low_disruption.·000e6970:·6c6f·775f·6469·7372·7570·7469·6f6e·0a20··low_disruption.·
000e6980:·202d·206d·6564·6975·6d5f·7365·7665·7269···-·medium_severi000e6980:·202d·206d·6564·6975·6d5f·7365·7665·7269···-·medium_severi
000e6990:·7479·0a20·202d·206e·6f5f·7265·626f·6f74··ty.··-·no_reboot000e6990:·7479·0a20·202d·206e·6f5f·7265·626f·6f74··ty.··-·no_reboot
Offset 59063, 20 lines modifiedOffset 59063, 20 lines modified
000e6b60:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t000e6b60:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
000e6b70:·683e·3c74·643e·7265·7374·7269·6374·3c2f··h><td>restrict</000e6b70:·683e·3c74·643e·7265·7374·7269·6374·3c2f··h><td>restrict</
000e6b80:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>000e6b80:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
000e6b90:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem000e6b90:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem
000e6ba0:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl000e6ba0:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl
000e6bb0:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c000e6bb0:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c
000e6bc0:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms000e6bc0:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms
000e6bd0:·0a69·6620·7270·6d20·2d2d·7175·6965·7420··.if·rpm·--quiet· 
000e6be0:·2d71·2061·7564·6974·2026·616d·703b·2661··-q·audit·&amp;&a 
000e6bf0:·6d70·3b20·5b20·2120·2d66·202f·2e64·6f63··mp;·[·!·-f·/.doc000e6bd0:·0a69·6620·5b20·2120·2d66·202f·2e64·6f63··.if·[·!·-f·/.doc
000e6c00:·6b65·7265·6e76·205d·2026·616d·703b·2661··kerenv·]·&amp;&a000e6be0:·6b65·7265·6e76·205d·2026·616d·703b·2661··kerenv·]·&amp;&a
000e6c10:·6d70·3b20·5b20·2120·2d66·202f·7275·6e2f··mp;·[·!·-f·/run/000e6bf0:·6d70·3b20·5b20·2120·2d66·202f·7275·6e2f··mp;·[·!·-f·/run/
000e6c20:·2e63·6f6e·7461·696e·6572·656e·7620·5d3b··.containerenv·];000e6c00:·2e63·6f6e·7461·696e·6572·656e·7620·5d20··.containerenv·]·
 000e6c10:·2661·6d70·3b26·616d·703b·2072·706d·202d··&amp;&amp;·rpm·-
 000e6c20:·2d71·7569·6574·202d·7120·6175·6469·743b··-quiet·-q·audit;
000e6c30:·2074·6865·6e0a·0a69·6620·5b20·2d65·2022···then..if·[·-e·"000e6c30:·2074·6865·6e0a·0a69·6620·5b20·2d65·2022···then..if·[·-e·"
000e6c40:·2f65·7463·2f61·7564·6974·2f61·7564·6974··/etc/audit/audit000e6c40:·2f65·7463·2f61·7564·6974·2f61·7564·6974··/etc/audit/audit
000e6c50:·642e·636f·6e66·2220·5d20·3b20·7468·656e··d.conf"·]·;·then000e6c50:·642e·636f·6e66·2220·5d20·3b20·7468·656e··d.conf"·]·;·then
000e6c60:·0a20·2020·200a·2020·2020·4c43·5f41·4c4c··.····.····LC_ALL000e6c60:·0a20·2020·200a·2020·2020·4c43·5f41·4c4c··.····.····LC_ALL
000e6c70:·3d43·2073·6564·202d·6920·222f·5e5c·732a··=C·sed·-i·"/^\s*000e6c70:·3d43·2073·6564·202d·6920·222f·5e5c·732a··=C·sed·-i·"/^\s*
000e6c80:·6672·6571·5c73·2a3d·5c73·2a2f·4964·2220··freq\s*=\s*/Id"·000e6c80:·6672·6571·5c73·2a3d·5c73·2a2f·4964·2220··freq\s*=\s*/Id"·
000e6c90:·222f·6574·632f·6175·6469·742f·6175·6469··"/etc/audit/audi000e6c90:·222f·6574·632f·6175·6469·742f·6175·6469··"/etc/audit/audi
Offset 59486, 23 lines modifiedOffset 59486, 23 lines modified
000e85d0:·6174·653a·2074·7275·650a·2020·2020·2020··ate:·true.······000e85d0:·6174·653a·2074·7275·650a·2020·2020·2020··ate:·true.······
000e85e0:·7265·6765·7870·3a20·283f·6929·5e5c·732a··regexp:·(?i)^\s*000e85e0:·7265·6765·7870·3a20·283f·6929·5e5c·732a··regexp:·(?i)^\s*
Max diff block lines reached; 16328/25937 bytes (62.95%) of diff not shown.
6.64 KB
html2text {}
    
Offset 79, 15 lines modifiedOffset 79, 15 lines modified
79 ····*·cpe:/o:redhat:enterprise_linux:8.779 ····*·cpe:/o:redhat:enterprise_linux:8.7
80 ····*·cpe:/o:redhat:enterprise_linux:8.880 ····*·cpe:/o:redhat:enterprise_linux:8.8
81 ····*·cpe:/o:redhat:enterprise_linux:8.981 ····*·cpe:/o:redhat:enterprise_linux:8.9
82 ····*·cpe:/o:redhat:enterprise_linux:882 ····*·cpe:/o:redhat:enterprise_linux:8
83 ····*·cpe:/o:centos:centos:883 ····*·cpe:/o:centos:centos:8
84 *****·Revision·History·*****84 *****·Revision·History·*****
85 Current·version:·0.1.6585 Current·version:·0.1.65
86 ····*·draft·(as·of·2024-01-14)86 ····*·draft·(as·of·2025-02-15)
87 *****·Table·of·Contents·*****87 *****·Table·of·Contents·*****
88 ···1.·System_Settings88 ···1.·System_Settings
89 ·········1.·Installing_and_Maintaining_Software89 ·········1.·Installing_and_Maintaining_Software
90 ·········2.·Account_and_Access_Control90 ·········2.·Account_and_Access_Control
91 ·········3.·System_Accounting_with_auditd91 ·········3.·System_Accounting_with_auditd
92 ·········4.·GRUB2_bootloader_configuration92 ·········4.·GRUB2_bootloader_configuration
93 ·········5.·zIPL_bootloader_configuration93 ·········5.·zIPL_bootloader_configuration
Offset 7769, 29 lines modifiedOffset 7769, 29 lines modified
7769 ··lineinfile:7769 ··lineinfile:
7770 ····dest:·/etc/audit/auditd.conf7770 ····dest:·/etc/audit/auditd.conf
7771 ····regexp:·^\s*flush\s*=\s*.*$7771 ····regexp:·^\s*flush\s*=\s*.*$
7772 ····line:·flush·=·{{·var_auditd_flush·}}7772 ····line:·flush·=·{{·var_auditd_flush·}}
7773 ····state:·present7773 ····state:·present
7774 ····create:·true7774 ····create:·true
7775 ··when:7775 ··when:
7776 ··-·'"audit"·in·ansible_facts.packages' 
7777 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]7776 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 7777 ··-·'"audit"·in·ansible_facts.packages'
7778 ··tags:7778 ··tags:
7779 ··-·NIST-800-171-3.3.17779 ··-·NIST-800-171-3.3.1
7780 ··-·NIST-800-53-AU-117780 ··-·NIST-800-53-AU-11
7781 ··-·NIST-800-53-CM-6(a)7781 ··-·NIST-800-53-CM-6(a)
7782 ··-·auditd_data_retention_flush7782 ··-·auditd_data_retention_flush
7783 ··-·low_complexity7783 ··-·low_complexity
7784 ··-·low_disruption7784 ··-·low_disruption
7785 ··-·medium_severity7785 ··-·medium_severity
7786 ··-·no_reboot_needed7786 ··-·no_reboot_needed
7787 ··-·restrict_strategy7787 ··-·restrict_strategy
7788 Remediation_Shell_script_⇲7788 Remediation_Shell_script_⇲
7789 #·Remediation·is·applicable·only·in·certain·platforms7789 #·Remediation·is·applicable·only·in·certain·platforms
7790 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then7790 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
7791 var_auditd_flush='incremental_async'7791 var_auditd_flush='incremental_async'
  
  
7792 AUDITCONFIG=/etc/audit/auditd.conf7792 AUDITCONFIG=/etc/audit/auditd.conf
  
7793 #·if·flush·is·present,·flush·param·edited·to·var_auditd_flush7793 #·if·flush·is·present,·flush·param·edited·to·var_auditd_flush
Offset 7888, 30 lines modifiedOffset 7888, 30 lines modified
7888 ····lineinfile:7888 ····lineinfile:
7889 ······path:·/etc/audit/auditd.conf7889 ······path:·/etc/audit/auditd.conf
7890 ······create:·true7890 ······create:·true
7891 ······regexp:·(?i)^\s*freq\s*=\s*7891 ······regexp:·(?i)^\s*freq\s*=\s*
7892 ······line:·freq·=·507892 ······line:·freq·=·50
7893 ······state:·present7893 ······state:·present
7894 ··when:7894 ··when:
7895 ··-·'"audit"·in·ansible_facts.packages' 
7896 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]7895 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 7896 ··-·'"audit"·in·ansible_facts.packages'
7897 ··tags:7897 ··tags:
7898 ··-·NIST-800-53-CM-67898 ··-·NIST-800-53-CM-6
7899 ··-·auditd_freq7899 ··-·auditd_freq
7900 ··-·low_complexity7900 ··-·low_complexity
7901 ··-·low_disruption7901 ··-·low_disruption
7902 ··-·medium_severity7902 ··-·medium_severity
7903 ··-·no_reboot_needed7903 ··-·no_reboot_needed
7904 ··-·restrict_strategy7904 ··-·restrict_strategy
7905 Remediation_Shell_script_⇲7905 Remediation_Shell_script_⇲
7906 Complexity:·low7906 Complexity:·low
7907 Disruption:·low7907 Disruption:·low
7908 Strategy:···restrict7908 Strategy:···restrict
7909 #·Remediation·is·applicable·only·in·certain·platforms7909 #·Remediation·is·applicable·only·in·certain·platforms
7910 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then7910 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
7911 if·[·-e·"/etc/audit/auditd.conf"·]·;·then7911 if·[·-e·"/etc/audit/auditd.conf"·]·;·then
  
7912 ····LC_ALL=C·sed·-i·"/^\s*freq\s*=\s*/Id"·"/etc/audit/auditd.conf"7912 ····LC_ALL=C·sed·-i·"/^\s*freq\s*=\s*/Id"·"/etc/audit/auditd.conf"
7913 else7913 else
7914 ····touch·"/etc/audit/auditd.conf"7914 ····touch·"/etc/audit/auditd.conf"
7915 fi7915 fi
Offset 7994, 31 lines modifiedOffset 7994, 31 lines modified
7994 ····lineinfile:7994 ····lineinfile:
7995 ······path:·/etc/audit/auditd.conf7995 ······path:·/etc/audit/auditd.conf
7996 ······create:·true7996 ······create:·true
7997 ······regexp:·(?i)^\s*local_events\s*=\s*7997 ······regexp:·(?i)^\s*local_events\s*=\s*
7998 ······line:·local_events·=·yes7998 ······line:·local_events·=·yes
7999 ······state:·present7999 ······state:·present
8000 ··when:8000 ··when:
8001 ··-·'"audit"·in·ansible_facts.packages' 
8002 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8001 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 8002 ··-·'"audit"·in·ansible_facts.packages'
8003 ··tags:8003 ··tags:
8004 ··-·DISA-STIG-RHEL-08-0300618004 ··-·DISA-STIG-RHEL-08-030061
8005 ··-·NIST-800-53-CM-68005 ··-·NIST-800-53-CM-6
8006 ··-·auditd_local_events8006 ··-·auditd_local_events
8007 ··-·low_complexity8007 ··-·low_complexity
8008 ··-·low_disruption8008 ··-·low_disruption
8009 ··-·medium_severity8009 ··-·medium_severity
8010 ··-·no_reboot_needed8010 ··-·no_reboot_needed
8011 ··-·restrict_strategy8011 ··-·restrict_strategy
8012 Remediation_Shell_script_⇲8012 Remediation_Shell_script_⇲
8013 Complexity:·low8013 Complexity:·low
8014 Disruption:·low8014 Disruption:·low
8015 Strategy:···restrict8015 Strategy:···restrict
8016 #·Remediation·is·applicable·only·in·certain·platforms8016 #·Remediation·is·applicable·only·in·certain·platforms
8017 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then8017 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
8018 if·[·-e·"/etc/audit/auditd.conf"·]·;·then8018 if·[·-e·"/etc/audit/auditd.conf"·]·;·then
  
8019 ····LC_ALL=C·sed·-i·"/^\s*local_events\s*=\s*/Id"·"/etc/audit/auditd.conf"8019 ····LC_ALL=C·sed·-i·"/^\s*local_events\s*=\s*/Id"·"/etc/audit/auditd.conf"
8020 else8020 else
8021 ····touch·"/etc/audit/auditd.conf"8021 ····touch·"/etc/audit/auditd.conf"
8022 fi8022 fi
Offset 8102, 16 lines modifiedOffset 8102, 16 lines modified
8102 ····lineinfile:8102 ····lineinfile:
8103 ······path:·/etc/audit/auditd.conf8103 ······path:·/etc/audit/auditd.conf
8104 ······create:·true8104 ······create:·true
8105 ······regexp:·(?i)^\s*log_format\s*=\s*8105 ······regexp:·(?i)^\s*log_format\s*=\s*
8106 ······line:·log_format·=·ENRICHED8106 ······line:·log_format·=·ENRICHED
8107 ······state:·present8107 ······state:·present
8108 ··when:8108 ··when:
8109 ··-·'"audit"·in·ansible_facts.packages' 
8110 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8109 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 8110 ··-·'"audit"·in·ansible_facts.packages'
8111 ··tags:8111 ··tags:
8112 ··-·DISA-STIG-RHEL-08-0300638112 ··-·DISA-STIG-RHEL-08-030063
8113 ··-·NIST-800-53-AU-38113 ··-·NIST-800-53-AU-3
8114 ··-·NIST-800-53-CM-68114 ··-·NIST-800-53-CM-6
8115 ··-·auditd_log_format8115 ··-·auditd_log_format
Max diff block lines reached; 2647/6779 bytes (39.05%) of diff not shown.
357 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-e8.html
    
Offset 14548, 15 lines modifiedOffset 14548, 15 lines modified
00038d30:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>00038d30:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>
00038d40:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:00038d40:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:
00038d50:·203c·7374·726f·6e67·3e30·2e31·2e36·353c···<strong>0.1.65<00038d50:·203c·7374·726f·6e67·3e30·2e31·2e36·353c···<strong>0.1.65<
00038d60:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>00038d60:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>
00038d70:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf00038d70:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf
00038d80:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····00038d80:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····
00038d90:·2020·2020·2020·2020·2020·2020·2020·2028·················(00038d90:·2020·2020·2020·2020·2020·2020·2020·2028·················(
00038da0:·6173·206f·6620·3230·3234·2d30·312d·3134··as·of·2024-01-1400038da0:·6173·206f·6620·3230·3235·2d30·322d·3135··as·of·2025-02-15
00038db0:·290a·2020·2020·2020·2020·2020·2020·2020··).··············00038db0:·290a·2020·2020·2020·2020·2020·2020·2020··).··············
00038dc0:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di00038dc0:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di
00038dd0:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C00038dd0:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C
00038de0:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>00038de0:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>
00038df0:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc00038df0:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc
00038e00:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje00038e00:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje
00038e10:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group00038e10:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group
Offset 29272, 23 lines modifiedOffset 29272, 23 lines modified
00072570:·6564·0a20·202d·2072·6573·7472·6963·745f··ed.··-·restrict_00072570:·6564·0a20·202d·2072·6573·7472·6963·745f··ed.··-·restrict_
00072580:·7374·7261·7465·6779·0a0a·2d20·6e61·6d65··strategy..-·name00072580:·7374·7261·7465·6779·0a0a·2d20·6e61·6d65··strategy..-·name
00072590:·3a20·5365·7420·6172·6368·6974·6563·7475··:·Set·architectu00072590:·3a20·5365·7420·6172·6368·6974·6563·7475··:·Set·architectu
000725a0:·7265·2066·6f72·2061·7564·6974·2063·686d··re·for·audit·chm000725a0:·7265·2066·6f72·2061·7564·6974·2063·686d··re·for·audit·chm
000725b0:·6f64·2074·6173·6b73·0a20·2073·6574·5f66··od·tasks.··set_f000725b0:·6f64·2074·6173·6b73·0a20·2073·6574·5f66··od·tasks.··set_f
000725c0:·6163·743a·0a20·2020·2061·7564·6974·5f61··act:.····audit_a000725c0:·6163·743a·0a20·2020·2061·7564·6974·5f61··act:.····audit_a
000725d0:·7263·683a·2062·3634·0a20·2077·6865·6e3a··rch:·b64.··when:000725d0:·7263·683a·2062·3634·0a20·2077·6865·6e3a··rch:·b64.··when:
000725e0:·0a20·202d·2027·2261·7564·6974·2220·696e··.··-·'"audit"·in 
000725f0:·2061·6e73·6962·6c65·5f66·6163·7473·2e70···ansible_facts.p 
00072600:·6163·6b61·6765·7327·0a20·202d·2061·6e73··ackages'.··-·ans 
00072610:·6962·6c65·5f76·6972·7475·616c·697a·6174··ible_virtualizat 
00072620:·696f·6e5f·7479·7065·206e·6f74·2069·6e20··ion_type·not·in· 
00072630:·5b22·646f·636b·6572·222c·2022·6c78·6322··["docker",·"lxc" 
00072640:·2c20·226f·7065·6e76·7a22·2c20·2270·6f64··,·"openvz",·"pod 
00072650:·6d61·6e22·2c20·2263·6f6e·7461·696e·6572··man",·"container000725e0:·0a20·202d·2061·6e73·6962·6c65·5f76·6972··.··-·ansible_vir
 000725f0:·7475·616c·697a·6174·696f·6e5f·7479·7065··tualization_type
 00072600:·206e·6f74·2069·6e20·5b22·646f·636b·6572···not·in·["docker
 00072610:·222c·2022·6c78·6322·2c20·226f·7065·6e76··",·"lxc",·"openv
 00072620:·7a22·2c20·2270·6f64·6d61·6e22·2c20·2263··z",·"podman",·"c
 00072630:·6f6e·7461·696e·6572·225d·0a20·202d·2027··ontainer"].··-·'
 00072640:·2261·7564·6974·2220·696e·2061·6e73·6962··"audit"·in·ansib
 00072650:·6c65·5f66·6163·7473·2e70·6163·6b61·6765··le_facts.package
00072660:·225d·0a20·202d·2061·6e73·6962·6c65·5f61··"].··-·ansible_a00072660:·7327·0a20·202d·2061·6e73·6962·6c65·5f61··s'.··-·ansible_a
00072670:·7263·6869·7465·6374·7572·6520·3d3d·2022··rchitecture·==·"00072670:·7263·6869·7465·6374·7572·6520·3d3d·2022··rchitecture·==·"
00072680:·6161·7263·6836·3422·206f·7220·616e·7369··aarch64"·or·ansi00072680:·6161·7263·6836·3422·206f·7220·616e·7369··aarch64"·or·ansi
00072690:·626c·655f·6172·6368·6974·6563·7475·7265··ble_architecture00072690:·626c·655f·6172·6368·6974·6563·7475·7265··ble_architecture
000726a0:·203d·3d20·2270·7063·3634·2220·6f72·2061···==·"ppc64"·or·a000726a0:·203d·3d20·2270·7063·3634·2220·6f72·2061···==·"ppc64"·or·a
000726b0:·6e73·6962·6c65·5f61·7263·6869·7465·6374··nsible_architect000726b0:·6e73·6962·6c65·5f61·7263·6869·7465·6374··nsible_architect
000726c0:·7572·650a·2020·2020·3d3d·2022·7070·6336··ure.····==·"ppc6000726c0:·7572·650a·2020·2020·3d3d·2022·7070·6336··ure.····==·"ppc6
000726d0:·346c·6522·206f·7220·616e·7369·626c·655f··4le"·or·ansible_000726d0:·346c·6522·206f·7220·616e·7369·626c·655f··4le"·or·ansible_
Offset 29595, 23 lines modifiedOffset 29595, 23 lines modified
000739a0:·793d·7065·726d·5f6d·6f64·0a20·2020·2020··y=perm_mod.·····000739a0:·793d·7065·726d·5f6d·6f64·0a20·2020·2020··y=perm_mod.·····
000739b0:·2063·7265·6174·653a·2074·7275·650a·2020···create:·true.··000739b0:·2063·7265·6174·653a·2074·7275·650a·2020···create:·true.··
000739c0:·2020·2020·6d6f·6465·3a20·6f2d·7277·780a······mode:·o-rwx.000739c0:·2020·2020·6d6f·6465·3a20·6f2d·7277·780a······mode:·o-rwx.
000739d0:·2020·2020·2020·7374·6174·653a·2070·7265········state:·pre000739d0:·2020·2020·2020·7374·6174·653a·2070·7265········state:·pre
000739e0:·7365·6e74·0a20·2020·2077·6865·6e3a·2073··sent.····when:·s000739e0:·7365·6e74·0a20·2020·2077·6865·6e3a·2073··sent.····when:·s
000739f0:·7973·6361·6c6c·735f·666f·756e·6420·7c20··yscalls_found·|·000739f0:·7973·6361·6c6c·735f·666f·756e·6420·7c20··yscalls_found·|·
00073a00:·6c65·6e67·7468·203d·3d20·300a·2020·7768··length·==·0.··wh00073a00:·6c65·6e67·7468·203d·3d20·300a·2020·7768··length·==·0.··wh
00073a10:·656e·3a0a·2020·2d20·2722·6175·6469·7422··en:.··-·'"audit" 
00073a20:·2069·6e20·616e·7369·626c·655f·6661·6374···in·ansible_fact 
00073a30:·732e·7061·636b·6167·6573·270a·2020·2d20··s.packages'.··-· 
00073a40:·616e·7369·626c·655f·7669·7274·7561·6c69··ansible_virtuali 
00073a50:·7a61·7469·6f6e·5f74·7970·6520·6e6f·7420··zation_type·not· 
00073a60:·696e·205b·2264·6f63·6b65·7222·2c20·226c··in·["docker",·"l 
00073a70:·7863·222c·2022·6f70·656e·767a·222c·2022··xc",·"openvz",·" 
00073a80:·706f·646d·616e·222c·2022·636f·6e74·6169··podman",·"contai00073a10:·656e·3a0a·2020·2d20·616e·7369·626c·655f··en:.··-·ansible_
 00073a20:·7669·7274·7561·6c69·7a61·7469·6f6e·5f74··virtualization_t
 00073a30:·7970·6520·6e6f·7420·696e·205b·2264·6f63··ype·not·in·["doc
 00073a40:·6b65·7222·2c20·226c·7863·222c·2022·6f70··ker",·"lxc",·"op
 00073a50:·656e·767a·222c·2022·706f·646d·616e·222c··envz",·"podman",
 00073a60:·2022·636f·6e74·6169·6e65·7222·5d0a·2020···"container"].··
 00073a70:·2d20·2722·6175·6469·7422·2069·6e20·616e··-·'"audit"·in·an
 00073a80:·7369·626c·655f·6661·6374·732e·7061·636b··sible_facts.pack
00073a90:·6e65·7222·5d0a·2020·7461·6773·3a0a·2020··ner"].··tags:.··00073a90:·6167·6573·270a·2020·7461·6773·3a0a·2020··ages'.··tags:.··
00073aa0:·2d20·434a·4953·2d35·2e34·2e31·2e31·0a20··-·CJIS-5.4.1.1.·00073aa0:·2d20·434a·4953·2d35·2e34·2e31·2e31·0a20··-·CJIS-5.4.1.1.·
00073ab0:·202d·2044·4953·412d·5354·4947·2d52·4845···-·DISA-STIG-RHE00073ab0:·202d·2044·4953·412d·5354·4947·2d52·4845···-·DISA-STIG-RHE
00073ac0:·4c2d·3038·2d30·3330·3439·300a·2020·2d20··L-08-030490.··-·00073ac0:·4c2d·3038·2d30·3330·3439·300a·2020·2d20··L-08-030490.··-·
00073ad0:·4e49·5354·2d38·3030·2d31·3731·2d33·2e31··NIST-800-171-3.100073ad0:·4e49·5354·2d38·3030·2d31·3731·2d33·2e31··NIST-800-171-3.1
00073ae0:·2e37·0a20·202d·204e·4953·542d·3830·302d··.7.··-·NIST-800-00073ae0:·2e37·0a20·202d·204e·4953·542d·3830·302d··.7.··-·NIST-800-
00073af0:·3533·2d41·552d·3132·2863·290a·2020·2d20··53-AU-12(c).··-·00073af0:·3533·2d41·552d·3132·2863·290a·2020·2d20··53-AU-12(c).··-·
00073b00:·4e49·5354·2d38·3030·2d35·332d·4155·2d32··NIST-800-53-AU-200073b00:·4e49·5354·2d38·3030·2d35·332d·4155·2d32··NIST-800-53-AU-2
Offset 29907, 22 lines modifiedOffset 29907, 22 lines modified
00074d20:·5f6d·6f64·0a20·2020·2020·2063·7265·6174··_mod.······creat00074d20:·5f6d·6f64·0a20·2020·2020·2063·7265·6174··_mod.······creat
00074d30:·653a·2074·7275·650a·2020·2020·2020·6d6f··e:·true.······mo00074d30:·653a·2074·7275·650a·2020·2020·2020·6d6f··e:·true.······mo
00074d40:·6465·3a20·6f2d·7277·780a·2020·2020·2020··de:·o-rwx.······00074d40:·6465·3a20·6f2d·7277·780a·2020·2020·2020··de:·o-rwx.······
00074d50:·7374·6174·653a·2070·7265·7365·6e74·0a20··state:·present.·00074d50:·7374·6174·653a·2070·7265·7365·6e74·0a20··state:·present.·
00074d60:·2020·2077·6865·6e3a·2073·7973·6361·6c6c·····when:·syscall00074d60:·2020·2077·6865·6e3a·2073·7973·6361·6c6c·····when:·syscall
00074d70:·735f·666f·756e·6420·7c20·6c65·6e67·7468··s_found·|·length00074d70:·735f·666f·756e·6420·7c20·6c65·6e67·7468··s_found·|·length
00074d80:·203d·3d20·300a·2020·7768·656e·3a0a·2020···==·0.··when:.··00074d80:·203d·3d20·300a·2020·7768·656e·3a0a·2020···==·0.··when:.··
00074d90:·2d20·2722·6175·6469·7422·2069·6e20·616e··-·'"audit"·in·an 
00074da0:·7369·626c·655f·6661·6374·732e·7061·636b··sible_facts.pack 
00074db0:·6167·6573·270a·2020·2d20·616e·7369·626c··ages'.··-·ansibl 
00074dc0:·655f·7669·7274·7561·6c69·7a61·7469·6f6e··e_virtualization 
00074dd0:·5f74·7970·6520·6e6f·7420·696e·205b·2264··_type·not·in·["d 
00074de0:·6f63·6b65·7222·2c20·226c·7863·222c·2022··ocker",·"lxc",·" 
00074df0:·6f70·656e·767a·222c·2022·706f·646d·616e··openvz",·"podman 
00074e00:·222c·2022·636f·6e74·6169·6e65·7222·5d0a··",·"container"].00074d90:·2d20·616e·7369·626c·655f·7669·7274·7561··-·ansible_virtua
 00074da0:·6c69·7a61·7469·6f6e·5f74·7970·6520·6e6f··lization_type·no
 00074db0:·7420·696e·205b·2264·6f63·6b65·7222·2c20··t·in·["docker",·
 00074dc0:·226c·7863·222c·2022·6f70·656e·767a·222c··"lxc",·"openvz",
 00074dd0:·2022·706f·646d·616e·222c·2022·636f·6e74···"podman",·"cont
 00074de0:·6169·6e65·7222·5d0a·2020·2d20·2722·6175··ainer"].··-·'"au
 00074df0:·6469·7422·2069·6e20·616e·7369·626c·655f··dit"·in·ansible_
 00074e00:·6661·6374·732e·7061·636b·6167·6573·270a··facts.packages'.
00074e10:·2020·2d20·6175·6469·745f·6172·6368·203d····-·audit_arch·=00074e10:·2020·2d20·6175·6469·745f·6172·6368·203d····-·audit_arch·=
00074e20:·3d20·2262·3634·220a·2020·7461·6773·3a0a··=·"b64".··tags:.00074e20:·3d20·2262·3634·220a·2020·7461·6773·3a0a··=·"b64".··tags:.
00074e30:·2020·2d20·434a·4953·2d35·2e34·2e31·2e31····-·CJIS-5.4.1.100074e30:·2020·2d20·434a·4953·2d35·2e34·2e31·2e31····-·CJIS-5.4.1.1
00074e40:·0a20·202d·2044·4953·412d·5354·4947·2d52··.··-·DISA-STIG-R00074e40:·0a20·202d·2044·4953·412d·5354·4947·2d52··.··-·DISA-STIG-R
00074e50:·4845·4c2d·3038·2d30·3330·3439·300a·2020··HEL-08-030490.··00074e50:·4845·4c2d·3038·2d30·3330·3439·300a·2020··HEL-08-030490.··
00074e60:·2d20·4e49·5354·2d38·3030·2d31·3731·2d33··-·NIST-800-171-300074e60:·2d20·4e49·5354·2d38·3030·2d31·3731·2d33··-·NIST-800-171-3
00074e70:·2e31·2e37·0a20·202d·204e·4953·542d·3830··.1.7.··-·NIST-8000074e70:·2e31·2e37·0a20·202d·204e·4953·542d·3830··.1.7.··-·NIST-80
Offset 29956, 21 lines modifiedOffset 29956, 21 lines modified
00075030:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas00075030:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
00075040:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps00075040:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
00075050:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="00075050:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
00075060:·6964·6d32·3533·3930·223e·3c70·7265·3e3c··idm25390"><pre><00075060:·6964·6d32·3533·3930·223e·3c70·7265·3e3c··idm25390"><pre><
00075070:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati00075070:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati
00075080:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable00075080:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable
00075090:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain00075090:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain
000750a0:·2070·6c61·7466·6f72·6d73·0a69·6620·7270···platforms.if·rp000750a0:·2070·6c61·7466·6f72·6d73·0a69·6620·5b20···platforms.if·[·
000750b0:·6d20·2d2d·7175·6965·7420·2d71·2061·7564··m·--quiet·-q·aud 
000750c0:·6974·2026·616d·703b·2661·6d70·3b20·5b20··it·&amp;&amp;·[· 
000750d0:·2120·2d66·202f·2e64·6f63·6b65·7265·6e76··!·-f·/.dockerenv000750b0:·2120·2d66·202f·2e64·6f63·6b65·7265·6e76··!·-f·/.dockerenv
000750e0:·205d·2026·616d·703b·2661·6d70·3b20·5b20···]·&amp;&amp;·[·000750c0:·205d·2026·616d·703b·2661·6d70·3b20·5b20···]·&amp;&amp;·[·
000750f0:·2120·2d66·202f·7275·6e2f·2e63·6f6e·7461··!·-f·/run/.conta000750d0:·2120·2d66·202f·7275·6e2f·2e63·6f6e·7461··!·-f·/run/.conta
00075100:·696e·6572·656e·7620·5d3b·2074·6865·6e0a··inerenv·];·then.000750e0:·696e·6572·656e·7620·5d20·2661·6d70·3b26··inerenv·]·&amp;&
 000750f0:·616d·703b·2072·706d·202d·2d71·7569·6574··amp;·rpm·--quiet
 00075100:·202d·7120·6175·6469·743b·2074·6865·6e0a···-q·audit;·then.
00075110:·0a23·2046·6972·7374·2070·6572·666f·726d··.#·First·perform00075110:·0a23·2046·6972·7374·2070·6572·666f·726d··.#·First·perform
00075120:·2074·6865·2072·656d·6564·6961·7469·6f6e···the·remediation00075120:·2074·6865·2072·656d·6564·6961·7469·6f6e···the·remediation
00075130:·206f·6620·7468·6520·7379·7363·616c·6c20···of·the·syscall·00075130:·206f·6620·7468·6520·7379·7363·616c·6c20···of·the·syscall·
Max diff block lines reached; 271091/280536 bytes (96.63%) of diff not shown.
83.0 KB
html2text {}
    
Offset 70, 15 lines modifiedOffset 70, 15 lines modified
70 ····*·cpe:/o:redhat:enterprise_linux:8.770 ····*·cpe:/o:redhat:enterprise_linux:8.7
71 ····*·cpe:/o:redhat:enterprise_linux:8.871 ····*·cpe:/o:redhat:enterprise_linux:8.8
72 ····*·cpe:/o:redhat:enterprise_linux:8.972 ····*·cpe:/o:redhat:enterprise_linux:8.9
73 ····*·cpe:/o:redhat:enterprise_linux:873 ····*·cpe:/o:redhat:enterprise_linux:8
74 ····*·cpe:/o:centos:centos:874 ····*·cpe:/o:centos:centos:8
75 *****·Revision·History·*****75 *****·Revision·History·*****
76 Current·version:·0.1.6576 Current·version:·0.1.65
77 ····*·draft·(as·of·2024-01-14)77 ····*·draft·(as·of·2025-02-15)
78 *****·Table·of·Contents·*****78 *****·Table·of·Contents·*****
79 ···1.·System_Settings79 ···1.·System_Settings
80 ·········1.·Installing_and_Maintaining_Software80 ·········1.·Installing_and_Maintaining_Software
81 ·········2.·Account_and_Access_Control81 ·········2.·Account_and_Access_Control
82 ·········3.·System_Accounting_with_auditd82 ·········3.·System_Accounting_with_auditd
83 ·········4.·Configure_Syslog83 ·········4.·Configure_Syslog
84 ·········5.·Network_Configuration_and_Firewalls84 ·········5.·Network_Configuration_and_Firewalls
Offset 1889, 16 lines modifiedOffset 1889, 16 lines modified
1889 ··-·reboot_required1889 ··-·reboot_required
1890 ··-·restrict_strategy1890 ··-·restrict_strategy
  
1891 -·name:·Set·architecture·for·audit·chmod·tasks1891 -·name:·Set·architecture·for·audit·chmod·tasks
1892 ··set_fact:1892 ··set_fact:
1893 ····audit_arch:·b641893 ····audit_arch:·b64
1894 ··when:1894 ··when:
1895 ··-·'"audit"·in·ansible_facts.packages' 
1896 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1895 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1896 ··-·'"audit"·in·ansible_facts.packages'
1897 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture1897 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
1898 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"1898 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
1899 ··tags:1899 ··tags:
1900 ··-·CJIS-5.4.1.11900 ··-·CJIS-5.4.1.1
1901 ··-·DISA-STIG-RHEL-08-0304901901 ··-·DISA-STIG-RHEL-08-030490
1902 ··-·NIST-800-171-3.1.71902 ··-·NIST-800-171-3.1.7
1903 ··-·NIST-800-53-AU-12(c)1903 ··-·NIST-800-53-AU-12(c)
Offset 2035, 16 lines modifiedOffset 2035, 16 lines modified
2035 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002035 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2036 ········-F·auid!=unset·-F·key=perm_mod2036 ········-F·auid!=unset·-F·key=perm_mod
2037 ······create:·true2037 ······create:·true
2038 ······mode:·o-rwx2038 ······mode:·o-rwx
2039 ······state:·present2039 ······state:·present
2040 ····when:·syscalls_found·|·length·==·02040 ····when:·syscalls_found·|·length·==·0
2041 ··when:2041 ··when:
2042 ··-·'"audit"·in·ansible_facts.packages' 
2043 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2042 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2043 ··-·'"audit"·in·ansible_facts.packages'
2044 ··tags:2044 ··tags:
2045 ··-·CJIS-5.4.1.12045 ··-·CJIS-5.4.1.1
2046 ··-·DISA-STIG-RHEL-08-0304902046 ··-·DISA-STIG-RHEL-08-030490
2047 ··-·NIST-800-171-3.1.72047 ··-·NIST-800-171-3.1.7
2048 ··-·NIST-800-53-AU-12(c)2048 ··-·NIST-800-53-AU-12(c)
2049 ··-·NIST-800-53-AU-2(d)2049 ··-·NIST-800-53-AU-2(d)
2050 ··-·NIST-800-53-CM-6(a)2050 ··-·NIST-800-53-CM-6(a)
Offset 2179, 16 lines modifiedOffset 2179, 16 lines modified
2179 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002179 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2180 ········-F·auid!=unset·-F·key=perm_mod2180 ········-F·auid!=unset·-F·key=perm_mod
2181 ······create:·true2181 ······create:·true
2182 ······mode:·o-rwx2182 ······mode:·o-rwx
2183 ······state:·present2183 ······state:·present
2184 ····when:·syscalls_found·|·length·==·02184 ····when:·syscalls_found·|·length·==·0
2185 ··when:2185 ··when:
2186 ··-·'"audit"·in·ansible_facts.packages' 
2187 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2186 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2187 ··-·'"audit"·in·ansible_facts.packages'
2188 ··-·audit_arch·==·"b64"2188 ··-·audit_arch·==·"b64"
2189 ··tags:2189 ··tags:
2190 ··-·CJIS-5.4.1.12190 ··-·CJIS-5.4.1.1
2191 ··-·DISA-STIG-RHEL-08-0304902191 ··-·DISA-STIG-RHEL-08-030490
2192 ··-·NIST-800-171-3.1.72192 ··-·NIST-800-171-3.1.7
2193 ··-·NIST-800-53-AU-12(c)2193 ··-·NIST-800-53-AU-12(c)
2194 ··-·NIST-800-53-AU-2(d)2194 ··-·NIST-800-53-AU-2(d)
Offset 2198, 15 lines modifiedOffset 2198, 15 lines modified
2198 ··-·low_complexity2198 ··-·low_complexity
2199 ··-·low_disruption2199 ··-·low_disruption
2200 ··-·medium_severity2200 ··-·medium_severity
2201 ··-·reboot_required2201 ··-·reboot_required
2202 ··-·restrict_strategy2202 ··-·restrict_strategy
2203 Remediation_Shell_script_⇲2203 Remediation_Shell_script_⇲
2204 #·Remediation·is·applicable·only·in·certain·platforms2204 #·Remediation·is·applicable·only·in·certain·platforms
2205 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then2205 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
2206 #·First·perform·the·remediation·of·the·syscall·rule2206 #·First·perform·the·remediation·of·the·syscall·rule
2207 #·Retrieve·hardware·architecture·of·the·underlying·system2207 #·Retrieve·hardware·architecture·of·the·underlying·system
2208 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")2208 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
2209 for·ARCH·in·"${RULE_ARCHS[@]}"2209 for·ARCH·in·"${RULE_ARCHS[@]}"
2210 do2210 do
Offset 2567, 16 lines modifiedOffset 2567, 16 lines modified
2567 ··-·reboot_required2567 ··-·reboot_required
2568 ··-·restrict_strategy2568 ··-·restrict_strategy
  
2569 -·name:·Set·architecture·for·audit·chown·tasks2569 -·name:·Set·architecture·for·audit·chown·tasks
2570 ··set_fact:2570 ··set_fact:
2571 ····audit_arch:·b642571 ····audit_arch:·b64
2572 ··when:2572 ··when:
2573 ··-·'"audit"·in·ansible_facts.packages' 
2574 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2573 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2574 ··-·'"audit"·in·ansible_facts.packages'
2575 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture2575 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
2576 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"2576 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
2577 ··tags:2577 ··tags:
2578 ··-·CJIS-5.4.1.12578 ··-·CJIS-5.4.1.1
2579 ··-·DISA-STIG-RHEL-08-0304802579 ··-·DISA-STIG-RHEL-08-030480
2580 ··-·NIST-800-171-3.1.72580 ··-·NIST-800-171-3.1.7
2581 ··-·NIST-800-53-AU-12(c)2581 ··-·NIST-800-53-AU-12(c)
Offset 2715, 16 lines modifiedOffset 2715, 16 lines modified
2715 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002715 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2716 ········-F·auid!=unset·-F·key=perm_mod2716 ········-F·auid!=unset·-F·key=perm_mod
2717 ······create:·true2717 ······create:·true
2718 ······mode:·o-rwx2718 ······mode:·o-rwx
2719 ······state:·present2719 ······state:·present
2720 ····when:·syscalls_found·|·length·==·02720 ····when:·syscalls_found·|·length·==·0
2721 ··when:2721 ··when:
2722 ··-·'"audit"·in·ansible_facts.packages' 
2723 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2722 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2723 ··-·'"audit"·in·ansible_facts.packages'
2724 ··tags:2724 ··tags:
2725 ··-·CJIS-5.4.1.12725 ··-·CJIS-5.4.1.1
2726 ··-·DISA-STIG-RHEL-08-0304802726 ··-·DISA-STIG-RHEL-08-030480
2727 ··-·NIST-800-171-3.1.72727 ··-·NIST-800-171-3.1.7
2728 ··-·NIST-800-53-AU-12(c)2728 ··-·NIST-800-53-AU-12(c)
2729 ··-·NIST-800-53-AU-2(d)2729 ··-·NIST-800-53-AU-2(d)
2730 ··-·NIST-800-53-CM-6(a)2730 ··-·NIST-800-53-CM-6(a)
Offset 2861, 16 lines modifiedOffset 2861, 16 lines modified
2861 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002861 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2862 ········-F·auid!=unset·-F·key=perm_mod2862 ········-F·auid!=unset·-F·key=perm_mod
2863 ······create:·true2863 ······create:·true
2864 ······mode:·o-rwx2864 ······mode:·o-rwx
2865 ······state:·present2865 ······state:·present
Max diff block lines reached; 80507/84996 bytes (94.72%) of diff not shown.
920 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-hipaa.html
    
Offset 14568, 15 lines modifiedOffset 14568, 15 lines modified
00038e70:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr00038e70:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr
00038e80:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st00038e80:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st
00038e90:·726f·6e67·3e30·2e31·2e36·353c·2f73·7472··rong>0.1.65</str00038e90:·726f·6e67·3e30·2e31·2e36·353c·2f73·7472··rong>0.1.65</str
00038ea0:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>00038ea0:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>
00038eb0:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s00038eb0:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s
00038ec0:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········00038ec0:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········
00038ed0:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o00038ed0:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o
00038ee0:·6620·3230·3234·2d30·312d·3134·290a·2020··f·2024-01-14).··00038ee0:·6620·3230·3235·2d30·322d·3135·290a·2020··f·2025-02-15).··
00038ef0:·2020·2020·2020·2020·2020·2020·2020·3c2f················</00038ef0:·2020·2020·2020·2020·2020·2020·2020·3c2f················</
00038f00:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h00038f00:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h
00038f10:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte00038f10:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte
00038f20:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>00038f20:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>
00038f30:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_00038f30:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_
00038f40:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c00038f40:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c
00038f50:·6f6e·7465·6e74·5f67·726f·7570·5f73·7973··ontent_group_sys00038f50:·6f6e·7465·6e74·5f67·726f·7570·5f73·7973··ontent_group_sys
Offset 32905, 23 lines modifiedOffset 32905, 23 lines modified
00080880:·6571·7569·7265·640a·2020·2d20·7265·7374··equired.··-·rest00080880:·6571·7569·7265·640a·2020·2d20·7265·7374··equired.··-·rest
00080890:·7269·6374·5f73·7472·6174·6567·790a·0a2d··rict_strategy..-00080890:·7269·6374·5f73·7472·6174·6567·790a·0a2d··rict_strategy..-
000808a0:·206e·616d·653a·2053·6574·2061·7263·6869···name:·Set·archi000808a0:·206e·616d·653a·2053·6574·2061·7263·6869···name:·Set·archi
000808b0:·7465·6374·7572·6520·666f·7220·6175·6469··tecture·for·audi000808b0:·7465·6374·7572·6520·666f·7220·6175·6469··tecture·for·audi
000808c0:·7420·6368·6d6f·6420·7461·736b·730a·2020··t·chmod·tasks.··000808c0:·7420·6368·6d6f·6420·7461·736b·730a·2020··t·chmod·tasks.··
000808d0:·7365·745f·6661·6374·3a0a·2020·2020·6175··set_fact:.····au000808d0:·7365·745f·6661·6374·3a0a·2020·2020·6175··set_fact:.····au
000808e0:·6469·745f·6172·6368·3a20·6236·340a·2020··dit_arch:·b64.··000808e0:·6469·745f·6172·6368·3a20·6236·340a·2020··dit_arch:·b64.··
000808f0:·7768·656e·3a0a·2020·2d20·2722·6175·6469··when:.··-·'"audi000808f0:·7768·656e·3a0a·2020·2d20·616e·7369·626c··when:.··-·ansibl
00080900:·7422·2069·6e20·616e·7369·626c·655f·6661··t"·in·ansible_fa 
00080910:·6374·732e·7061·636b·6167·6573·270a·2020··cts.packages'.·· 
00080920:·2d20·616e·7369·626c·655f·7669·7274·7561··-·ansible_virtua 
00080930:·6c69·7a61·7469·6f6e·5f74·7970·6520·6e6f··lization_type·no 
00080940:·7420·696e·205b·2264·6f63·6b65·7222·2c20··t·in·["docker",· 
00080950:·226c·7863·222c·2022·6f70·656e·767a·222c··"lxc",·"openvz", 
00080960:·2022·706f·646d·616e·222c·2022·636f·6e74···"podman",·"cont00080900:·655f·7669·7274·7561·6c69·7a61·7469·6f6e··e_virtualization
 00080910:·5f74·7970·6520·6e6f·7420·696e·205b·2264··_type·not·in·["d
 00080920:·6f63·6b65·7222·2c20·226c·7863·222c·2022··ocker",·"lxc",·"
 00080930:·6f70·656e·767a·222c·2022·706f·646d·616e··openvz",·"podman
 00080940:·222c·2022·636f·6e74·6169·6e65·7222·5d0a··",·"container"].
 00080950:·2020·2d20·2722·6175·6469·7422·2069·6e20····-·'"audit"·in·
 00080960:·616e·7369·626c·655f·6661·6374·732e·7061··ansible_facts.pa
00080970:·6169·6e65·7222·5d0a·2020·2d20·616e·7369··ainer"].··-·ansi00080970:·636b·6167·6573·270a·2020·2d20·616e·7369··ckages'.··-·ansi
00080980:·626c·655f·6172·6368·6974·6563·7475·7265··ble_architecture00080980:·626c·655f·6172·6368·6974·6563·7475·7265··ble_architecture
00080990:·203d·3d20·2261·6172·6368·3634·2220·6f72···==·"aarch64"·or00080990:·203d·3d20·2261·6172·6368·3634·2220·6f72···==·"aarch64"·or
000809a0:·2061·6e73·6962·6c65·5f61·7263·6869·7465···ansible_archite000809a0:·2061·6e73·6962·6c65·5f61·7263·6869·7465···ansible_archite
000809b0:·6374·7572·6520·3d3d·2022·7070·6336·3422··cture·==·"ppc64"000809b0:·6374·7572·6520·3d3d·2022·7070·6336·3422··cture·==·"ppc64"
000809c0:·206f·7220·616e·7369·626c·655f·6172·6368···or·ansible_arch000809c0:·206f·7220·616e·7369·626c·655f·6172·6368···or·ansible_arch
000809d0:·6974·6563·7475·7265·0a20·2020·203d·3d20··itecture.····==·000809d0:·6974·6563·7475·7265·0a20·2020·203d·3d20··itecture.····==·
000809e0:·2270·7063·3634·6c65·2220·6f72·2061·6e73··"ppc64le"·or·ans000809e0:·2270·7063·3634·6c65·2220·6f72·2061·6e73··"ppc64le"·or·ans
Offset 33228, 23 lines modifiedOffset 33228, 23 lines modified
00081cb0:·2d46·206b·6579·3d70·6572·6d5f·6d6f·640a··-F·key=perm_mod.00081cb0:·2d46·206b·6579·3d70·6572·6d5f·6d6f·640a··-F·key=perm_mod.
00081cc0:·2020·2020·2020·6372·6561·7465·3a20·7472········create:·tr00081cc0:·2020·2020·2020·6372·6561·7465·3a20·7472········create:·tr
00081cd0:·7565·0a20·2020·2020·206d·6f64·653a·206f··ue.······mode:·o00081cd0:·7565·0a20·2020·2020·206d·6f64·653a·206f··ue.······mode:·o
00081ce0:·2d72·7778·0a20·2020·2020·2073·7461·7465··-rwx.······state00081ce0:·2d72·7778·0a20·2020·2020·2073·7461·7465··-rwx.······state
00081cf0:·3a20·7072·6573·656e·740a·2020·2020·7768··:·present.····wh00081cf0:·3a20·7072·6573·656e·740a·2020·2020·7768··:·present.····wh
00081d00:·656e·3a20·7379·7363·616c·6c73·5f66·6f75··en:·syscalls_fou00081d00:·656e·3a20·7379·7363·616c·6c73·5f66·6f75··en:·syscalls_fou
00081d10:·6e64·207c·206c·656e·6774·6820·3d3d·2030··nd·|·length·==·000081d10:·6e64·207c·206c·656e·6774·6820·3d3d·2030··nd·|·length·==·0
00081d20:·0a20·2077·6865·6e3a·0a20·202d·2027·2261··.··when:.··-·'"a00081d20:·0a20·2077·6865·6e3a·0a20·202d·2061·6e73··.··when:.··-·ans
00081d30:·7564·6974·2220·696e·2061·6e73·6962·6c65··udit"·in·ansible 
00081d40:·5f66·6163·7473·2e70·6163·6b61·6765·7327··_facts.packages' 
00081d50:·0a20·202d·2061·6e73·6962·6c65·5f76·6972··.··-·ansible_vir 
00081d60:·7475·616c·697a·6174·696f·6e5f·7479·7065··tualization_type 
00081d70:·206e·6f74·2069·6e20·5b22·646f·636b·6572···not·in·["docker 
00081d80:·222c·2022·6c78·6322·2c20·226f·7065·6e76··",·"lxc",·"openv 
00081d90:·7a22·2c20·2270·6f64·6d61·6e22·2c20·2263··z",·"podman",·"c 
00081da0:·6f6e·7461·696e·6572·225d·0a20·2074·6167··ontainer"].··tag00081d30:·6962·6c65·5f76·6972·7475·616c·697a·6174··ible_virtualizat
 00081d40:·696f·6e5f·7479·7065·206e·6f74·2069·6e20··ion_type·not·in·
 00081d50:·5b22·646f·636b·6572·222c·2022·6c78·6322··["docker",·"lxc"
 00081d60:·2c20·226f·7065·6e76·7a22·2c20·2270·6f64··,·"openvz",·"pod
 00081d70:·6d61·6e22·2c20·2263·6f6e·7461·696e·6572··man",·"container
 00081d80:·225d·0a20·202d·2027·2261·7564·6974·2220··"].··-·'"audit"·
 00081d90:·696e·2061·6e73·6962·6c65·5f66·6163·7473··in·ansible_facts
 00081da0:·2e70·6163·6b61·6765·7327·0a20·2074·6167··.packages'.··tag
00081db0:·733a·0a20·202d·2043·4a49·532d·352e·342e··s:.··-·CJIS-5.4.00081db0:·733a·0a20·202d·2043·4a49·532d·352e·342e··s:.··-·CJIS-5.4.
00081dc0:·312e·310a·2020·2d20·4449·5341·2d53·5449··1.1.··-·DISA-STI00081dc0:·312e·310a·2020·2d20·4449·5341·2d53·5449··1.1.··-·DISA-STI
00081dd0:·472d·5248·454c·2d30·382d·3033·3034·3930··G-RHEL-08-03049000081dd0:·472d·5248·454c·2d30·382d·3033·3034·3930··G-RHEL-08-030490
00081de0:·0a20·202d·204e·4953·542d·3830·302d·3137··.··-·NIST-800-1700081de0:·0a20·202d·204e·4953·542d·3830·302d·3137··.··-·NIST-800-17
00081df0:·312d·332e·312e·370a·2020·2d20·4e49·5354··1-3.1.7.··-·NIST00081df0:·312d·332e·312e·370a·2020·2d20·4e49·5354··1-3.1.7.··-·NIST
00081e00:·2d38·3030·2d35·332d·4155·2d31·3228·6329··-800-53-AU-12(c)00081e00:·2d38·3030·2d35·332d·4155·2d31·3228·6329··-800-53-AU-12(c)
00081e10:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-5300081e10:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
Offset 33540, 23 lines modifiedOffset 33540, 23 lines modified
00083030:·3d70·6572·6d5f·6d6f·640a·2020·2020·2020··=perm_mod.······00083030:·3d70·6572·6d5f·6d6f·640a·2020·2020·2020··=perm_mod.······
00083040:·6372·6561·7465·3a20·7472·7565·0a20·2020··create:·true.···00083040:·6372·6561·7465·3a20·7472·7565·0a20·2020··create:·true.···
00083050:·2020·206d·6f64·653a·206f·2d72·7778·0a20·····mode:·o-rwx.·00083050:·2020·206d·6f64·653a·206f·2d72·7778·0a20·····mode:·o-rwx.·
00083060:·2020·2020·2073·7461·7465·3a20·7072·6573·······state:·pres00083060:·2020·2020·2073·7461·7465·3a20·7072·6573·······state:·pres
00083070:·656e·740a·2020·2020·7768·656e·3a20·7379··ent.····when:·sy00083070:·656e·740a·2020·2020·7768·656e·3a20·7379··ent.····when:·sy
00083080:·7363·616c·6c73·5f66·6f75·6e64·207c·206c··scalls_found·|·l00083080:·7363·616c·6c73·5f66·6f75·6e64·207c·206c··scalls_found·|·l
00083090:·656e·6774·6820·3d3d·2030·0a20·2077·6865··ength·==·0.··whe00083090:·656e·6774·6820·3d3d·2030·0a20·2077·6865··ength·==·0.··whe
000830a0:·6e3a·0a20·202d·2027·2261·7564·6974·2220··n:.··-·'"audit"· 
000830b0:·696e·2061·6e73·6962·6c65·5f66·6163·7473··in·ansible_facts 
000830c0:·2e70·6163·6b61·6765·7327·0a20·202d·2061··.packages'.··-·a 
000830d0:·6e73·6962·6c65·5f76·6972·7475·616c·697a··nsible_virtualiz 
000830e0:·6174·696f·6e5f·7479·7065·206e·6f74·2069··ation_type·not·i 
000830f0:·6e20·5b22·646f·636b·6572·222c·2022·6c78··n·["docker",·"lx 
00083100:·6322·2c20·226f·7065·6e76·7a22·2c20·2270··c",·"openvz",·"p 
00083110:·6f64·6d61·6e22·2c20·2263·6f6e·7461·696e··odman",·"contain000830a0:·6e3a·0a20·202d·2061·6e73·6962·6c65·5f76··n:.··-·ansible_v
 000830b0:·6972·7475·616c·697a·6174·696f·6e5f·7479··irtualization_ty
 000830c0:·7065·206e·6f74·2069·6e20·5b22·646f·636b··pe·not·in·["dock
 000830d0:·6572·222c·2022·6c78·6322·2c20·226f·7065··er",·"lxc",·"ope
 000830e0:·6e76·7a22·2c20·2270·6f64·6d61·6e22·2c20··nvz",·"podman",·
 000830f0:·2263·6f6e·7461·696e·6572·225d·0a20·202d··"container"].··-
 00083100:·2027·2261·7564·6974·2220·696e·2061·6e73···'"audit"·in·ans
 00083110:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa
00083120:·6572·225d·0a20·202d·2061·7564·6974·5f61··er"].··-·audit_a00083120:·6765·7327·0a20·202d·2061·7564·6974·5f61··ges'.··-·audit_a
00083130:·7263·6820·3d3d·2022·6236·3422·0a20·2074··rch·==·"b64".··t00083130:·7263·6820·3d3d·2022·6236·3422·0a20·2074··rch·==·"b64".··t
00083140:·6167·733a·0a20·202d·2043·4a49·532d·352e··ags:.··-·CJIS-5.00083140:·6167·733a·0a20·202d·2043·4a49·532d·352e··ags:.··-·CJIS-5.
00083150:·342e·312e·310a·2020·2d20·4449·5341·2d53··4.1.1.··-·DISA-S00083150:·342e·312e·310a·2020·2d20·4449·5341·2d53··4.1.1.··-·DISA-S
00083160:·5449·472d·5248·454c·2d30·382d·3033·3034··TIG-RHEL-08-030400083160:·5449·472d·5248·454c·2d30·382d·3033·3034··TIG-RHEL-08-0304
00083170:·3930·0a20·202d·204e·4953·542d·3830·302d··90.··-·NIST-800-00083170:·3930·0a20·202d·204e·4953·542d·3830·302d··90.··-·NIST-800-
00083180:·3137·312d·332e·312e·370a·2020·2d20·4e49··171-3.1.7.··-·NI00083180:·3137·312d·332e·312e·370a·2020·2d20·4e49··171-3.1.7.··-·NI
00083190:·5354·2d38·3030·2d35·332d·4155·2d31·3228··ST-800-53-AU-12(00083190:·5354·2d38·3030·2d35·332d·4155·2d31·3228··ST-800-53-AU-12(
Offset 33590, 20 lines modifiedOffset 33590, 20 lines modified
00083350:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co00083350:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
00083360:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"00083360:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
00083370:·2069·643d·2269·646d·3235·3339·3022·3e3c···id="idm25390"><00083370:·2069·643d·2269·646d·3235·3339·3022·3e3c···id="idm25390"><
00083380:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme00083380:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme
00083390:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli00083390:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli
000833a0:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce000833a0:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce
000833b0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.000833b0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.
000833c0:·6966·2072·706d·202d·2d71·7569·6574·202d··if·rpm·--quiet·- 
000833d0:·7120·6175·6469·7420·2661·6d70·3b26·616d··q·audit·&amp;&am 
000833e0:·703b·205b·2021·202d·6620·2f2e·646f·636b··p;·[·!·-f·/.dock000833c0:·6966·205b·2021·202d·6620·2f2e·646f·636b··if·[·!·-f·/.dock
000833f0:·6572·656e·7620·5d20·2661·6d70·3b26·616d··erenv·]·&amp;&am000833d0:·6572·656e·7620·5d20·2661·6d70·3b26·616d··erenv·]·&amp;&am
00083400:·703b·205b·2021·202d·6620·2f72·756e·2f2e··p;·[·!·-f·/run/.000833e0:·703b·205b·2021·202d·6620·2f72·756e·2f2e··p;·[·!·-f·/run/.
00083410:·636f·6e74·6169·6e65·7265·6e76·205d·3b20··containerenv·];·000833f0:·636f·6e74·6169·6e65·7265·6e76·205d·2026··containerenv·]·&
 00083400:·616d·703b·2661·6d70·3b20·7270·6d20·2d2d··amp;&amp;·rpm·--
 00083410:·7175·6965·7420·2d71·2061·7564·6974·3b20··quiet·-q·audit;·
00083420:·7468·656e·0a0a·2320·4669·7273·7420·7065··then..#·First·pe00083420:·7468·656e·0a0a·2320·4669·7273·7420·7065··then..#·First·pe
00083430:·7266·6f72·6d20·7468·6520·7265·6d65·6469··rform·the·remedi00083430:·7266·6f72·6d20·7468·6520·7265·6d65·6469··rform·the·remedi
00083440:·6174·696f·6e20·6f66·2074·6865·2073·7973··ation·of·the·sys00083440:·6174·696f·6e20·6f66·2074·6865·2073·7973··ation·of·the·sys
00083450:·6361·6c6c·2072·756c·650a·2320·5265·7472··call·rule.#·Retr00083450:·6361·6c6c·2072·756c·650a·2320·5265·7472··call·rule.#·Retr
Max diff block lines reached; 719546/729060 bytes (98.70%) of diff not shown.
208 KB
html2text {}
    
Offset 75, 15 lines modifiedOffset 75, 15 lines modified
75 ····*·cpe:/o:redhat:enterprise_linux:8.775 ····*·cpe:/o:redhat:enterprise_linux:8.7
76 ····*·cpe:/o:redhat:enterprise_linux:8.876 ····*·cpe:/o:redhat:enterprise_linux:8.8
77 ····*·cpe:/o:redhat:enterprise_linux:8.977 ····*·cpe:/o:redhat:enterprise_linux:8.9
78 ····*·cpe:/o:redhat:enterprise_linux:878 ····*·cpe:/o:redhat:enterprise_linux:8
79 ····*·cpe:/o:centos:centos:879 ····*·cpe:/o:centos:centos:8
80 *****·Revision·History·*****80 *****·Revision·History·*****
81 Current·version:·0.1.6581 Current·version:·0.1.65
82 ····*·draft·(as·of·2024-01-14)82 ····*·draft·(as·of·2025-02-15)
83 *****·Table·of·Contents·*****83 *****·Table·of·Contents·*****
84 ···1.·System_Settings84 ···1.·System_Settings
85 ·········1.·Installing_and_Maintaining_Software85 ·········1.·Installing_and_Maintaining_Software
86 ·········2.·Account_and_Access_Control86 ·········2.·Account_and_Access_Control
87 ·········3.·System_Accounting_with_auditd87 ·········3.·System_Accounting_with_auditd
88 ·········4.·GRUB2_bootloader_configuration88 ·········4.·GRUB2_bootloader_configuration
89 ·········5.·Configure_Syslog89 ·········5.·Configure_Syslog
Offset 2298, 16 lines modifiedOffset 2298, 16 lines modified
2298 ··-·reboot_required2298 ··-·reboot_required
2299 ··-·restrict_strategy2299 ··-·restrict_strategy
  
2300 -·name:·Set·architecture·for·audit·chmod·tasks2300 -·name:·Set·architecture·for·audit·chmod·tasks
2301 ··set_fact:2301 ··set_fact:
2302 ····audit_arch:·b642302 ····audit_arch:·b64
2303 ··when:2303 ··when:
2304 ··-·'"audit"·in·ansible_facts.packages' 
2305 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2304 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2305 ··-·'"audit"·in·ansible_facts.packages'
2306 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture2306 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
2307 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"2307 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
2308 ··tags:2308 ··tags:
2309 ··-·CJIS-5.4.1.12309 ··-·CJIS-5.4.1.1
2310 ··-·DISA-STIG-RHEL-08-0304902310 ··-·DISA-STIG-RHEL-08-030490
2311 ··-·NIST-800-171-3.1.72311 ··-·NIST-800-171-3.1.7
2312 ··-·NIST-800-53-AU-12(c)2312 ··-·NIST-800-53-AU-12(c)
Offset 2444, 16 lines modifiedOffset 2444, 16 lines modified
2444 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002444 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2445 ········-F·auid!=unset·-F·key=perm_mod2445 ········-F·auid!=unset·-F·key=perm_mod
2446 ······create:·true2446 ······create:·true
2447 ······mode:·o-rwx2447 ······mode:·o-rwx
2448 ······state:·present2448 ······state:·present
2449 ····when:·syscalls_found·|·length·==·02449 ····when:·syscalls_found·|·length·==·0
2450 ··when:2450 ··when:
2451 ··-·'"audit"·in·ansible_facts.packages' 
2452 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2451 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2452 ··-·'"audit"·in·ansible_facts.packages'
2453 ··tags:2453 ··tags:
2454 ··-·CJIS-5.4.1.12454 ··-·CJIS-5.4.1.1
2455 ··-·DISA-STIG-RHEL-08-0304902455 ··-·DISA-STIG-RHEL-08-030490
2456 ··-·NIST-800-171-3.1.72456 ··-·NIST-800-171-3.1.7
2457 ··-·NIST-800-53-AU-12(c)2457 ··-·NIST-800-53-AU-12(c)
2458 ··-·NIST-800-53-AU-2(d)2458 ··-·NIST-800-53-AU-2(d)
2459 ··-·NIST-800-53-CM-6(a)2459 ··-·NIST-800-53-CM-6(a)
Offset 2588, 16 lines modifiedOffset 2588, 16 lines modified
2588 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002588 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2589 ········-F·auid!=unset·-F·key=perm_mod2589 ········-F·auid!=unset·-F·key=perm_mod
2590 ······create:·true2590 ······create:·true
2591 ······mode:·o-rwx2591 ······mode:·o-rwx
2592 ······state:·present2592 ······state:·present
2593 ····when:·syscalls_found·|·length·==·02593 ····when:·syscalls_found·|·length·==·0
2594 ··when:2594 ··when:
2595 ··-·'"audit"·in·ansible_facts.packages' 
2596 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2595 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2596 ··-·'"audit"·in·ansible_facts.packages'
2597 ··-·audit_arch·==·"b64"2597 ··-·audit_arch·==·"b64"
2598 ··tags:2598 ··tags:
2599 ··-·CJIS-5.4.1.12599 ··-·CJIS-5.4.1.1
2600 ··-·DISA-STIG-RHEL-08-0304902600 ··-·DISA-STIG-RHEL-08-030490
2601 ··-·NIST-800-171-3.1.72601 ··-·NIST-800-171-3.1.7
2602 ··-·NIST-800-53-AU-12(c)2602 ··-·NIST-800-53-AU-12(c)
2603 ··-·NIST-800-53-AU-2(d)2603 ··-·NIST-800-53-AU-2(d)
Offset 2607, 15 lines modifiedOffset 2607, 15 lines modified
2607 ··-·low_complexity2607 ··-·low_complexity
2608 ··-·low_disruption2608 ··-·low_disruption
2609 ··-·medium_severity2609 ··-·medium_severity
2610 ··-·reboot_required2610 ··-·reboot_required
2611 ··-·restrict_strategy2611 ··-·restrict_strategy
2612 Remediation_Shell_script_⇲2612 Remediation_Shell_script_⇲
2613 #·Remediation·is·applicable·only·in·certain·platforms2613 #·Remediation·is·applicable·only·in·certain·platforms
2614 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then2614 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
2615 #·First·perform·the·remediation·of·the·syscall·rule2615 #·First·perform·the·remediation·of·the·syscall·rule
2616 #·Retrieve·hardware·architecture·of·the·underlying·system2616 #·Retrieve·hardware·architecture·of·the·underlying·system
2617 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")2617 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
2618 for·ARCH·in·"${RULE_ARCHS[@]}"2618 for·ARCH·in·"${RULE_ARCHS[@]}"
2619 do2619 do
Offset 2976, 16 lines modifiedOffset 2976, 16 lines modified
2976 ··-·reboot_required2976 ··-·reboot_required
2977 ··-·restrict_strategy2977 ··-·restrict_strategy
  
2978 -·name:·Set·architecture·for·audit·chown·tasks2978 -·name:·Set·architecture·for·audit·chown·tasks
2979 ··set_fact:2979 ··set_fact:
2980 ····audit_arch:·b642980 ····audit_arch:·b64
2981 ··when:2981 ··when:
2982 ··-·'"audit"·in·ansible_facts.packages' 
2983 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2982 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2983 ··-·'"audit"·in·ansible_facts.packages'
2984 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture2984 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
2985 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"2985 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
2986 ··tags:2986 ··tags:
2987 ··-·CJIS-5.4.1.12987 ··-·CJIS-5.4.1.1
2988 ··-·DISA-STIG-RHEL-08-0304802988 ··-·DISA-STIG-RHEL-08-030480
2989 ··-·NIST-800-171-3.1.72989 ··-·NIST-800-171-3.1.7
2990 ··-·NIST-800-53-AU-12(c)2990 ··-·NIST-800-53-AU-12(c)
Offset 3124, 16 lines modifiedOffset 3124, 16 lines modified
3124 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10003124 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
3125 ········-F·auid!=unset·-F·key=perm_mod3125 ········-F·auid!=unset·-F·key=perm_mod
3126 ······create:·true3126 ······create:·true
3127 ······mode:·o-rwx3127 ······mode:·o-rwx
3128 ······state:·present3128 ······state:·present
3129 ····when:·syscalls_found·|·length·==·03129 ····when:·syscalls_found·|·length·==·0
3130 ··when:3130 ··when:
3131 ··-·'"audit"·in·ansible_facts.packages' 
3132 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3131 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3132 ··-·'"audit"·in·ansible_facts.packages'
3133 ··tags:3133 ··tags:
3134 ··-·CJIS-5.4.1.13134 ··-·CJIS-5.4.1.1
3135 ··-·DISA-STIG-RHEL-08-0304803135 ··-·DISA-STIG-RHEL-08-030480
3136 ··-·NIST-800-171-3.1.73136 ··-·NIST-800-171-3.1.7
3137 ··-·NIST-800-53-AU-12(c)3137 ··-·NIST-800-53-AU-12(c)
3138 ··-·NIST-800-53-AU-2(d)3138 ··-·NIST-800-53-AU-2(d)
3139 ··-·NIST-800-53-CM-6(a)3139 ··-·NIST-800-53-CM-6(a)
Offset 3270, 16 lines modifiedOffset 3270, 16 lines modified
3270 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10003270 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
3271 ········-F·auid!=unset·-F·key=perm_mod3271 ········-F·auid!=unset·-F·key=perm_mod
3272 ······create:·true3272 ······create:·true
3273 ······mode:·o-rwx3273 ······mode:·o-rwx
3274 ······state:·present3274 ······state:·present
Max diff block lines reached; 207983/212467 bytes (97.89%) of diff not shown.
437 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-ism_o.html
    
Offset 14561, 15 lines modifiedOffset 14561, 15 lines modified
00038e00:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr00038e00:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr
00038e10:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st00038e10:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st
00038e20:·726f·6e67·3e30·2e31·2e36·353c·2f73·7472··rong>0.1.65</str00038e20:·726f·6e67·3e30·2e31·2e36·353c·2f73·7472··rong>0.1.65</str
00038e30:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>00038e30:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>
00038e40:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s00038e40:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s
00038e50:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········00038e50:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········
00038e60:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o00038e60:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o
00038e70:·6620·3230·3234·2d30·312d·3134·290a·2020··f·2024-01-14).··00038e70:·6620·3230·3235·2d30·322d·3135·290a·2020··f·2025-02-15).··
00038e80:·2020·2020·2020·2020·2020·2020·2020·3c2f················</00038e80:·2020·2020·2020·2020·2020·2020·2020·3c2f················</
00038e90:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h00038e90:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h
00038ea0:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte00038ea0:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte
00038eb0:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>00038eb0:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>
00038ec0:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_00038ec0:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_
00038ed0:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c00038ed0:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c
00038ee0:·6f6e·7465·6e74·5f67·726f·7570·5f73·7973··ontent_group_sys00038ee0:·6f6e·7465·6e74·5f67·726f·7570·5f73·7973··ontent_group_sys
Offset 48891, 23 lines modifiedOffset 48891, 23 lines modified
000befa0:·7265·640a·2020·2d20·7265·7374·7269·6374··red.··-·restrict000befa0:·7265·640a·2020·2d20·7265·7374·7269·6374··red.··-·restrict
000befb0:·5f73·7472·6174·6567·790a·0a2d·206e·616d··_strategy..-·nam000befb0:·5f73·7472·6174·6567·790a·0a2d·206e·616d··_strategy..-·nam
000befc0:·653a·2053·6574·2061·7263·6869·7465·6374··e:·Set·architect000befc0:·653a·2053·6574·2061·7263·6869·7465·6374··e:·Set·architect
000befd0:·7572·6520·666f·7220·6175·6469·7420·6368··ure·for·audit·ch000befd0:·7572·6520·666f·7220·6175·6469·7420·6368··ure·for·audit·ch
000befe0:·6d6f·6420·7461·736b·730a·2020·7365·745f··mod·tasks.··set_000befe0:·6d6f·6420·7461·736b·730a·2020·7365·745f··mod·tasks.··set_
000beff0:·6661·6374·3a0a·2020·2020·6175·6469·745f··fact:.····audit_000beff0:·6661·6374·3a0a·2020·2020·6175·6469·745f··fact:.····audit_
000bf000:·6172·6368·3a20·6236·340a·2020·7768·656e··arch:·b64.··when000bf000:·6172·6368·3a20·6236·340a·2020·7768·656e··arch:·b64.··when
000bf010:·3a0a·2020·2d20·2722·6175·6469·7422·2069··:.··-·'"audit"·i 
000bf020:·6e20·616e·7369·626c·655f·6661·6374·732e··n·ansible_facts. 
000bf030:·7061·636b·6167·6573·270a·2020·2d20·616e··packages'.··-·an 
000bf040:·7369·626c·655f·7669·7274·7561·6c69·7a61··sible_virtualiza 
000bf050:·7469·6f6e·5f74·7970·6520·6e6f·7420·696e··tion_type·not·in 
000bf060:·205b·2264·6f63·6b65·7222·2c20·226c·7863···["docker",·"lxc 
000bf070:·222c·2022·6f70·656e·767a·222c·2022·706f··",·"openvz",·"po 
000bf080:·646d·616e·222c·2022·636f·6e74·6169·6e65··dman",·"containe000bf010:·3a0a·2020·2d20·616e·7369·626c·655f·7669··:.··-·ansible_vi
 000bf020:·7274·7561·6c69·7a61·7469·6f6e·5f74·7970··rtualization_typ
 000bf030:·6520·6e6f·7420·696e·205b·2264·6f63·6b65··e·not·in·["docke
 000bf040:·7222·2c20·226c·7863·222c·2022·6f70·656e··r",·"lxc",·"open
 000bf050:·767a·222c·2022·706f·646d·616e·222c·2022··vz",·"podman",·"
 000bf060:·636f·6e74·6169·6e65·7222·5d0a·2020·2d20··container"].··-·
 000bf070:·2722·6175·6469·7422·2069·6e20·616e·7369··'"audit"·in·ansi
 000bf080:·626c·655f·6661·6374·732e·7061·636b·6167··ble_facts.packag
000bf090:·7222·5d0a·2020·2d20·616e·7369·626c·655f··r"].··-·ansible_000bf090:·6573·270a·2020·2d20·616e·7369·626c·655f··es'.··-·ansible_
000bf0a0:·6172·6368·6974·6563·7475·7265·203d·3d20··architecture·==·000bf0a0:·6172·6368·6974·6563·7475·7265·203d·3d20··architecture·==·
000bf0b0:·2261·6172·6368·3634·2220·6f72·2061·6e73··"aarch64"·or·ans000bf0b0:·2261·6172·6368·3634·2220·6f72·2061·6e73··"aarch64"·or·ans
000bf0c0:·6962·6c65·5f61·7263·6869·7465·6374·7572··ible_architectur000bf0c0:·6962·6c65·5f61·7263·6869·7465·6374·7572··ible_architectur
000bf0d0:·6520·3d3d·2022·7070·6336·3422·206f·7220··e·==·"ppc64"·or·000bf0d0:·6520·3d3d·2022·7070·6336·3422·206f·7220··e·==·"ppc64"·or·
000bf0e0:·616e·7369·626c·655f·6172·6368·6974·6563··ansible_architec000bf0e0:·616e·7369·626c·655f·6172·6368·6974·6563··ansible_architec
000bf0f0:·7475·7265·0a20·2020·203d·3d20·2270·7063··ture.····==·"ppc000bf0f0:·7475·7265·0a20·2020·203d·3d20·2270·7063··ture.····==·"ppc
000bf100:·3634·6c65·2220·6f72·2061·6e73·6962·6c65··64le"·or·ansible000bf100:·3634·6c65·2220·6f72·2061·6e73·6962·6c65··64le"·or·ansible
Offset 49214, 23 lines modifiedOffset 49214, 23 lines modified
000c03d0:·6579·3d70·6572·6d5f·6d6f·640a·2020·2020··ey=perm_mod.····000c03d0:·6579·3d70·6572·6d5f·6d6f·640a·2020·2020··ey=perm_mod.····
000c03e0:·2020·6372·6561·7465·3a20·7472·7565·0a20····create:·true.·000c03e0:·2020·6372·6561·7465·3a20·7472·7565·0a20····create:·true.·
000c03f0:·2020·2020·206d·6f64·653a·206f·2d72·7778·······mode:·o-rwx000c03f0:·2020·2020·206d·6f64·653a·206f·2d72·7778·······mode:·o-rwx
000c0400:·0a20·2020·2020·2073·7461·7465·3a20·7072··.······state:·pr000c0400:·0a20·2020·2020·2073·7461·7465·3a20·7072··.······state:·pr
000c0410:·6573·656e·740a·2020·2020·7768·656e·3a20··esent.····when:·000c0410:·6573·656e·740a·2020·2020·7768·656e·3a20··esent.····when:·
000c0420:·7379·7363·616c·6c73·5f66·6f75·6e64·207c··syscalls_found·|000c0420:·7379·7363·616c·6c73·5f66·6f75·6e64·207c··syscalls_found·|
000c0430:·206c·656e·6774·6820·3d3d·2030·0a20·2077···length·==·0.··w000c0430:·206c·656e·6774·6820·3d3d·2030·0a20·2077···length·==·0.··w
000c0440:·6865·6e3a·0a20·202d·2027·2261·7564·6974··hen:.··-·'"audit000c0440:·6865·6e3a·0a20·202d·2061·6e73·6962·6c65··hen:.··-·ansible
000c0450:·2220·696e·2061·6e73·6962·6c65·5f66·6163··"·in·ansible_fac 
000c0460:·7473·2e70·6163·6b61·6765·7327·0a20·202d··ts.packages'.··- 
000c0470:·2061·6e73·6962·6c65·5f76·6972·7475·616c···ansible_virtual 
000c0480:·697a·6174·696f·6e5f·7479·7065·206e·6f74··ization_type·not 
000c0490:·2069·6e20·5b22·646f·636b·6572·222c·2022···in·["docker",·" 
000c04a0:·6c78·6322·2c20·226f·7065·6e76·7a22·2c20··lxc",·"openvz",· 
000c04b0:·2270·6f64·6d61·6e22·2c20·2263·6f6e·7461··"podman",·"conta000c0450:·5f76·6972·7475·616c·697a·6174·696f·6e5f··_virtualization_
 000c0460:·7479·7065·206e·6f74·2069·6e20·5b22·646f··type·not·in·["do
 000c0470:·636b·6572·222c·2022·6c78·6322·2c20·226f··cker",·"lxc",·"o
 000c0480:·7065·6e76·7a22·2c20·2270·6f64·6d61·6e22··penvz",·"podman"
 000c0490:·2c20·2263·6f6e·7461·696e·6572·225d·0a20··,·"container"].·
 000c04a0:·202d·2027·2261·7564·6974·2220·696e·2061···-·'"audit"·in·a
 000c04b0:·6e73·6962·6c65·5f66·6163·7473·2e70·6163··nsible_facts.pac
000c04c0:·696e·6572·225d·0a20·2074·6167·733a·0a20··iner"].··tags:.·000c04c0:·6b61·6765·7327·0a20·2074·6167·733a·0a20··kages'.··tags:.·
000c04d0:·202d·2043·4a49·532d·352e·342e·312e·310a···-·CJIS-5.4.1.1.000c04d0:·202d·2043·4a49·532d·352e·342e·312e·310a···-·CJIS-5.4.1.1.
000c04e0:·2020·2d20·4449·5341·2d53·5449·472d·5248····-·DISA-STIG-RH000c04e0:·2020·2d20·4449·5341·2d53·5449·472d·5248····-·DISA-STIG-RH
000c04f0:·454c·2d30·382d·3033·3034·3930·0a20·202d··EL-08-030490.··-000c04f0:·454c·2d30·382d·3033·3034·3930·0a20·202d··EL-08-030490.··-
000c0500:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.000c0500:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.
000c0510:·312e·370a·2020·2d20·4e49·5354·2d38·3030··1.7.··-·NIST-800000c0510:·312e·370a·2020·2d20·4e49·5354·2d38·3030··1.7.··-·NIST-800
000c0520:·2d35·332d·4155·2d31·3228·6329·0a20·202d··-53-AU-12(c).··-000c0520:·2d35·332d·4155·2d31·3228·6329·0a20·202d··-53-AU-12(c).··-
000c0530:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-000c0530:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-
Offset 49526, 22 lines modifiedOffset 49526, 22 lines modified
000c1750:·6d5f·6d6f·640a·2020·2020·2020·6372·6561··m_mod.······crea000c1750:·6d5f·6d6f·640a·2020·2020·2020·6372·6561··m_mod.······crea
000c1760:·7465·3a20·7472·7565·0a20·2020·2020·206d··te:·true.······m000c1760:·7465·3a20·7472·7565·0a20·2020·2020·206d··te:·true.······m
000c1770:·6f64·653a·206f·2d72·7778·0a20·2020·2020··ode:·o-rwx.·····000c1770:·6f64·653a·206f·2d72·7778·0a20·2020·2020··ode:·o-rwx.·····
000c1780:·2073·7461·7465·3a20·7072·6573·656e·740a···state:·present.000c1780:·2073·7461·7465·3a20·7072·6573·656e·740a···state:·present.
000c1790:·2020·2020·7768·656e·3a20·7379·7363·616c······when:·syscal000c1790:·2020·2020·7768·656e·3a20·7379·7363·616c······when:·syscal
000c17a0:·6c73·5f66·6f75·6e64·207c·206c·656e·6774··ls_found·|·lengt000c17a0:·6c73·5f66·6f75·6e64·207c·206c·656e·6774··ls_found·|·lengt
000c17b0:·6820·3d3d·2030·0a20·2077·6865·6e3a·0a20··h·==·0.··when:.·000c17b0:·6820·3d3d·2030·0a20·2077·6865·6e3a·0a20··h·==·0.··when:.·
000c17c0:·202d·2027·2261·7564·6974·2220·696e·2061···-·'"audit"·in·a 
000c17d0:·6e73·6962·6c65·5f66·6163·7473·2e70·6163··nsible_facts.pac 
000c17e0:·6b61·6765·7327·0a20·202d·2061·6e73·6962··kages'.··-·ansib 
000c17f0:·6c65·5f76·6972·7475·616c·697a·6174·696f··le_virtualizatio 
000c1800:·6e5f·7479·7065·206e·6f74·2069·6e20·5b22··n_type·not·in·[" 
000c1810:·646f·636b·6572·222c·2022·6c78·6322·2c20··docker",·"lxc",· 
000c1820:·226f·7065·6e76·7a22·2c20·2270·6f64·6d61··"openvz",·"podma 
000c1830:·6e22·2c20·2263·6f6e·7461·696e·6572·225d··n",·"container"]000c17c0:·202d·2061·6e73·6962·6c65·5f76·6972·7475···-·ansible_virtu
 000c17d0:·616c·697a·6174·696f·6e5f·7479·7065·206e··alization_type·n
 000c17e0:·6f74·2069·6e20·5b22·646f·636b·6572·222c··ot·in·["docker",
 000c17f0:·2022·6c78·6322·2c20·226f·7065·6e76·7a22···"lxc",·"openvz"
 000c1800:·2c20·2270·6f64·6d61·6e22·2c20·2263·6f6e··,·"podman",·"con
 000c1810:·7461·696e·6572·225d·0a20·202d·2027·2261··tainer"].··-·'"a
 000c1820:·7564·6974·2220·696e·2061·6e73·6962·6c65··udit"·in·ansible
 000c1830:·5f66·6163·7473·2e70·6163·6b61·6765·7327··_facts.packages'
000c1840:·0a20·202d·2061·7564·6974·5f61·7263·6820··.··-·audit_arch·000c1840:·0a20·202d·2061·7564·6974·5f61·7263·6820··.··-·audit_arch·
000c1850:·3d3d·2022·6236·3422·0a20·2074·6167·733a··==·"b64".··tags:000c1850:·3d3d·2022·6236·3422·0a20·2074·6167·733a··==·"b64".··tags:
000c1860:·0a20·202d·2043·4a49·532d·352e·342e·312e··.··-·CJIS-5.4.1.000c1860:·0a20·202d·2043·4a49·532d·352e·342e·312e··.··-·CJIS-5.4.1.
000c1870:·310a·2020·2d20·4449·5341·2d53·5449·472d··1.··-·DISA-STIG-000c1870:·310a·2020·2d20·4449·5341·2d53·5449·472d··1.··-·DISA-STIG-
000c1880:·5248·454c·2d30·382d·3033·3034·3930·0a20··RHEL-08-030490.·000c1880:·5248·454c·2d30·382d·3033·3034·3930·0a20··RHEL-08-030490.·
000c1890:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-000c1890:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-
000c18a0:·332e·312e·370a·2020·2d20·4e49·5354·2d38··3.1.7.··-·NIST-8000c18a0:·332e·312e·370a·2020·2d20·4e49·5354·2d38··3.1.7.··-·NIST-8
Offset 49575, 21 lines modifiedOffset 49575, 21 lines modified
000c1a60:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla000c1a60:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
000c1a70:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap000c1a70:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
000c1a80:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=000c1a80:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
000c1a90:·2269·646d·3235·3339·3022·3e3c·7072·653e··"idm25390"><pre>000c1a90:·2269·646d·3235·3339·3022·3e3c·7072·653e··"idm25390"><pre>
000c1aa0:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat000c1aa0:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat
000c1ab0:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl000c1ab0:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl
000c1ac0:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai000c1ac0:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai
000c1ad0:·6e20·706c·6174·666f·726d·730a·6966·2072··n·platforms.if·r000c1ad0:·6e20·706c·6174·666f·726d·730a·6966·205b··n·platforms.if·[
000c1ae0:·706d·202d·2d71·7569·6574·202d·7120·6175··pm·--quiet·-q·au 
000c1af0:·6469·7420·2661·6d70·3b26·616d·703b·205b··dit·&amp;&amp;·[ 
000c1b00:·2021·202d·6620·2f2e·646f·636b·6572·656e···!·-f·/.dockeren000c1ae0:·2021·202d·6620·2f2e·646f·636b·6572·656e···!·-f·/.dockeren
000c1b10:·7620·5d20·2661·6d70·3b26·616d·703b·205b··v·]·&amp;&amp;·[000c1af0:·7620·5d20·2661·6d70·3b26·616d·703b·205b··v·]·&amp;&amp;·[
000c1b20:·2021·202d·6620·2f72·756e·2f2e·636f·6e74···!·-f·/run/.cont000c1b00:·2021·202d·6620·2f72·756e·2f2e·636f·6e74···!·-f·/run/.cont
000c1b30:·6169·6e65·7265·6e76·205d·3b20·7468·656e··ainerenv·];·then000c1b10:·6169·6e65·7265·6e76·205d·2026·616d·703b··ainerenv·]·&amp;
 000c1b20:·2661·6d70·3b20·7270·6d20·2d2d·7175·6965··&amp;·rpm·--quie
 000c1b30:·7420·2d71·2061·7564·6974·3b20·7468·656e··t·-q·audit;·then
000c1b40:·0a0a·2320·4669·7273·7420·7065·7266·6f72··..#·First·perfor000c1b40:·0a0a·2320·4669·7273·7420·7065·7266·6f72··..#·First·perfor
000c1b50:·6d20·7468·6520·7265·6d65·6469·6174·696f··m·the·remediatio000c1b50:·6d20·7468·6520·7265·6d65·6469·6174·696f··m·the·remediatio
000c1b60:·6e20·6f66·2074·6865·2073·7973·6361·6c6c··n·of·the·syscall000c1b60:·6e20·6f66·2074·6865·2073·7973·6361·6c6c··n·of·the·syscall
000c1b70:·2072·756c·650a·2320·5265·7472·6965·7665···rule.#·Retrieve000c1b70:·2072·756c·650a·2320·5265·7472·6965·7665···rule.#·Retrieve
Max diff block lines reached; 333764/343278 bytes (97.23%) of diff not shown.
102 KB
html2text {}
    
Offset 73, 15 lines modifiedOffset 73, 15 lines modified
73 ····*·cpe:/o:redhat:enterprise_linux:8.773 ····*·cpe:/o:redhat:enterprise_linux:8.7
74 ····*·cpe:/o:redhat:enterprise_linux:8.874 ····*·cpe:/o:redhat:enterprise_linux:8.8
75 ····*·cpe:/o:redhat:enterprise_linux:8.975 ····*·cpe:/o:redhat:enterprise_linux:8.9
76 ····*·cpe:/o:redhat:enterprise_linux:876 ····*·cpe:/o:redhat:enterprise_linux:8
77 ····*·cpe:/o:centos:centos:877 ····*·cpe:/o:centos:centos:8
78 *****·Revision·History·*****78 *****·Revision·History·*****
79 Current·version:·0.1.6579 Current·version:·0.1.65
80 ····*·draft·(as·of·2024-01-14)80 ····*·draft·(as·of·2025-02-15)
81 *****·Table·of·Contents·*****81 *****·Table·of·Contents·*****
82 ···1.·System_Settings82 ···1.·System_Settings
83 ·········1.·Installing_and_Maintaining_Software83 ·········1.·Installing_and_Maintaining_Software
84 ·········2.·Account_and_Access_Control84 ·········2.·Account_and_Access_Control
85 ·········3.·System_Accounting_with_auditd85 ·········3.·System_Accounting_with_auditd
86 ·········4.·Configure_Syslog86 ·········4.·Configure_Syslog
87 ·········5.·Network_Configuration_and_Firewalls87 ·········5.·Network_Configuration_and_Firewalls
Offset 6401, 16 lines modifiedOffset 6401, 16 lines modified
6401 ··-·reboot_required6401 ··-·reboot_required
6402 ··-·restrict_strategy6402 ··-·restrict_strategy
  
6403 -·name:·Set·architecture·for·audit·chmod·tasks6403 -·name:·Set·architecture·for·audit·chmod·tasks
6404 ··set_fact:6404 ··set_fact:
6405 ····audit_arch:·b646405 ····audit_arch:·b64
6406 ··when:6406 ··when:
6407 ··-·'"audit"·in·ansible_facts.packages' 
6408 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6407 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 6408 ··-·'"audit"·in·ansible_facts.packages'
6409 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture6409 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
6410 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"6410 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
6411 ··tags:6411 ··tags:
6412 ··-·CJIS-5.4.1.16412 ··-·CJIS-5.4.1.1
6413 ··-·DISA-STIG-RHEL-08-0304906413 ··-·DISA-STIG-RHEL-08-030490
6414 ··-·NIST-800-171-3.1.76414 ··-·NIST-800-171-3.1.7
6415 ··-·NIST-800-53-AU-12(c)6415 ··-·NIST-800-53-AU-12(c)
Offset 6547, 16 lines modifiedOffset 6547, 16 lines modified
6547 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10006547 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
6548 ········-F·auid!=unset·-F·key=perm_mod6548 ········-F·auid!=unset·-F·key=perm_mod
6549 ······create:·true6549 ······create:·true
6550 ······mode:·o-rwx6550 ······mode:·o-rwx
6551 ······state:·present6551 ······state:·present
6552 ····when:·syscalls_found·|·length·==·06552 ····when:·syscalls_found·|·length·==·0
6553 ··when:6553 ··when:
6554 ··-·'"audit"·in·ansible_facts.packages' 
6555 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6554 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 6555 ··-·'"audit"·in·ansible_facts.packages'
6556 ··tags:6556 ··tags:
6557 ··-·CJIS-5.4.1.16557 ··-·CJIS-5.4.1.1
6558 ··-·DISA-STIG-RHEL-08-0304906558 ··-·DISA-STIG-RHEL-08-030490
6559 ··-·NIST-800-171-3.1.76559 ··-·NIST-800-171-3.1.7
6560 ··-·NIST-800-53-AU-12(c)6560 ··-·NIST-800-53-AU-12(c)
6561 ··-·NIST-800-53-AU-2(d)6561 ··-·NIST-800-53-AU-2(d)
6562 ··-·NIST-800-53-CM-6(a)6562 ··-·NIST-800-53-CM-6(a)
Offset 6691, 16 lines modifiedOffset 6691, 16 lines modified
6691 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10006691 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
6692 ········-F·auid!=unset·-F·key=perm_mod6692 ········-F·auid!=unset·-F·key=perm_mod
6693 ······create:·true6693 ······create:·true
6694 ······mode:·o-rwx6694 ······mode:·o-rwx
6695 ······state:·present6695 ······state:·present
6696 ····when:·syscalls_found·|·length·==·06696 ····when:·syscalls_found·|·length·==·0
6697 ··when:6697 ··when:
6698 ··-·'"audit"·in·ansible_facts.packages' 
6699 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6698 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 6699 ··-·'"audit"·in·ansible_facts.packages'
6700 ··-·audit_arch·==·"b64"6700 ··-·audit_arch·==·"b64"
6701 ··tags:6701 ··tags:
6702 ··-·CJIS-5.4.1.16702 ··-·CJIS-5.4.1.1
6703 ··-·DISA-STIG-RHEL-08-0304906703 ··-·DISA-STIG-RHEL-08-030490
6704 ··-·NIST-800-171-3.1.76704 ··-·NIST-800-171-3.1.7
6705 ··-·NIST-800-53-AU-12(c)6705 ··-·NIST-800-53-AU-12(c)
6706 ··-·NIST-800-53-AU-2(d)6706 ··-·NIST-800-53-AU-2(d)
Offset 6710, 15 lines modifiedOffset 6710, 15 lines modified
6710 ··-·low_complexity6710 ··-·low_complexity
6711 ··-·low_disruption6711 ··-·low_disruption
6712 ··-·medium_severity6712 ··-·medium_severity
6713 ··-·reboot_required6713 ··-·reboot_required
6714 ··-·restrict_strategy6714 ··-·restrict_strategy
6715 Remediation_Shell_script_⇲6715 Remediation_Shell_script_⇲
6716 #·Remediation·is·applicable·only·in·certain·platforms6716 #·Remediation·is·applicable·only·in·certain·platforms
6717 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then6717 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
6718 #·First·perform·the·remediation·of·the·syscall·rule6718 #·First·perform·the·remediation·of·the·syscall·rule
6719 #·Retrieve·hardware·architecture·of·the·underlying·system6719 #·Retrieve·hardware·architecture·of·the·underlying·system
6720 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")6720 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
6721 for·ARCH·in·"${RULE_ARCHS[@]}"6721 for·ARCH·in·"${RULE_ARCHS[@]}"
6722 do6722 do
Offset 7079, 16 lines modifiedOffset 7079, 16 lines modified
7079 ··-·reboot_required7079 ··-·reboot_required
7080 ··-·restrict_strategy7080 ··-·restrict_strategy
  
7081 -·name:·Set·architecture·for·audit·chown·tasks7081 -·name:·Set·architecture·for·audit·chown·tasks
7082 ··set_fact:7082 ··set_fact:
7083 ····audit_arch:·b647083 ····audit_arch:·b64
7084 ··when:7084 ··when:
7085 ··-·'"audit"·in·ansible_facts.packages' 
7086 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]7085 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 7086 ··-·'"audit"·in·ansible_facts.packages'
7087 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture7087 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
7088 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"7088 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
7089 ··tags:7089 ··tags:
7090 ··-·CJIS-5.4.1.17090 ··-·CJIS-5.4.1.1
7091 ··-·DISA-STIG-RHEL-08-0304807091 ··-·DISA-STIG-RHEL-08-030480
7092 ··-·NIST-800-171-3.1.77092 ··-·NIST-800-171-3.1.7
7093 ··-·NIST-800-53-AU-12(c)7093 ··-·NIST-800-53-AU-12(c)
Offset 7227, 16 lines modifiedOffset 7227, 16 lines modified
7227 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10007227 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
7228 ········-F·auid!=unset·-F·key=perm_mod7228 ········-F·auid!=unset·-F·key=perm_mod
7229 ······create:·true7229 ······create:·true
7230 ······mode:·o-rwx7230 ······mode:·o-rwx
7231 ······state:·present7231 ······state:·present
7232 ····when:·syscalls_found·|·length·==·07232 ····when:·syscalls_found·|·length·==·0
7233 ··when:7233 ··when:
7234 ··-·'"audit"·in·ansible_facts.packages' 
7235 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]7234 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 7235 ··-·'"audit"·in·ansible_facts.packages'
7236 ··tags:7236 ··tags:
7237 ··-·CJIS-5.4.1.17237 ··-·CJIS-5.4.1.1
7238 ··-·DISA-STIG-RHEL-08-0304807238 ··-·DISA-STIG-RHEL-08-030480
7239 ··-·NIST-800-171-3.1.77239 ··-·NIST-800-171-3.1.7
7240 ··-·NIST-800-53-AU-12(c)7240 ··-·NIST-800-53-AU-12(c)
7241 ··-·NIST-800-53-AU-2(d)7241 ··-·NIST-800-53-AU-2(d)
7242 ··-·NIST-800-53-CM-6(a)7242 ··-·NIST-800-53-CM-6(a)
Offset 7373, 16 lines modifiedOffset 7373, 16 lines modified
7373 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10007373 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
7374 ········-F·auid!=unset·-F·key=perm_mod7374 ········-F·auid!=unset·-F·key=perm_mod
7375 ······create:·true7375 ······create:·true
7376 ······mode:·o-rwx7376 ······mode:·o-rwx
7377 ······state:·present7377 ······state:·present
Max diff block lines reached; 99757/104246 bytes (95.69%) of diff not shown.
31.9 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-ospp.html
    
Offset 14555, 15 lines modifiedOffset 14555, 15 lines modified
00038da0:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current00038da0:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current
00038db0:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron00038db0:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron
00038dc0:·673e·302e·312e·3635·3c2f·7374·726f·6e67··g>0.1.65</strong00038dc0:·673e·302e·312e·3635·3c2f·7374·726f·6e67··g>0.1.65</strong
00038dd0:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st00038dd0:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st
00038de0:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro00038de0:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro
00038df0:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············00038df0:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············
00038e00:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·200038e00:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·2
00038e10:·3032·342d·3031·2d31·3429·0a20·2020·2020··024-01-14).·····00038e10:·3032·352d·3032·2d31·3529·0a20·2020·2020··025-02-15).·····
00038e20:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>00038e20:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>
00038e30:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T00038e30:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T
00038e40:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents00038e40:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents
00038e50:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·00038e50:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·
00038e60:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org00038e60:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org
00038e70:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont00038e70:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont
00038e80:·656e·745f·6772·6f75·705f·7379·7374·656d··ent_group_system00038e80:·656e·745f·6772·6f75·705f·7379·7374·656d··ent_group_system
Offset 58474, 23 lines modifiedOffset 58474, 23 lines modified
000e4690:·2020·2072·6567·6578·703a·205e·5c73·2a66·····regexp:·^\s*f000e4690:·2020·2072·6567·6578·703a·205e·5c73·2a66·····regexp:·^\s*f
000e46a0:·6c75·7368·5c73·2a3d·5c73·2a2e·2a24·0a20··lush\s*=\s*.*$.·000e46a0:·6c75·7368·5c73·2a3d·5c73·2a2e·2a24·0a20··lush\s*=\s*.*$.·
000e46b0:·2020·206c·696e·653a·2066·6c75·7368·203d·····line:·flush·=000e46b0:·2020·206c·696e·653a·2066·6c75·7368·203d·····line:·flush·=
000e46c0:·207b·7b20·7661·725f·6175·6469·7464·5f66···{{·var_auditd_f000e46c0:·207b·7b20·7661·725f·6175·6469·7464·5f66···{{·var_auditd_f
000e46d0:·6c75·7368·207d·7d0a·2020·2020·7374·6174··lush·}}.····stat000e46d0:·6c75·7368·207d·7d0a·2020·2020·7374·6174··lush·}}.····stat
000e46e0:·653a·2070·7265·7365·6e74·0a20·2020·2063··e:·present.····c000e46e0:·653a·2070·7265·7365·6e74·0a20·2020·2063··e:·present.····c
000e46f0:·7265·6174·653a·2074·7275·650a·2020·7768··reate:·true.··wh000e46f0:·7265·6174·653a·2074·7275·650a·2020·7768··reate:·true.··wh
000e4700:·656e·3a0a·2020·2d20·2722·6175·6469·7422··en:.··-·'"audit" 
000e4710:·2069·6e20·616e·7369·626c·655f·6661·6374···in·ansible_fact 
000e4720:·732e·7061·636b·6167·6573·270a·2020·2d20··s.packages'.··-· 
000e4730:·616e·7369·626c·655f·7669·7274·7561·6c69··ansible_virtuali 
000e4740:·7a61·7469·6f6e·5f74·7970·6520·6e6f·7420··zation_type·not· 
000e4750:·696e·205b·2264·6f63·6b65·7222·2c20·226c··in·["docker",·"l 
000e4760:·7863·222c·2022·6f70·656e·767a·222c·2022··xc",·"openvz",·" 
000e4770:·706f·646d·616e·222c·2022·636f·6e74·6169··podman",·"contai000e4700:·656e·3a0a·2020·2d20·616e·7369·626c·655f··en:.··-·ansible_
 000e4710:·7669·7274·7561·6c69·7a61·7469·6f6e·5f74··virtualization_t
 000e4720:·7970·6520·6e6f·7420·696e·205b·2264·6f63··ype·not·in·["doc
 000e4730:·6b65·7222·2c20·226c·7863·222c·2022·6f70··ker",·"lxc",·"op
 000e4740:·656e·767a·222c·2022·706f·646d·616e·222c··envz",·"podman",
 000e4750:·2022·636f·6e74·6169·6e65·7222·5d0a·2020···"container"].··
 000e4760:·2d20·2722·6175·6469·7422·2069·6e20·616e··-·'"audit"·in·an
 000e4770:·7369·626c·655f·6661·6374·732e·7061·636b··sible_facts.pack
000e4780:·6e65·7222·5d0a·2020·7461·6773·3a0a·2020··ner"].··tags:.··000e4780:·6167·6573·270a·2020·7461·6773·3a0a·2020··ages'.··tags:.··
000e4790:·2d20·4e49·5354·2d38·3030·2d31·3731·2d33··-·NIST-800-171-3000e4790:·2d20·4e49·5354·2d38·3030·2d31·3731·2d33··-·NIST-800-171-3
000e47a0:·2e33·2e31·0a20·202d·204e·4953·542d·3830··.3.1.··-·NIST-80000e47a0:·2e33·2e31·0a20·202d·204e·4953·542d·3830··.3.1.··-·NIST-80
000e47b0:·302d·3533·2d41·552d·3131·0a20·202d·204e··0-53-AU-11.··-·N000e47b0:·302d·3533·2d41·552d·3131·0a20·202d·204e··0-53-AU-11.··-·N
000e47c0:·4953·542d·3830·302d·3533·2d43·4d2d·3628··IST-800-53-CM-6(000e47c0:·4953·542d·3830·302d·3533·2d43·4d2d·3628··IST-800-53-CM-6(
000e47d0:·6129·0a20·202d·2061·7564·6974·645f·6461··a).··-·auditd_da000e47d0:·6129·0a20·202d·2061·7564·6974·645f·6461··a).··-·auditd_da
000e47e0:·7461·5f72·6574·656e·7469·6f6e·5f66·6c75··ta_retention_flu000e47e0:·7461·5f72·6574·656e·7469·6f6e·5f66·6c75··ta_retention_flu
000e47f0:·7368·0a20·202d·206c·6f77·5f63·6f6d·706c··sh.··-·low_compl000e47f0:·7368·0a20·202d·206c·6f77·5f63·6f6d·706c··sh.··-·low_compl
Offset 58516, 21 lines modifiedOffset 58516, 21 lines modified
000e4930:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel000e4930:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
000e4940:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap000e4940:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
000e4950:·7365·2220·6964·3d22·6964·6d33·3832·3436··se"·id="idm38246000e4950:·7365·2220·6964·3d22·6964·6d33·3832·3436··se"·id="idm38246
000e4960:·223e·3c70·7265·3e3c·636f·6465·3e23·2052··"><pre><code>#·R000e4960:·223e·3c70·7265·3e3c·636f·6465·3e23·2052··"><pre><code>#·R
000e4970:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap000e4970:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap
000e4980:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in000e4980:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in
000e4990:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor000e4990:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor
000e49a0:·6d73·0a69·6620·7270·6d20·2d2d·7175·6965··ms.if·rpm·--quie 
000e49b0:·7420·2d71·2061·7564·6974·2026·616d·703b··t·-q·audit·&amp; 
000e49c0:·2661·6d70·3b20·5b20·2120·2d66·202f·2e64··&amp;·[·!·-f·/.d000e49a0:·6d73·0a69·6620·5b20·2120·2d66·202f·2e64··ms.if·[·!·-f·/.d
000e49d0:·6f63·6b65·7265·6e76·205d·2026·616d·703b··ockerenv·]·&amp;000e49b0:·6f63·6b65·7265·6e76·205d·2026·616d·703b··ockerenv·]·&amp;
000e49e0:·2661·6d70·3b20·5b20·2120·2d66·202f·7275··&amp;·[·!·-f·/ru000e49c0:·2661·6d70·3b20·5b20·2120·2d66·202f·7275··&amp;·[·!·-f·/ru
000e49f0:·6e2f·2e63·6f6e·7461·696e·6572·656e·7620··n/.containerenv·000e49d0:·6e2f·2e63·6f6e·7461·696e·6572·656e·7620··n/.containerenv·
 000e49e0:·5d20·2661·6d70·3b26·616d·703b·2072·706d··]·&amp;&amp;·rpm
 000e49f0:·202d·2d71·7569·6574·202d·7120·6175·6469···--quiet·-q·audi
000e4a00:·5d3b·2074·6865·6e0a·0a76·6172·5f61·7564··];·then..var_aud000e4a00:·743b·2074·6865·6e0a·0a76·6172·5f61·7564··t;·then..var_aud
000e4a10:·6974·645f·666c·7573·683d·273c·6162·6272··itd_flush='<abbr000e4a10:·6974·645f·666c·7573·683d·273c·6162·6272··itd_flush='<abbr
000e4a20:·2074·6974·6c65·3d22·6672·6f6d·2050·726f···title="from·Pro000e4a20:·2074·6974·6c65·3d22·6672·6f6d·2050·726f···title="from·Pro
000e4a30:·6669·6c65·2f72·6566·696e·652d·7661·6c75··file/refine-valu000e4a30:·6669·6c65·2f72·6566·696e·652d·7661·6c75··file/refine-valu
000e4a40:·653a·2078·6363·6466·5f6f·7267·2e73·7367··e:·xccdf_org.ssg000e4a40:·653a·2078·6363·6466·5f6f·7267·2e73·7367··e:·xccdf_org.ssg
000e4a50:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_000e4a50:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_
000e4a60:·7661·6c75·655f·7661·725f·6175·6469·7464··value_var_auditd000e4a60:·7661·6c75·655f·7661·725f·6175·6469·7464··value_var_auditd
000e4a70:·5f66·6c75·7368·223e·696e·6372·656d·656e··_flush">incremen000e4a70:·5f66·6c75·7368·223e·696e·6372·656d·656e··_flush">incremen
Offset 58986, 22 lines modifiedOffset 58986, 22 lines modified
000e6690:·2e63·6f6e·660a·2020·2020·2020·6372·6561··.conf.······crea000e6690:·2e63·6f6e·660a·2020·2020·2020·6372·6561··.conf.······crea
000e66a0:·7465·3a20·7472·7565·0a20·2020·2020·2072··te:·true.······r000e66a0:·7465·3a20·7472·7565·0a20·2020·2020·2072··te:·true.······r
000e66b0:·6567·6578·703a·2028·3f69·295e·5c73·2a66··egexp:·(?i)^\s*f000e66b0:·6567·6578·703a·2028·3f69·295e·5c73·2a66··egexp:·(?i)^\s*f
000e66c0:·7265·715c·732a·3d5c·732a·0a20·2020·2020··req\s*=\s*.·····000e66c0:·7265·715c·732a·3d5c·732a·0a20·2020·2020··req\s*=\s*.·····
000e66d0:·206c·696e·653a·2066·7265·7120·3d20·3530···line:·freq·=·50000e66d0:·206c·696e·653a·2066·7265·7120·3d20·3530···line:·freq·=·50
000e66e0:·0a20·2020·2020·2073·7461·7465·3a20·7072··.······state:·pr000e66e0:·0a20·2020·2020·2073·7461·7465·3a20·7072··.······state:·pr
000e66f0:·6573·656e·740a·2020·7768·656e·3a0a·2020··esent.··when:.··000e66f0:·6573·656e·740a·2020·7768·656e·3a0a·2020··esent.··when:.··
000e6700:·2d20·2722·6175·6469·7422·2069·6e20·616e··-·'"audit"·in·an 
000e6710:·7369·626c·655f·6661·6374·732e·7061·636b··sible_facts.pack 
000e6720:·6167·6573·270a·2020·2d20·616e·7369·626c··ages'.··-·ansibl 
000e6730:·655f·7669·7274·7561·6c69·7a61·7469·6f6e··e_virtualization 
000e6740:·5f74·7970·6520·6e6f·7420·696e·205b·2264··_type·not·in·["d 
000e6750:·6f63·6b65·7222·2c20·226c·7863·222c·2022··ocker",·"lxc",·" 
000e6760:·6f70·656e·767a·222c·2022·706f·646d·616e··openvz",·"podman 
000e6770:·222c·2022·636f·6e74·6169·6e65·7222·5d0a··",·"container"].000e6700:·2d20·616e·7369·626c·655f·7669·7274·7561··-·ansible_virtua
 000e6710:·6c69·7a61·7469·6f6e·5f74·7970·6520·6e6f··lization_type·no
 000e6720:·7420·696e·205b·2264·6f63·6b65·7222·2c20··t·in·["docker",·
 000e6730:·226c·7863·222c·2022·6f70·656e·767a·222c··"lxc",·"openvz",
 000e6740:·2022·706f·646d·616e·222c·2022·636f·6e74···"podman",·"cont
 000e6750:·6169·6e65·7222·5d0a·2020·2d20·2722·6175··ainer"].··-·'"au
 000e6760:·6469·7422·2069·6e20·616e·7369·626c·655f··dit"·in·ansible_
 000e6770:·6661·6374·732e·7061·636b·6167·6573·270a··facts.packages'.
000e6780:·2020·7461·6773·3a0a·2020·2d20·4e49·5354····tags:.··-·NIST000e6780:·2020·7461·6773·3a0a·2020·2d20·4e49·5354····tags:.··-·NIST
000e6790:·2d38·3030·2d35·332d·434d·2d36·0a20·202d··-800-53-CM-6.··-000e6790:·2d38·3030·2d35·332d·434d·2d36·0a20·202d··-800-53-CM-6.··-
000e67a0:·2061·7564·6974·645f·6672·6571·0a20·202d···auditd_freq.··-000e67a0:·2061·7564·6974·645f·6672·6571·0a20·202d···auditd_freq.··-
000e67b0:·206c·6f77·5f63·6f6d·706c·6578·6974·790a···low_complexity.000e67b0:·206c·6f77·5f63·6f6d·706c·6578·6974·790a···low_complexity.
000e67c0:·2020·2d20·6c6f·775f·6469·7372·7570·7469····-·low_disrupti000e67c0:·2020·2d20·6c6f·775f·6469·7372·7570·7469····-·low_disrupti
000e67d0:·6f6e·0a20·202d·206d·6564·6975·6d5f·7365··on.··-·medium_se000e67d0:·6f6e·0a20·202d·206d·6564·6975·6d5f·7365··on.··-·medium_se
000e67e0:·7665·7269·7479·0a20·202d·206e·6f5f·7265··verity.··-·no_re000e67e0:·7665·7269·7479·0a20·202d·206e·6f5f·7265··verity.··-·no_re
Offset 59036, 21 lines modifiedOffset 59036, 21 lines modified
000e69b0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy000e69b0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
000e69c0:·3a3c·2f74·683e·3c74·643e·7265·7374·7269··:</th><td>restri000e69c0:·3a3c·2f74·683e·3c74·643e·7265·7374·7269··:</th><td>restri
000e69d0:·6374·3c2f·7464·3e3c·2f74·723e·3c2f·7461··ct</td></tr></ta000e69d0:·6374·3c2f·7464·3e3c·2f74·723e·3c2f·7461··ct</td></tr></ta
000e69e0:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code>#000e69e0:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code>#
000e69f0:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·000e69f0:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
000e6a00:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·000e6a00:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
000e6a10:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf000e6a10:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
000e6a20:·6f72·6d73·0a69·6620·7270·6d20·2d2d·7175··orms.if·rpm·--qu000e6a20:·6f72·6d73·0a69·6620·5b20·2120·2d66·202f··orms.if·[·!·-f·/
000e6a30:·6965·7420·2d71·2061·7564·6974·2026·616d··iet·-q·audit·&am000e6a30:·2e64·6f63·6b65·7265·6e76·205d·2026·616d··.dockerenv·]·&am
000e6a40:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/000e6a40:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/
000e6a50:·2e64·6f63·6b65·7265·6e76·205d·2026·616d··.dockerenv·]·&am 
000e6a60:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/ 
000e6a70:·7275·6e2f·2e63·6f6e·7461·696e·6572·656e··run/.containeren000e6a50:·7275·6e2f·2e63·6f6e·7461·696e·6572·656e··run/.containeren
 000e6a60:·7620·5d20·2661·6d70·3b26·616d·703b·2072··v·]·&amp;&amp;·r
 000e6a70:·706d·202d·2d71·7569·6574·202d·7120·6175··pm·--quiet·-q·au
000e6a80:·7620·5d3b·2074·6865·6e0a·0a69·6620·5b20··v·];·then..if·[·000e6a80:·6469·743b·2074·6865·6e0a·0a69·6620·5b20··dit;·then..if·[·
000e6a90:·2d65·2022·2f65·7463·2f61·7564·6974·2f61··-e·"/etc/audit/a000e6a90:·2d65·2022·2f65·7463·2f61·7564·6974·2f61··-e·"/etc/audit/a
000e6aa0:·7564·6974·642e·636f·6e66·2220·5d20·3b20··uditd.conf"·]·;·000e6aa0:·7564·6974·642e·636f·6e66·2220·5d20·3b20··uditd.conf"·]·;·
000e6ab0:·7468·656e·0a20·2020·200a·2020·2020·4c43··then.····.····LC000e6ab0:·7468·656e·0a20·2020·200a·2020·2020·4c43··then.····.····LC
000e6ac0:·5f41·4c4c·3d43·2073·6564·202d·6920·222f··_ALL=C·sed·-i·"/000e6ac0:·5f41·4c4c·3d43·2073·6564·202d·6920·222f··_ALL=C·sed·-i·"/
000e6ad0:·5e5c·732a·6672·6571·5c73·2a3d·5c73·2a2f··^\s*freq\s*=\s*/000e6ad0:·5e5c·732a·6672·6571·5c73·2a3d·5c73·2a2f··^\s*freq\s*=\s*/
000e6ae0:·4964·2220·222f·6574·632f·6175·6469·742f··Id"·"/etc/audit/000e6ae0:·4964·2220·222f·6574·632f·6175·6469·742f··Id"·"/etc/audit/
000e6af0:·6175·6469·7464·2e63·6f6e·6622·0a65·6c73··auditd.conf".els000e6af0:·6175·6469·7464·2e63·6f6e·6622·0a65·6c73··auditd.conf".els
Offset 59459, 23 lines modifiedOffset 59459, 23 lines modified
000e8420:·2063·7265·6174·653a·2074·7275·650a·2020···create:·true.··000e8420:·2063·7265·6174·653a·2074·7275·650a·2020···create:·true.··
000e8430:·2020·2020·7265·6765·7870·3a20·283f·6929······regexp:·(?i)000e8430:·2020·2020·7265·6765·7870·3a20·283f·6929······regexp:·(?i)
Max diff block lines reached; 16190/25730 bytes (62.92%) of diff not shown.
6.64 KB
html2text {}
    
Offset 71, 15 lines modifiedOffset 71, 15 lines modified
71 ····*·cpe:/o:redhat:enterprise_linux:8.771 ····*·cpe:/o:redhat:enterprise_linux:8.7
72 ····*·cpe:/o:redhat:enterprise_linux:8.872 ····*·cpe:/o:redhat:enterprise_linux:8.8
73 ····*·cpe:/o:redhat:enterprise_linux:8.973 ····*·cpe:/o:redhat:enterprise_linux:8.9
74 ····*·cpe:/o:redhat:enterprise_linux:874 ····*·cpe:/o:redhat:enterprise_linux:8
75 ····*·cpe:/o:centos:centos:875 ····*·cpe:/o:centos:centos:8
76 *****·Revision·History·*****76 *****·Revision·History·*****
77 Current·version:·0.1.6577 Current·version:·0.1.65
78 ····*·draft·(as·of·2024-01-14)78 ····*·draft·(as·of·2025-02-15)
79 *****·Table·of·Contents·*****79 *****·Table·of·Contents·*****
80 ···1.·System_Settings80 ···1.·System_Settings
81 ·········1.·Installing_and_Maintaining_Software81 ·········1.·Installing_and_Maintaining_Software
82 ·········2.·Account_and_Access_Control82 ·········2.·Account_and_Access_Control
83 ·········3.·System_Accounting_with_auditd83 ·········3.·System_Accounting_with_auditd
84 ·········4.·GRUB2_bootloader_configuration84 ·········4.·GRUB2_bootloader_configuration
85 ·········5.·zIPL_bootloader_configuration85 ·········5.·zIPL_bootloader_configuration
Offset 7761, 29 lines modifiedOffset 7761, 29 lines modified
7761 ··lineinfile:7761 ··lineinfile:
7762 ····dest:·/etc/audit/auditd.conf7762 ····dest:·/etc/audit/auditd.conf
7763 ····regexp:·^\s*flush\s*=\s*.*$7763 ····regexp:·^\s*flush\s*=\s*.*$
7764 ····line:·flush·=·{{·var_auditd_flush·}}7764 ····line:·flush·=·{{·var_auditd_flush·}}
7765 ····state:·present7765 ····state:·present
7766 ····create:·true7766 ····create:·true
7767 ··when:7767 ··when:
7768 ··-·'"audit"·in·ansible_facts.packages' 
7769 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]7768 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 7769 ··-·'"audit"·in·ansible_facts.packages'
7770 ··tags:7770 ··tags:
7771 ··-·NIST-800-171-3.3.17771 ··-·NIST-800-171-3.3.1
7772 ··-·NIST-800-53-AU-117772 ··-·NIST-800-53-AU-11
7773 ··-·NIST-800-53-CM-6(a)7773 ··-·NIST-800-53-CM-6(a)
7774 ··-·auditd_data_retention_flush7774 ··-·auditd_data_retention_flush
7775 ··-·low_complexity7775 ··-·low_complexity
7776 ··-·low_disruption7776 ··-·low_disruption
7777 ··-·medium_severity7777 ··-·medium_severity
7778 ··-·no_reboot_needed7778 ··-·no_reboot_needed
7779 ··-·restrict_strategy7779 ··-·restrict_strategy
7780 Remediation_Shell_script_⇲7780 Remediation_Shell_script_⇲
7781 #·Remediation·is·applicable·only·in·certain·platforms7781 #·Remediation·is·applicable·only·in·certain·platforms
7782 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then7782 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
7783 var_auditd_flush='incremental_async'7783 var_auditd_flush='incremental_async'
  
  
7784 AUDITCONFIG=/etc/audit/auditd.conf7784 AUDITCONFIG=/etc/audit/auditd.conf
  
7785 #·if·flush·is·present,·flush·param·edited·to·var_auditd_flush7785 #·if·flush·is·present,·flush·param·edited·to·var_auditd_flush
Offset 7880, 30 lines modifiedOffset 7880, 30 lines modified
7880 ····lineinfile:7880 ····lineinfile:
7881 ······path:·/etc/audit/auditd.conf7881 ······path:·/etc/audit/auditd.conf
7882 ······create:·true7882 ······create:·true
7883 ······regexp:·(?i)^\s*freq\s*=\s*7883 ······regexp:·(?i)^\s*freq\s*=\s*
7884 ······line:·freq·=·507884 ······line:·freq·=·50
7885 ······state:·present7885 ······state:·present
7886 ··when:7886 ··when:
7887 ··-·'"audit"·in·ansible_facts.packages' 
7888 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]7887 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 7888 ··-·'"audit"·in·ansible_facts.packages'
7889 ··tags:7889 ··tags:
7890 ··-·NIST-800-53-CM-67890 ··-·NIST-800-53-CM-6
7891 ··-·auditd_freq7891 ··-·auditd_freq
7892 ··-·low_complexity7892 ··-·low_complexity
7893 ··-·low_disruption7893 ··-·low_disruption
7894 ··-·medium_severity7894 ··-·medium_severity
7895 ··-·no_reboot_needed7895 ··-·no_reboot_needed
7896 ··-·restrict_strategy7896 ··-·restrict_strategy
7897 Remediation_Shell_script_⇲7897 Remediation_Shell_script_⇲
7898 Complexity:·low7898 Complexity:·low
7899 Disruption:·low7899 Disruption:·low
7900 Strategy:···restrict7900 Strategy:···restrict
7901 #·Remediation·is·applicable·only·in·certain·platforms7901 #·Remediation·is·applicable·only·in·certain·platforms
7902 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then7902 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
7903 if·[·-e·"/etc/audit/auditd.conf"·]·;·then7903 if·[·-e·"/etc/audit/auditd.conf"·]·;·then
  
7904 ····LC_ALL=C·sed·-i·"/^\s*freq\s*=\s*/Id"·"/etc/audit/auditd.conf"7904 ····LC_ALL=C·sed·-i·"/^\s*freq\s*=\s*/Id"·"/etc/audit/auditd.conf"
7905 else7905 else
7906 ····touch·"/etc/audit/auditd.conf"7906 ····touch·"/etc/audit/auditd.conf"
7907 fi7907 fi
Offset 7986, 31 lines modifiedOffset 7986, 31 lines modified
7986 ····lineinfile:7986 ····lineinfile:
7987 ······path:·/etc/audit/auditd.conf7987 ······path:·/etc/audit/auditd.conf
7988 ······create:·true7988 ······create:·true
7989 ······regexp:·(?i)^\s*local_events\s*=\s*7989 ······regexp:·(?i)^\s*local_events\s*=\s*
7990 ······line:·local_events·=·yes7990 ······line:·local_events·=·yes
7991 ······state:·present7991 ······state:·present
7992 ··when:7992 ··when:
7993 ··-·'"audit"·in·ansible_facts.packages' 
7994 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]7993 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 7994 ··-·'"audit"·in·ansible_facts.packages'
7995 ··tags:7995 ··tags:
7996 ··-·DISA-STIG-RHEL-08-0300617996 ··-·DISA-STIG-RHEL-08-030061
7997 ··-·NIST-800-53-CM-67997 ··-·NIST-800-53-CM-6
7998 ··-·auditd_local_events7998 ··-·auditd_local_events
7999 ··-·low_complexity7999 ··-·low_complexity
8000 ··-·low_disruption8000 ··-·low_disruption
8001 ··-·medium_severity8001 ··-·medium_severity
8002 ··-·no_reboot_needed8002 ··-·no_reboot_needed
8003 ··-·restrict_strategy8003 ··-·restrict_strategy
8004 Remediation_Shell_script_⇲8004 Remediation_Shell_script_⇲
8005 Complexity:·low8005 Complexity:·low
8006 Disruption:·low8006 Disruption:·low
8007 Strategy:···restrict8007 Strategy:···restrict
8008 #·Remediation·is·applicable·only·in·certain·platforms8008 #·Remediation·is·applicable·only·in·certain·platforms
8009 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then8009 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
8010 if·[·-e·"/etc/audit/auditd.conf"·]·;·then8010 if·[·-e·"/etc/audit/auditd.conf"·]·;·then
  
8011 ····LC_ALL=C·sed·-i·"/^\s*local_events\s*=\s*/Id"·"/etc/audit/auditd.conf"8011 ····LC_ALL=C·sed·-i·"/^\s*local_events\s*=\s*/Id"·"/etc/audit/auditd.conf"
8012 else8012 else
8013 ····touch·"/etc/audit/auditd.conf"8013 ····touch·"/etc/audit/auditd.conf"
8014 fi8014 fi
Offset 8094, 16 lines modifiedOffset 8094, 16 lines modified
8094 ····lineinfile:8094 ····lineinfile:
8095 ······path:·/etc/audit/auditd.conf8095 ······path:·/etc/audit/auditd.conf
8096 ······create:·true8096 ······create:·true
8097 ······regexp:·(?i)^\s*log_format\s*=\s*8097 ······regexp:·(?i)^\s*log_format\s*=\s*
8098 ······line:·log_format·=·ENRICHED8098 ······line:·log_format·=·ENRICHED
8099 ······state:·present8099 ······state:·present
8100 ··when:8100 ··when:
8101 ··-·'"audit"·in·ansible_facts.packages' 
8102 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8101 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 8102 ··-·'"audit"·in·ansible_facts.packages'
8103 ··tags:8103 ··tags:
8104 ··-·DISA-STIG-RHEL-08-0300638104 ··-·DISA-STIG-RHEL-08-030063
8105 ··-·NIST-800-53-AU-38105 ··-·NIST-800-53-AU-3
8106 ··-·NIST-800-53-CM-68106 ··-·NIST-800-53-CM-6
8107 ··-·auditd_log_format8107 ··-·auditd_log_format
Max diff block lines reached; 2647/6779 bytes (39.05%) of diff not shown.
804 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-pci-dss.html
    
Offset 14532, 15 lines modifiedOffset 14532, 15 lines modified
00038c30:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C00038c30:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C
00038c40:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·00038c40:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·
00038c50:·3c73·7472·6f6e·673e·302e·312e·3635·3c2f··<strong>0.1.65</00038c50:·3c73·7472·6f6e·673e·302e·312e·3635·3c2f··<strong>0.1.65</
00038c60:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><00038c60:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><
00038c70:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft00038c70:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft
00038c80:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······00038c80:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······
00038c90:·2020·2020·2020·2020·2020·2020·2020·2861················(a00038c90:·2020·2020·2020·2020·2020·2020·2020·2861················(a
00038ca0:·7320·6f66·2032·3032·342d·3031·2d31·3429··s·of·2024-01-14)00038ca0:·7320·6f66·2032·3032·352d·3032·2d31·3529··s·of·2025-02-15)
00038cb0:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00038cb0:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00038cc0:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div00038cc0:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div
00038cd0:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co00038cd0:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co
00038ce0:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><00038ce0:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><
00038cf0:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc00038cf0:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc
00038d00:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec00038d00:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec
00038d10:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_00038d10:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_
Offset 54634, 23 lines modifiedOffset 54634, 23 lines modified
000d5690:·5f72·6571·7569·7265·640a·2020·2d20·7265··_required.··-·re000d5690:·5f72·6571·7569·7265·640a·2020·2d20·7265··_required.··-·re
000d56a0:·7374·7269·6374·5f73·7472·6174·6567·790a··strict_strategy.000d56a0:·7374·7269·6374·5f73·7472·6174·6567·790a··strict_strategy.
000d56b0:·0a2d·206e·616d·653a·2053·6574·2061·7263··.-·name:·Set·arc000d56b0:·0a2d·206e·616d·653a·2053·6574·2061·7263··.-·name:·Set·arc
000d56c0:·6869·7465·6374·7572·6520·666f·7220·6175··hitecture·for·au000d56c0:·6869·7465·6374·7572·6520·666f·7220·6175··hitecture·for·au
000d56d0:·6469·7420·6368·6d6f·6420·7461·736b·730a··dit·chmod·tasks.000d56d0:·6469·7420·6368·6d6f·6420·7461·736b·730a··dit·chmod·tasks.
000d56e0:·2020·7365·745f·6661·6374·3a0a·2020·2020····set_fact:.····000d56e0:·2020·7365·745f·6661·6374·3a0a·2020·2020····set_fact:.····
000d56f0:·6175·6469·745f·6172·6368·3a20·6236·340a··audit_arch:·b64.000d56f0:·6175·6469·745f·6172·6368·3a20·6236·340a··audit_arch:·b64.
000d5700:·2020·7768·656e·3a0a·2020·2d20·2722·6175····when:.··-·'"au000d5700:·2020·7768·656e·3a0a·2020·2d20·616e·7369····when:.··-·ansi
000d5710:·6469·7422·2069·6e20·616e·7369·626c·655f··dit"·in·ansible_ 
000d5720:·6661·6374·732e·7061·636b·6167·6573·270a··facts.packages'. 
000d5730:·2020·2d20·616e·7369·626c·655f·7669·7274····-·ansible_virt 
000d5740:·7561·6c69·7a61·7469·6f6e·5f74·7970·6520··ualization_type· 
000d5750:·6e6f·7420·696e·205b·2264·6f63·6b65·7222··not·in·["docker" 
000d5760:·2c20·226c·7863·222c·2022·6f70·656e·767a··,·"lxc",·"openvz 
000d5770:·222c·2022·706f·646d·616e·222c·2022·636f··",·"podman",·"co 
000d5780:·6e74·6169·6e65·7222·5d0a·2020·2d20·616e··ntainer"].··-·an000d5710:·626c·655f·7669·7274·7561·6c69·7a61·7469··ble_virtualizati
 000d5720:·6f6e·5f74·7970·6520·6e6f·7420·696e·205b··on_type·not·in·[
 000d5730:·2264·6f63·6b65·7222·2c20·226c·7863·222c··"docker",·"lxc",
 000d5740:·2022·6f70·656e·767a·222c·2022·706f·646d···"openvz",·"podm
 000d5750:·616e·222c·2022·636f·6e74·6169·6e65·7222··an",·"container"
 000d5760:·5d0a·2020·2d20·2722·6175·6469·7422·2069··].··-·'"audit"·i
 000d5770:·6e20·616e·7369·626c·655f·6661·6374·732e··n·ansible_facts.
 000d5780:·7061·636b·6167·6573·270a·2020·2d20·616e··packages'.··-·an
000d5790:·7369·626c·655f·6172·6368·6974·6563·7475··sible_architectu000d5790:·7369·626c·655f·6172·6368·6974·6563·7475··sible_architectu
000d57a0:·7265·203d·3d20·2261·6172·6368·3634·2220··re·==·"aarch64"·000d57a0:·7265·203d·3d20·2261·6172·6368·3634·2220··re·==·"aarch64"·
000d57b0:·6f72·2061·6e73·6962·6c65·5f61·7263·6869··or·ansible_archi000d57b0:·6f72·2061·6e73·6962·6c65·5f61·7263·6869··or·ansible_archi
000d57c0:·7465·6374·7572·6520·3d3d·2022·7070·6336··tecture·==·"ppc6000d57c0:·7465·6374·7572·6520·3d3d·2022·7070·6336··tecture·==·"ppc6
000d57d0:·3422·206f·7220·616e·7369·626c·655f·6172··4"·or·ansible_ar000d57d0:·3422·206f·7220·616e·7369·626c·655f·6172··4"·or·ansible_ar
000d57e0:·6368·6974·6563·7475·7265·0a20·2020·203d··chitecture.····=000d57e0:·6368·6974·6563·7475·7265·0a20·2020·203d··chitecture.····=
000d57f0:·3d20·2270·7063·3634·6c65·2220·6f72·2061··=·"ppc64le"·or·a000d57f0:·3d20·2270·7063·3634·6c65·2220·6f72·2061··=·"ppc64le"·or·a
Offset 54957, 23 lines modifiedOffset 54957, 23 lines modified
000d6ac0:·7420·2d46·206b·6579·3d70·6572·6d5f·6d6f··t·-F·key=perm_mo000d6ac0:·7420·2d46·206b·6579·3d70·6572·6d5f·6d6f··t·-F·key=perm_mo
000d6ad0:·640a·2020·2020·2020·6372·6561·7465·3a20··d.······create:·000d6ad0:·640a·2020·2020·2020·6372·6561·7465·3a20··d.······create:·
000d6ae0:·7472·7565·0a20·2020·2020·206d·6f64·653a··true.······mode:000d6ae0:·7472·7565·0a20·2020·2020·206d·6f64·653a··true.······mode:
000d6af0:·206f·2d72·7778·0a20·2020·2020·2073·7461···o-rwx.······sta000d6af0:·206f·2d72·7778·0a20·2020·2020·2073·7461···o-rwx.······sta
000d6b00:·7465·3a20·7072·6573·656e·740a·2020·2020··te:·present.····000d6b00:·7465·3a20·7072·6573·656e·740a·2020·2020··te:·present.····
000d6b10:·7768·656e·3a20·7379·7363·616c·6c73·5f66··when:·syscalls_f000d6b10:·7768·656e·3a20·7379·7363·616c·6c73·5f66··when:·syscalls_f
000d6b20:·6f75·6e64·207c·206c·656e·6774·6820·3d3d··ound·|·length·==000d6b20:·6f75·6e64·207c·206c·656e·6774·6820·3d3d··ound·|·length·==
000d6b30:·2030·0a20·2077·6865·6e3a·0a20·202d·2027···0.··when:.··-·'000d6b30:·2030·0a20·2077·6865·6e3a·0a20·202d·2061···0.··when:.··-·a
000d6b40:·2261·7564·6974·2220·696e·2061·6e73·6962··"audit"·in·ansib 
000d6b50:·6c65·5f66·6163·7473·2e70·6163·6b61·6765··le_facts.package 
000d6b60:·7327·0a20·202d·2061·6e73·6962·6c65·5f76··s'.··-·ansible_v 
000d6b70:·6972·7475·616c·697a·6174·696f·6e5f·7479··irtualization_ty 
000d6b80:·7065·206e·6f74·2069·6e20·5b22·646f·636b··pe·not·in·["dock 
000d6b90:·6572·222c·2022·6c78·6322·2c20·226f·7065··er",·"lxc",·"ope 
000d6ba0:·6e76·7a22·2c20·2270·6f64·6d61·6e22·2c20··nvz",·"podman",· 
000d6bb0:·2263·6f6e·7461·696e·6572·225d·0a20·2074··"container"].··t000d6b40:·6e73·6962·6c65·5f76·6972·7475·616c·697a··nsible_virtualiz
 000d6b50:·6174·696f·6e5f·7479·7065·206e·6f74·2069··ation_type·not·i
 000d6b60:·6e20·5b22·646f·636b·6572·222c·2022·6c78··n·["docker",·"lx
 000d6b70:·6322·2c20·226f·7065·6e76·7a22·2c20·2270··c",·"openvz",·"p
 000d6b80:·6f64·6d61·6e22·2c20·2263·6f6e·7461·696e··odman",·"contain
 000d6b90:·6572·225d·0a20·202d·2027·2261·7564·6974··er"].··-·'"audit
 000d6ba0:·2220·696e·2061·6e73·6962·6c65·5f66·6163··"·in·ansible_fac
 000d6bb0:·7473·2e70·6163·6b61·6765·7327·0a20·2074··ts.packages'.··t
000d6bc0:·6167·733a·0a20·202d·2043·4a49·532d·352e··ags:.··-·CJIS-5.000d6bc0:·6167·733a·0a20·202d·2043·4a49·532d·352e··ags:.··-·CJIS-5.
000d6bd0:·342e·312e·310a·2020·2d20·4449·5341·2d53··4.1.1.··-·DISA-S000d6bd0:·342e·312e·310a·2020·2d20·4449·5341·2d53··4.1.1.··-·DISA-S
000d6be0:·5449·472d·5248·454c·2d30·382d·3033·3034··TIG-RHEL-08-0304000d6be0:·5449·472d·5248·454c·2d30·382d·3033·3034··TIG-RHEL-08-0304
000d6bf0:·3930·0a20·202d·204e·4953·542d·3830·302d··90.··-·NIST-800-000d6bf0:·3930·0a20·202d·204e·4953·542d·3830·302d··90.··-·NIST-800-
000d6c00:·3137·312d·332e·312e·370a·2020·2d20·4e49··171-3.1.7.··-·NI000d6c00:·3137·312d·332e·312e·370a·2020·2d20·4e49··171-3.1.7.··-·NI
000d6c10:·5354·2d38·3030·2d35·332d·4155·2d31·3228··ST-800-53-AU-12(000d6c10:·5354·2d38·3030·2d35·332d·4155·2d31·3228··ST-800-53-AU-12(
000d6c20:·6329·0a20·202d·204e·4953·542d·3830·302d··c).··-·NIST-800-000d6c20:·6329·0a20·202d·204e·4953·542d·3830·302d··c).··-·NIST-800-
Offset 55269, 23 lines modifiedOffset 55269, 23 lines modified
000d7e40:·6579·3d70·6572·6d5f·6d6f·640a·2020·2020··ey=perm_mod.····000d7e40:·6579·3d70·6572·6d5f·6d6f·640a·2020·2020··ey=perm_mod.····
000d7e50:·2020·6372·6561·7465·3a20·7472·7565·0a20····create:·true.·000d7e50:·2020·6372·6561·7465·3a20·7472·7565·0a20····create:·true.·
000d7e60:·2020·2020·206d·6f64·653a·206f·2d72·7778·······mode:·o-rwx000d7e60:·2020·2020·206d·6f64·653a·206f·2d72·7778·······mode:·o-rwx
000d7e70:·0a20·2020·2020·2073·7461·7465·3a20·7072··.······state:·pr000d7e70:·0a20·2020·2020·2073·7461·7465·3a20·7072··.······state:·pr
000d7e80:·6573·656e·740a·2020·2020·7768·656e·3a20··esent.····when:·000d7e80:·6573·656e·740a·2020·2020·7768·656e·3a20··esent.····when:·
000d7e90:·7379·7363·616c·6c73·5f66·6f75·6e64·207c··syscalls_found·|000d7e90:·7379·7363·616c·6c73·5f66·6f75·6e64·207c··syscalls_found·|
000d7ea0:·206c·656e·6774·6820·3d3d·2030·0a20·2077···length·==·0.··w000d7ea0:·206c·656e·6774·6820·3d3d·2030·0a20·2077···length·==·0.··w
000d7eb0:·6865·6e3a·0a20·202d·2027·2261·7564·6974··hen:.··-·'"audit000d7eb0:·6865·6e3a·0a20·202d·2061·6e73·6962·6c65··hen:.··-·ansible
000d7ec0:·2220·696e·2061·6e73·6962·6c65·5f66·6163··"·in·ansible_fac 
000d7ed0:·7473·2e70·6163·6b61·6765·7327·0a20·202d··ts.packages'.··- 
000d7ee0:·2061·6e73·6962·6c65·5f76·6972·7475·616c···ansible_virtual 
000d7ef0:·697a·6174·696f·6e5f·7479·7065·206e·6f74··ization_type·not 
000d7f00:·2069·6e20·5b22·646f·636b·6572·222c·2022···in·["docker",·" 
000d7f10:·6c78·6322·2c20·226f·7065·6e76·7a22·2c20··lxc",·"openvz",· 
000d7f20:·2270·6f64·6d61·6e22·2c20·2263·6f6e·7461··"podman",·"conta000d7ec0:·5f76·6972·7475·616c·697a·6174·696f·6e5f··_virtualization_
 000d7ed0:·7479·7065·206e·6f74·2069·6e20·5b22·646f··type·not·in·["do
 000d7ee0:·636b·6572·222c·2022·6c78·6322·2c20·226f··cker",·"lxc",·"o
 000d7ef0:·7065·6e76·7a22·2c20·2270·6f64·6d61·6e22··penvz",·"podman"
 000d7f00:·2c20·2263·6f6e·7461·696e·6572·225d·0a20··,·"container"].·
 000d7f10:·202d·2027·2261·7564·6974·2220·696e·2061···-·'"audit"·in·a
 000d7f20:·6e73·6962·6c65·5f66·6163·7473·2e70·6163··nsible_facts.pac
000d7f30:·696e·6572·225d·0a20·202d·2061·7564·6974··iner"].··-·audit000d7f30:·6b61·6765·7327·0a20·202d·2061·7564·6974··kages'.··-·audit
000d7f40:·5f61·7263·6820·3d3d·2022·6236·3422·0a20··_arch·==·"b64".·000d7f40:·5f61·7263·6820·3d3d·2022·6236·3422·0a20··_arch·==·"b64".·
000d7f50:·2074·6167·733a·0a20·202d·2043·4a49·532d···tags:.··-·CJIS-000d7f50:·2074·6167·733a·0a20·202d·2043·4a49·532d···tags:.··-·CJIS-
000d7f60:·352e·342e·312e·310a·2020·2d20·4449·5341··5.4.1.1.··-·DISA000d7f60:·352e·342e·312e·310a·2020·2d20·4449·5341··5.4.1.1.··-·DISA
000d7f70:·2d53·5449·472d·5248·454c·2d30·382d·3033··-STIG-RHEL-08-03000d7f70:·2d53·5449·472d·5248·454c·2d30·382d·3033··-STIG-RHEL-08-03
000d7f80:·3034·3930·0a20·202d·204e·4953·542d·3830··0490.··-·NIST-80000d7f80:·3034·3930·0a20·202d·204e·4953·542d·3830··0490.··-·NIST-80
000d7f90:·302d·3137·312d·332e·312e·370a·2020·2d20··0-171-3.1.7.··-·000d7f90:·302d·3137·312d·332e·312e·370a·2020·2d20··0-171-3.1.7.··-·
000d7fa0:·4e49·5354·2d38·3030·2d35·332d·4155·2d31··NIST-800-53-AU-1000d7fa0:·4e49·5354·2d38·3030·2d35·332d·4155·2d31··NIST-800-53-AU-1
Offset 55319, 20 lines modifiedOffset 55319, 20 lines modified
000d8160:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-000d8160:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
000d8170:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps000d8170:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
000d8180:·6522·2069·643d·2269·646d·3235·3339·3022··e"·id="idm25390"000d8180:·6522·2069·643d·2269·646d·3235·3339·3022··e"·id="idm25390"
000d8190:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re000d8190:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re
000d81a0:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app000d81a0:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app
000d81b0:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in·000d81b0:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in·
000d81c0:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform000d81c0:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform
000d81d0:·730a·6966·2072·706d·202d·2d71·7569·6574··s.if·rpm·--quiet 
000d81e0:·202d·7120·6175·6469·7420·2661·6d70·3b26···-q·audit·&amp;& 
000d81f0:·616d·703b·205b·2021·202d·6620·2f2e·646f··amp;·[·!·-f·/.do000d81d0:·730a·6966·205b·2021·202d·6620·2f2e·646f··s.if·[·!·-f·/.do
000d8200:·636b·6572·656e·7620·5d20·2661·6d70·3b26··ckerenv·]·&amp;&000d81e0:·636b·6572·656e·7620·5d20·2661·6d70·3b26··ckerenv·]·&amp;&
000d8210:·616d·703b·205b·2021·202d·6620·2f72·756e··amp;·[·!·-f·/run000d81f0:·616d·703b·205b·2021·202d·6620·2f72·756e··amp;·[·!·-f·/run
000d8220:·2f2e·636f·6e74·6169·6e65·7265·6e76·205d··/.containerenv·]000d8200:·2f2e·636f·6e74·6169·6e65·7265·6e76·205d··/.containerenv·]
 000d8210:·2026·616d·703b·2661·6d70·3b20·7270·6d20···&amp;&amp;·rpm·
 000d8220:·2d2d·7175·6965·7420·2d71·2061·7564·6974··--quiet·-q·audit
000d8230:·3b20·7468·656e·0a0a·2320·4669·7273·7420··;·then..#·First·000d8230:·3b20·7468·656e·0a0a·2320·4669·7273·7420··;·then..#·First·
000d8240:·7065·7266·6f72·6d20·7468·6520·7265·6d65··perform·the·reme000d8240:·7065·7266·6f72·6d20·7468·6520·7265·6d65··perform·the·reme
000d8250:·6469·6174·696f·6e20·6f66·2074·6865·2073··diation·of·the·s000d8250:·6469·6174·696f·6e20·6f66·2074·6865·2073··diation·of·the·s
000d8260:·7973·6361·6c6c·2072·756c·650a·2320·5265··yscall·rule.#·Re000d8260:·7973·6361·6c6c·2072·756c·650a·2320·5265··yscall·rule.#·Re
Max diff block lines reached; 625407/634921 bytes (98.50%) of diff not shown.
184 KB
html2text {}
    
Offset 66, 15 lines modifiedOffset 66, 15 lines modified
66 ····*·cpe:/o:redhat:enterprise_linux:8.766 ····*·cpe:/o:redhat:enterprise_linux:8.7
67 ····*·cpe:/o:redhat:enterprise_linux:8.867 ····*·cpe:/o:redhat:enterprise_linux:8.8
68 ····*·cpe:/o:redhat:enterprise_linux:8.968 ····*·cpe:/o:redhat:enterprise_linux:8.9
69 ····*·cpe:/o:redhat:enterprise_linux:869 ····*·cpe:/o:redhat:enterprise_linux:8
70 ····*·cpe:/o:centos:centos:870 ····*·cpe:/o:centos:centos:8
71 *****·Revision·History·*****71 *****·Revision·History·*****
72 Current·version:·0.1.6572 Current·version:·0.1.65
73 ····*·draft·(as·of·2024-01-14)73 ····*·draft·(as·of·2025-02-15)
74 *****·Table·of·Contents·*****74 *****·Table·of·Contents·*****
75 ···1.·System_Settings75 ···1.·System_Settings
76 ·········1.·Installing_and_Maintaining_Software76 ·········1.·Installing_and_Maintaining_Software
77 ·········2.·Account_and_Access_Control77 ·········2.·Account_and_Access_Control
78 ·········3.·System_Accounting_with_auditd78 ·········3.·System_Accounting_with_auditd
79 ·········4.·GRUB2_bootloader_configuration79 ·········4.·GRUB2_bootloader_configuration
80 ·········5.·Configure_Syslog80 ·········5.·Configure_Syslog
Offset 7375, 16 lines modifiedOffset 7375, 16 lines modified
7375 ··-·reboot_required7375 ··-·reboot_required
7376 ··-·restrict_strategy7376 ··-·restrict_strategy
  
7377 -·name:·Set·architecture·for·audit·chmod·tasks7377 -·name:·Set·architecture·for·audit·chmod·tasks
7378 ··set_fact:7378 ··set_fact:
7379 ····audit_arch:·b647379 ····audit_arch:·b64
7380 ··when:7380 ··when:
7381 ··-·'"audit"·in·ansible_facts.packages' 
7382 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]7381 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 7382 ··-·'"audit"·in·ansible_facts.packages'
7383 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture7383 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
7384 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"7384 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
7385 ··tags:7385 ··tags:
7386 ··-·CJIS-5.4.1.17386 ··-·CJIS-5.4.1.1
7387 ··-·DISA-STIG-RHEL-08-0304907387 ··-·DISA-STIG-RHEL-08-030490
7388 ··-·NIST-800-171-3.1.77388 ··-·NIST-800-171-3.1.7
7389 ··-·NIST-800-53-AU-12(c)7389 ··-·NIST-800-53-AU-12(c)
Offset 7521, 16 lines modifiedOffset 7521, 16 lines modified
7521 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10007521 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
7522 ········-F·auid!=unset·-F·key=perm_mod7522 ········-F·auid!=unset·-F·key=perm_mod
7523 ······create:·true7523 ······create:·true
7524 ······mode:·o-rwx7524 ······mode:·o-rwx
7525 ······state:·present7525 ······state:·present
7526 ····when:·syscalls_found·|·length·==·07526 ····when:·syscalls_found·|·length·==·0
7527 ··when:7527 ··when:
7528 ··-·'"audit"·in·ansible_facts.packages' 
7529 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]7528 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 7529 ··-·'"audit"·in·ansible_facts.packages'
7530 ··tags:7530 ··tags:
7531 ··-·CJIS-5.4.1.17531 ··-·CJIS-5.4.1.1
7532 ··-·DISA-STIG-RHEL-08-0304907532 ··-·DISA-STIG-RHEL-08-030490
7533 ··-·NIST-800-171-3.1.77533 ··-·NIST-800-171-3.1.7
7534 ··-·NIST-800-53-AU-12(c)7534 ··-·NIST-800-53-AU-12(c)
7535 ··-·NIST-800-53-AU-2(d)7535 ··-·NIST-800-53-AU-2(d)
7536 ··-·NIST-800-53-CM-6(a)7536 ··-·NIST-800-53-CM-6(a)
Offset 7665, 16 lines modifiedOffset 7665, 16 lines modified
7665 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10007665 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
7666 ········-F·auid!=unset·-F·key=perm_mod7666 ········-F·auid!=unset·-F·key=perm_mod
7667 ······create:·true7667 ······create:·true
7668 ······mode:·o-rwx7668 ······mode:·o-rwx
7669 ······state:·present7669 ······state:·present
7670 ····when:·syscalls_found·|·length·==·07670 ····when:·syscalls_found·|·length·==·0
7671 ··when:7671 ··when:
7672 ··-·'"audit"·in·ansible_facts.packages' 
7673 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]7672 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 7673 ··-·'"audit"·in·ansible_facts.packages'
7674 ··-·audit_arch·==·"b64"7674 ··-·audit_arch·==·"b64"
7675 ··tags:7675 ··tags:
7676 ··-·CJIS-5.4.1.17676 ··-·CJIS-5.4.1.1
7677 ··-·DISA-STIG-RHEL-08-0304907677 ··-·DISA-STIG-RHEL-08-030490
7678 ··-·NIST-800-171-3.1.77678 ··-·NIST-800-171-3.1.7
7679 ··-·NIST-800-53-AU-12(c)7679 ··-·NIST-800-53-AU-12(c)
7680 ··-·NIST-800-53-AU-2(d)7680 ··-·NIST-800-53-AU-2(d)
Offset 7684, 15 lines modifiedOffset 7684, 15 lines modified
7684 ··-·low_complexity7684 ··-·low_complexity
7685 ··-·low_disruption7685 ··-·low_disruption
7686 ··-·medium_severity7686 ··-·medium_severity
7687 ··-·reboot_required7687 ··-·reboot_required
7688 ··-·restrict_strategy7688 ··-·restrict_strategy
7689 Remediation_Shell_script_⇲7689 Remediation_Shell_script_⇲
7690 #·Remediation·is·applicable·only·in·certain·platforms7690 #·Remediation·is·applicable·only·in·certain·platforms
7691 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then7691 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
7692 #·First·perform·the·remediation·of·the·syscall·rule7692 #·First·perform·the·remediation·of·the·syscall·rule
7693 #·Retrieve·hardware·architecture·of·the·underlying·system7693 #·Retrieve·hardware·architecture·of·the·underlying·system
7694 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")7694 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
7695 for·ARCH·in·"${RULE_ARCHS[@]}"7695 for·ARCH·in·"${RULE_ARCHS[@]}"
7696 do7696 do
Offset 8053, 16 lines modifiedOffset 8053, 16 lines modified
8053 ··-·reboot_required8053 ··-·reboot_required
8054 ··-·restrict_strategy8054 ··-·restrict_strategy
  
8055 -·name:·Set·architecture·for·audit·chown·tasks8055 -·name:·Set·architecture·for·audit·chown·tasks
8056 ··set_fact:8056 ··set_fact:
8057 ····audit_arch:·b648057 ····audit_arch:·b64
8058 ··when:8058 ··when:
8059 ··-·'"audit"·in·ansible_facts.packages' 
8060 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8059 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 8060 ··-·'"audit"·in·ansible_facts.packages'
8061 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture8061 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
8062 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"8062 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
8063 ··tags:8063 ··tags:
8064 ··-·CJIS-5.4.1.18064 ··-·CJIS-5.4.1.1
8065 ··-·DISA-STIG-RHEL-08-0304808065 ··-·DISA-STIG-RHEL-08-030480
8066 ··-·NIST-800-171-3.1.78066 ··-·NIST-800-171-3.1.7
8067 ··-·NIST-800-53-AU-12(c)8067 ··-·NIST-800-53-AU-12(c)
Offset 8201, 16 lines modifiedOffset 8201, 16 lines modified
8201 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10008201 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
8202 ········-F·auid!=unset·-F·key=perm_mod8202 ········-F·auid!=unset·-F·key=perm_mod
8203 ······create:·true8203 ······create:·true
8204 ······mode:·o-rwx8204 ······mode:·o-rwx
8205 ······state:·present8205 ······state:·present
8206 ····when:·syscalls_found·|·length·==·08206 ····when:·syscalls_found·|·length·==·0
8207 ··when:8207 ··when:
8208 ··-·'"audit"·in·ansible_facts.packages' 
8209 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8208 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 8209 ··-·'"audit"·in·ansible_facts.packages'
8210 ··tags:8210 ··tags:
8211 ··-·CJIS-5.4.1.18211 ··-·CJIS-5.4.1.1
8212 ··-·DISA-STIG-RHEL-08-0304808212 ··-·DISA-STIG-RHEL-08-030480
8213 ··-·NIST-800-171-3.1.78213 ··-·NIST-800-171-3.1.7
8214 ··-·NIST-800-53-AU-12(c)8214 ··-·NIST-800-53-AU-12(c)
8215 ··-·NIST-800-53-AU-2(d)8215 ··-·NIST-800-53-AU-2(d)
8216 ··-·NIST-800-53-CM-6(a)8216 ··-·NIST-800-53-CM-6(a)
Offset 8347, 16 lines modifiedOffset 8347, 16 lines modified
8347 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10008347 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
8348 ········-F·auid!=unset·-F·key=perm_mod8348 ········-F·auid!=unset·-F·key=perm_mod
8349 ······create:·true8349 ······create:·true
8350 ······mode:·o-rwx8350 ······mode:·o-rwx
8351 ······state:·present8351 ······state:·present
Max diff block lines reached; 183714/188198 bytes (97.62%) of diff not shown.
28.1 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-rht-ccp.html
    
Offset 14540, 15 lines modifiedOffset 14540, 15 lines modified
00038cb0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu00038cb0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu
00038cc0:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<00038cc0:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<
00038cd0:·7374·726f·6e67·3e30·2e31·2e36·353c·2f73··strong>0.1.65</s00038cd0:·7374·726f·6e67·3e30·2e31·2e36·353c·2f73··strong>0.1.65</s
00038ce0:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l00038ce0:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l
00038cf0:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<00038cf0:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<
00038d00:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······00038d00:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······
00038d10:·2020·2020·2020·2020·2020·2020·2028·6173···············(as00038d10:·2020·2020·2020·2020·2020·2020·2028·6173···············(as
00038d20:·206f·6620·3230·3234·2d30·312d·3134·290a···of·2024-01-14).00038d20:·206f·6620·3230·3235·2d30·322d·3135·290a···of·2025-02-15).
00038d30:·2020·2020·2020·2020·2020·2020·2020·2020··················00038d30:·2020·2020·2020·2020·2020·2020·2020·2020··················
00038d40:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>00038d40:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>
00038d50:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con00038d50:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con
00038d60:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l00038d60:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l
00038d70:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd00038d70:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd
00038d80:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject00038d80:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject
00038d90:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s00038d90:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s
Offset 43928, 21 lines modifiedOffset 43928, 21 lines modified
000ab970:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane000ab970:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
000ab980:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla000ab980:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
000ab990:·7073·6522·2069·643d·2269·646d·3235·3232··pse"·id="idm2522000ab990:·7073·6522·2069·643d·2269·646d·3235·3232··pse"·id="idm2522
000ab9a0:·3722·3e3c·7072·653e·3c63·6f64·653e·2320··7"><pre><code>#·000ab9a0:·3722·3e3c·7072·653e·3c63·6f64·653e·2320··7"><pre><code>#·
000ab9b0:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a000ab9b0:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a
000ab9c0:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i000ab9c0:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i
000ab9d0:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo000ab9d0:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo
000ab9e0:·726d·730a·6966·2072·706d·202d·2d71·7569··rms.if·rpm·--qui 
000ab9f0:·6574·202d·7120·6175·6469·7420·2661·6d70··et·-q·audit·&amp 
000aba00:·3b26·616d·703b·205b·2021·202d·6620·2f2e··;&amp;·[·!·-f·/.000ab9e0:·726d·730a·6966·205b·2021·202d·6620·2f2e··rms.if·[·!·-f·/.
000aba10:·646f·636b·6572·656e·7620·5d20·2661·6d70··dockerenv·]·&amp000ab9f0:·646f·636b·6572·656e·7620·5d20·2661·6d70··dockerenv·]·&amp
000aba20:·3b26·616d·703b·205b·2021·202d·6620·2f72··;&amp;·[·!·-f·/r000aba00:·3b26·616d·703b·205b·2021·202d·6620·2f72··;&amp;·[·!·-f·/r
000aba30:·756e·2f2e·636f·6e74·6169·6e65·7265·6e76··un/.containerenv000aba10:·756e·2f2e·636f·6e74·6169·6e65·7265·6e76··un/.containerenv
 000aba20:·205d·2026·616d·703b·2661·6d70·3b20·7270···]·&amp;&amp;·rp
 000aba30:·6d20·2d2d·7175·6965·7420·2d71·2061·7564··m·--quiet·-q·aud
000aba40:·205d·3b20·7468·656e·0a0a·6966·204c·435f···];·then..if·LC_000aba40:·6974·3b20·7468·656e·0a0a·6966·204c·435f··it;·then..if·LC_
000aba50:·414c·4c3d·4320·6772·6570·202d·6977·205e··ALL=C·grep·-iw·^000aba50:·414c·4c3d·4320·6772·6570·202d·6977·205e··ALL=C·grep·-iw·^
000aba60:·6c6f·675f·6669·6c65·202f·6574·632f·6175··log_file·/etc/au000aba60:·6c6f·675f·6669·6c65·202f·6574·632f·6175··log_file·/etc/au
000aba70:·6469·742f·6175·6469·7464·2e63·6f6e·663b··dit/auditd.conf;000aba70:·6469·742f·6175·6469·7464·2e63·6f6e·663b··dit/auditd.conf;
000aba80:·2074·6865·6e0a·2020·2020·4649·4c45·3d24···then.····FILE=$000aba80:·2074·6865·6e0a·2020·2020·4649·4c45·3d24···then.····FILE=$
000aba90:·2861·776b·202d·4620·223d·2220·272f·5e6c··(awk·-F·"="·'/^l000aba90:·2861·776b·202d·4620·223d·2220·272f·5e6c··(awk·-F·"="·'/^l
000abaa0:·6f67·5f66·696c·652f·207b·7072·696e·7420··og_file/·{print·000abaa0:·6f67·5f66·696c·652f·207b·7072·696e·7420··og_file/·{print·
000abab0:·2432·7d27·202f·6574·632f·6175·6469·742f··$2}'·/etc/audit/000abab0:·2432·7d27·202f·6574·632f·6175·6469·742f··$2}'·/etc/audit/
Offset 44578, 22 lines modifiedOffset 44578, 22 lines modified
000ae210:·2d20·6e61·6d65·3a20·5465·7374·2066·6f72··-·name:·Test·for000ae210:·2d20·6e61·6d65·3a20·5465·7374·2066·6f72··-·name:·Test·for
000ae220:·2065·7869·7374·656e·6365·202f·626f·6f74···existence·/boot000ae220:·2065·7869·7374·656e·6365·202f·626f·6f74···existence·/boot
000ae230:·2f67·7275·6232·2f67·7275·622e·6366·670a··/grub2/grub.cfg.000ae230:·2f67·7275·6232·2f67·7275·622e·6366·670a··/grub2/grub.cfg.
000ae240:·2020·7374·6174·3a0a·2020·2020·7061·7468····stat:.····path000ae240:·2020·7374·6174·3a0a·2020·2020·7061·7468····stat:.····path
000ae250:·3a20·2f62·6f6f·742f·6772·7562·322f·6772··:·/boot/grub2/gr000ae250:·3a20·2f62·6f6f·742f·6772·7562·322f·6772··:·/boot/grub2/gr
000ae260:·7562·2e63·6667·0a20·2072·6567·6973·7465··ub.cfg.··registe000ae260:·7562·2e63·6667·0a20·2072·6567·6973·7465··ub.cfg.··registe
000ae270:·723a·2066·696c·655f·6578·6973·7473·0a20··r:·file_exists.·000ae270:·723a·2066·696c·655f·6578·6973·7473·0a20··r:·file_exists.·
000ae280:·2077·6865·6e3a·0a20·202d·2027·2267·7275···when:.··-·'"gru000ae280:·2077·6865·6e3a·0a20·202d·2027·222f·626f···when:.··-·'"/bo
000ae290:·6232·2d63·6f6d·6d6f·6e22·2069·6e20·616e··b2-common"·in·an 
000ae2a0:·7369·626c·655f·6661·6374·732e·7061·636b··sible_facts.pack 
000ae2b0:·6167·6573·270a·2020·2d20·2722·2f62·6f6f··ages'.··-·'"/boo 
000ae2c0:·742f·6566·6922·206e·6f74·2069·6e20·616e··t/efi"·not·in·an 
000ae2d0:·7369·626c·655f·6d6f·756e·7473·207c·206d··sible_mounts·|·m 
000ae2e0:·6170·2861·7474·7269·6275·7465·3d22·6d6f··ap(attribute="mo 
000ae2f0:·756e·7422·2920·7c20·6c69·7374·270a·2020··unt")·|·list'.··000ae290:·6f74·2f65·6669·2220·6e6f·7420·696e·2061··ot/efi"·not·in·a
 000ae2a0:·6e73·6962·6c65·5f6d·6f75·6e74·7320·7c20··nsible_mounts·|·
 000ae2b0:·6d61·7028·6174·7472·6962·7574·653d·226d··map(attribute="m
 000ae2c0:·6f75·6e74·2229·207c·206c·6973·7427·0a20··ount")·|·list'.·
 000ae2d0:·202d·2027·2267·7275·6232·2d63·6f6d·6d6f···-·'"grub2-commo
 000ae2e0:·6e22·2069·6e20·616e·7369·626c·655f·6661··n"·in·ansible_fa
 000ae2f0:·6374·732e·7061·636b·6167·6573·270a·2020··cts.packages'.··
000ae300:·2d20·616e·7369·626c·655f·7669·7274·7561··-·ansible_virtua000ae300:·2d20·616e·7369·626c·655f·7669·7274·7561··-·ansible_virtua
000ae310:·6c69·7a61·7469·6f6e·5f74·7970·6520·6e6f··lization_type·no000ae310:·6c69·7a61·7469·6f6e·5f74·7970·6520·6e6f··lization_type·no
000ae320:·7420·696e·205b·2264·6f63·6b65·7222·2c20··t·in·["docker",·000ae320:·7420·696e·205b·2264·6f63·6b65·7222·2c20··t·in·["docker",·
000ae330:·226c·7863·222c·2022·6f70·656e·767a·222c··"lxc",·"openvz",000ae330:·226c·7863·222c·2022·6f70·656e·767a·222c··"lxc",·"openvz",
000ae340:·2022·706f·646d·616e·222c·2022·636f·6e74···"podman",·"cont000ae340:·2022·706f·646d·616e·222c·2022·636f·6e74···"podman",·"cont
000ae350:·6169·6e65·7222·5d0a·2020·7461·6773·3a0a··ainer"].··tags:.000ae350:·6169·6e65·7222·5d0a·2020·7461·6773·3a0a··ainer"].··tags:.
000ae360:·2020·2d20·434a·4953·2d35·2e35·2e32·2e32····-·CJIS-5.5.2.2000ae360:·2020·2d20·434a·4953·2d35·2e35·2e32·2e32····-·CJIS-5.5.2.2
Offset 44614, 22 lines modifiedOffset 44614, 22 lines modified
000ae450:·0a2d·206e·616d·653a·2045·6e73·7572·6520··.-·name:·Ensure·000ae450:·0a2d·206e·616d·653a·2045·6e73·7572·6520··.-·name:·Ensure·
000ae460:·6772·6f75·7020·6f77·6e65·7220·3020·6f6e··group·owner·0·on000ae460:·6772·6f75·7020·6f77·6e65·7220·3020·6f6e··group·owner·0·on
000ae470:·202f·626f·6f74·2f67·7275·6232·2f67·7275···/boot/grub2/gru000ae470:·202f·626f·6f74·2f67·7275·6232·2f67·7275···/boot/grub2/gru
000ae480:·622e·6366·670a·2020·6669·6c65·3a0a·2020··b.cfg.··file:.··000ae480:·622e·6366·670a·2020·6669·6c65·3a0a·2020··b.cfg.··file:.··
000ae490:·2020·7061·7468·3a20·2f62·6f6f·742f·6772····path:·/boot/gr000ae490:·2020·7061·7468·3a20·2f62·6f6f·742f·6772····path:·/boot/gr
000ae4a0:·7562·322f·6772·7562·2e63·6667·0a20·2020··ub2/grub.cfg.···000ae4a0:·7562·322f·6772·7562·2e63·6667·0a20·2020··ub2/grub.cfg.···
000ae4b0:·2067·726f·7570·3a20·2730·270a·2020·7768···group:·'0'.··wh000ae4b0:·2067·726f·7570·3a20·2730·270a·2020·7768···group:·'0'.··wh
000ae4c0:·656e·3a0a·2020·2d20·2722·6772·7562·322d··en:.··-·'"grub2-000ae4c0:·656e·3a0a·2020·2d20·2722·2f62·6f6f·742f··en:.··-·'"/boot/
000ae4d0:·636f·6d6d·6f6e·2220·696e·2061·6e73·6962··common"·in·ansib 
000ae4e0:·6c65·5f66·6163·7473·2e70·6163·6b61·6765··le_facts.package 
000ae4f0:·7327·0a20·202d·2027·222f·626f·6f74·2f65··s'.··-·'"/boot/e 
000ae500:·6669·2220·6e6f·7420·696e·2061·6e73·6962··fi"·not·in·ansib 
000ae510:·6c65·5f6d·6f75·6e74·7320·7c20·6d61·7028··le_mounts·|·map( 
000ae520:·6174·7472·6962·7574·653d·226d·6f75·6e74··attribute="mount 
000ae530:·2229·207c·206c·6973·7427·0a20·202d·2061··")·|·list'.··-·a000ae4d0:·6566·6922·206e·6f74·2069·6e20·616e·7369··efi"·not·in·ansi
 000ae4e0:·626c·655f·6d6f·756e·7473·207c·206d·6170··ble_mounts·|·map
 000ae4f0:·2861·7474·7269·6275·7465·3d22·6d6f·756e··(attribute="moun
 000ae500:·7422·2920·7c20·6c69·7374·270a·2020·2d20··t")·|·list'.··-·
 000ae510:·2722·6772·7562·322d·636f·6d6d·6f6e·2220··'"grub2-common"·
 000ae520:·696e·2061·6e73·6962·6c65·5f66·6163·7473··in·ansible_facts
 000ae530:·2e70·6163·6b61·6765·7327·0a20·202d·2061··.packages'.··-·a
000ae540:·6e73·6962·6c65·5f76·6972·7475·616c·697a··nsible_virtualiz000ae540:·6e73·6962·6c65·5f76·6972·7475·616c·697a··nsible_virtualiz
000ae550:·6174·696f·6e5f·7479·7065·206e·6f74·2069··ation_type·not·i000ae550:·6174·696f·6e5f·7479·7065·206e·6f74·2069··ation_type·not·i
000ae560:·6e20·5b22·646f·636b·6572·222c·2022·6c78··n·["docker",·"lx000ae560:·6e20·5b22·646f·636b·6572·222c·2022·6c78··n·["docker",·"lx
000ae570:·6322·2c20·226f·7065·6e76·7a22·2c20·2270··c",·"openvz",·"p000ae570:·6322·2c20·226f·7065·6e76·7a22·2c20·2270··c",·"openvz",·"p
000ae580:·6f64·6d61·6e22·2c20·2263·6f6e·7461·696e··odman",·"contain000ae580:·6f64·6d61·6e22·2c20·2263·6f6e·7461·696e··odman",·"contain
000ae590:·6572·225d·0a20·202d·2066·696c·655f·6578··er"].··-·file_ex000ae590:·6572·225d·0a20·202d·2066·696c·655f·6578··er"].··-·file_ex
000ae5a0:·6973·7473·2e73·7461·7420·6973·2064·6566··ists.stat·is·def000ae5a0:·6973·7473·2e73·7461·7420·6973·2064·6566··ists.stat·is·def
Offset 44680, 19 lines modifiedOffset 44680, 19 lines modified
000ae870:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td000ae870:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
000ae880:·3e63·6f6e·6669·6775·7265·3c2f·7464·3e3c··>configure</td><000ae880:·3e63·6f6e·6669·6775·7265·3c2f·7464·3e3c··>configure</td><
000ae890:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre000ae890:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
000ae8a0:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia000ae8a0:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia
000ae8b0:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab000ae8b0:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab
000ae8c0:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa000ae8c0:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa
000ae8d0:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if·000ae8d0:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if·
000ae8e0:·7270·6d20·2d2d·7175·6965·7420·2d71·2067··rpm·--quiet·-q·g 
000ae8f0:·7275·6232·2d63·6f6d·6d6f·6e20·2661·6d70··rub2-common·&amp 
000ae900:·3b26·616d·703b·205b·2021·202d·6620·2f73··;&amp;·[·!·-f·/s 
000ae910:·7973·2f66·6972·6d77·6172·652f·6566·6920··ys/firmware/efi·000ae8e0:·5b20·2120·2d66·202f·7379·732f·6669·726d··[·!·-f·/sys/firm
 000ae8f0:·7761·7265·2f65·6669·205d·2026·616d·703b··ware/efi·]·&amp;
 000ae900:·2661·6d70·3b20·7270·6d20·2d2d·7175·6965··&amp;·rpm·--quie
 000ae910:·7420·2d71·2067·7275·6232·2d63·6f6d·6d6f··t·-q·grub2-commo
000ae920:·5d20·2661·6d70·3b26·616d·703b·207b·205b··]·&amp;&amp;·{·[000ae920:·6e20·2661·6d70·3b26·616d·703b·207b·205b··n·&amp;&amp;·{·[
000ae930:·2021·202d·6620·2f2e·646f·636b·6572·656e···!·-f·/.dockeren000ae930:·2021·202d·6620·2f2e·646f·636b·6572·656e···!·-f·/.dockeren
000ae940:·7620·5d20·2661·6d70·3b26·616d·703b·205b··v·]·&amp;&amp;·[000ae940:·7620·5d20·2661·6d70·3b26·616d·703b·205b··v·]·&amp;&amp;·[
000ae950:·2021·202d·6620·2f72·756e·2f2e·636f·6e74···!·-f·/run/.cont000ae950:·2021·202d·6620·2f72·756e·2f2e·636f·6e74···!·-f·/run/.cont
000ae960:·6169·6e65·7265·6e76·205d·3b20·7d3b·2074··ainerenv·];·};·t000ae960:·6169·6e65·7265·6e76·205d·3b20·7d3b·2074··ainerenv·];·};·t
000ae970:·6865·6e0a·0a63·6867·7270·2030·202f·626f··hen..chgrp·0·/bo000ae970:·6865·6e0a·0a63·6867·7270·2030·202f·626f··hen..chgrp·0·/bo
000ae980:·6f74·2f67·7275·6232·2f67·7275·622e·6366··ot/grub2/grub.cf000ae980:·6f74·2f67·7275·6232·2f67·7275·622e·6366··ot/grub2/grub.cf
000ae990:·670a·0a65·6c73·650a·2020·2020·2667·743b··g..else.····&gt;000ae990:·670a·0a65·6c73·650a·2020·2020·2667·743b··g..else.····&gt;
Offset 45158, 22 lines modifiedOffset 45158, 22 lines modified
000b0650:·7374·2066·6f72·2065·7869·7374·656e·6365··st·for·existence000b0650:·7374·2066·6f72·2065·7869·7374·656e·6365··st·for·existence
000b0660:·202f·626f·6f74·2f67·7275·6232·2f67·7275···/boot/grub2/gru000b0660:·202f·626f·6f74·2f67·7275·6232·2f67·7275···/boot/grub2/gru
000b0670:·622e·6366·670a·2020·7374·6174·3a0a·2020··b.cfg.··stat:.··000b0670:·622e·6366·670a·2020·7374·6174·3a0a·2020··b.cfg.··stat:.··
000b0680:·2020·7061·7468·3a20·2f62·6f6f·742f·6772····path:·/boot/gr000b0680:·2020·7061·7468·3a20·2f62·6f6f·742f·6772····path:·/boot/gr
000b0690:·7562·322f·6772·7562·2e63·6667·0a20·2072··ub2/grub.cfg.··r000b0690:·7562·322f·6772·7562·2e63·6667·0a20·2072··ub2/grub.cfg.··r
000b06a0:·6567·6973·7465·723a·2066·696c·655f·6578··egister:·file_ex000b06a0:·6567·6973·7465·723a·2066·696c·655f·6578··egister:·file_ex
Max diff block lines reached; 11239/20710 bytes (54.27%) of diff not shown.
7.76 KB
html2text {}
    
Offset 68, 15 lines modifiedOffset 68, 15 lines modified
68 ····*·cpe:/o:redhat:enterprise_linux:8.768 ····*·cpe:/o:redhat:enterprise_linux:8.7
69 ····*·cpe:/o:redhat:enterprise_linux:8.869 ····*·cpe:/o:redhat:enterprise_linux:8.8
70 ····*·cpe:/o:redhat:enterprise_linux:8.970 ····*·cpe:/o:redhat:enterprise_linux:8.9
71 ····*·cpe:/o:redhat:enterprise_linux:871 ····*·cpe:/o:redhat:enterprise_linux:8
72 ····*·cpe:/o:centos:centos:872 ····*·cpe:/o:centos:centos:8
73 *****·Revision·History·*****73 *****·Revision·History·*****
74 Current·version:·0.1.6574 Current·version:·0.1.65
75 ····*·draft·(as·of·2024-01-14)75 ····*·draft·(as·of·2025-02-15)
76 *****·Table·of·Contents·*****76 *****·Table·of·Contents·*****
77 ···1.·System_Settings77 ···1.·System_Settings
78 ·········1.·Installing_and_Maintaining_Software78 ·········1.·Installing_and_Maintaining_Software
79 ·········2.·Account_and_Access_Control79 ·········2.·Account_and_Access_Control
80 ·········3.·System_Accounting_with_auditd80 ·········3.·System_Accounting_with_auditd
81 ·········4.·GRUB2_bootloader_configuration81 ·········4.·GRUB2_bootloader_configuration
82 ·········5.·Network_Configuration_and_Firewalls82 ·········5.·Network_Configuration_and_Firewalls
Offset 4766, 15 lines modifiedOffset 4766, 15 lines modified
4766 By·default,·audit_log_file·is·"/var/log/audit/audit.log".4766 By·default,·audit_log_file·is·"/var/log/audit/audit.log".
4767 Rationale:·················If·users·can·write·to·audit·logs,·audit·trails·can·be·modified·or·destroyed.4767 Rationale:·················If·users·can·write·to·audit·logs,·audit·trails·can·be·modified·or·destroyed.
4768 Severity: ················medium4768 Severity: ················medium
4769 Rule·ID:···················xccdf_org.ssgproject.content_rule_file_permissions_var_log_audit4769 Rule·ID:···················xccdf_org.ssgproject.content_rule_file_permissions_var_log_audit
4770 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·18,·19,·3,·4,·5,·6,·7,·8,·5.4.1.1,·APO01.06,·APO11.04,·APO12.06,·BAI03.05,·BAI08.02,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS05.04,·DSS05.07,·DSS06.02,·MEA02.01,·3.3.1,·CCI-000162,·CCI-000163,·CCI-000164,·CCI-001314,·4.2.3.10,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.7.3,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_2.1,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.8,·SR_2.9,·SR_5.2,·SR_6.1,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CIP-003-8_R5.1.1,·CIP-003-8_R5.3,·CIP-004-6_R2.3,·CIP-007-3_R2.1,·CIP-007-3_R2.2,·CIP-007-3_R2.3,·CIP-007-3_R5.1,·CIP-007-3_R5.1.1,·CIP-007-3_R5.1.2,·CM-6(a),·AC-6(1),·AU-9(4),·DE.AE-3,·DE.AE-5,·PR.AC-4,·PR.DS-5,·PR.PT-1,·RS.AN-1,·RS.AN-4,·Req-10.5,·SRG-OS-000057-GPOS-00027,·SRG-OS-000058-GPOS-00028,·SRG-OS-000059-GPOS-00029,·SRG-OS-000206-GPOS-00084,·SV-230396r627750_rule4770 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·18,·19,·3,·4,·5,·6,·7,·8,·5.4.1.1,·APO01.06,·APO11.04,·APO12.06,·BAI03.05,·BAI08.02,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS05.04,·DSS05.07,·DSS06.02,·MEA02.01,·3.3.1,·CCI-000162,·CCI-000163,·CCI-000164,·CCI-001314,·4.2.3.10,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.7.3,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_2.1,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.8,·SR_2.9,·SR_5.2,·SR_6.1,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CIP-003-8_R5.1.1,·CIP-003-8_R5.3,·CIP-004-6_R2.3,·CIP-007-3_R2.1,·CIP-007-3_R2.2,·CIP-007-3_R2.3,·CIP-007-3_R5.1,·CIP-007-3_R5.1.1,·CIP-007-3_R5.1.2,·CM-6(a),·AC-6(1),·AU-9(4),·DE.AE-3,·DE.AE-5,·PR.AC-4,·PR.DS-5,·PR.PT-1,·RS.AN-1,·RS.AN-4,·Req-10.5,·SRG-OS-000057-GPOS-00027,·SRG-OS-000058-GPOS-00028,·SRG-OS-000059-GPOS-00029,·SRG-OS-000206-GPOS-00084,·SV-230396r627750_rule
4771 Remediation_Shell_script_⇲4771 Remediation_Shell_script_⇲
4772 #·Remediation·is·applicable·only·in·certain·platforms4772 #·Remediation·is·applicable·only·in·certain·platforms
4773 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then4773 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
4774 if·LC_ALL=C·grep·-iw·^log_file·/etc/audit/auditd.conf;·then4774 if·LC_ALL=C·grep·-iw·^log_file·/etc/audit/auditd.conf;·then
4775 ····FILE=$(awk·-F·"="·'/^log_file/·{print·$2}'·/etc/audit/auditd.conf·|·tr·-d·'·')4775 ····FILE=$(awk·-F·"="·'/^log_file/·{print·$2}'·/etc/audit/auditd.conf·|·tr·-d·'·')
4776 else4776 else
4777 ····FILE="/var/log/audit/audit.log"4777 ····FILE="/var/log/audit/audit.log"
4778 fi4778 fi
  
Offset 4816, 16 lines modifiedOffset 4816, 16 lines modified
4816 ··-·no_reboot_needed4816 ··-·no_reboot_needed
  
4817 -·name:·Test·for·existence·/boot/grub2/grub.cfg4817 -·name:·Test·for·existence·/boot/grub2/grub.cfg
4818 ··stat:4818 ··stat:
4819 ····path:·/boot/grub2/grub.cfg4819 ····path:·/boot/grub2/grub.cfg
4820 ··register:·file_exists4820 ··register:·file_exists
4821 ··when:4821 ··when:
4822 ··-·'"grub2-common"·in·ansible_facts.packages' 
4823 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'4822 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 4823 ··-·'"grub2-common"·in·ansible_facts.packages'
4824 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4824 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4825 ··tags:4825 ··tags:
4826 ··-·CJIS-5.5.2.24826 ··-·CJIS-5.5.2.2
4827 ··-·NIST-800-171-3.4.54827 ··-·NIST-800-171-3.4.5
4828 ··-·NIST-800-53-AC-6(1)4828 ··-·NIST-800-53-AC-6(1)
4829 ··-·NIST-800-53-CM-6(a)4829 ··-·NIST-800-53-CM-6(a)
4830 ··-·PCI-DSS-Req-7.14830 ··-·PCI-DSS-Req-7.1
Offset 4837, 16 lines modifiedOffset 4837, 16 lines modified
4837 ··-·no_reboot_needed4837 ··-·no_reboot_needed
  
4838 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg4838 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
4839 ··file:4839 ··file:
4840 ····path:·/boot/grub2/grub.cfg4840 ····path:·/boot/grub2/grub.cfg
4841 ····group:·'0'4841 ····group:·'0'
4842 ··when:4842 ··when:
4843 ··-·'"grub2-common"·in·ansible_facts.packages' 
4844 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'4843 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 4844 ··-·'"grub2-common"·in·ansible_facts.packages'
4845 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4845 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4846 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists4846 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists
4847 ··tags:4847 ··tags:
4848 ··-·CJIS-5.5.2.24848 ··-·CJIS-5.5.2.2
4849 ··-·NIST-800-171-3.4.54849 ··-·NIST-800-171-3.4.5
4850 ··-·NIST-800-53-AC-6(1)4850 ··-·NIST-800-53-AC-6(1)
4851 ··-·NIST-800-53-CM-6(a)4851 ··-·NIST-800-53-CM-6(a)
Offset 4858, 15 lines modifiedOffset 4858, 15 lines modified
4858 ··-·medium_severity4858 ··-·medium_severity
4859 ··-·no_reboot_needed4859 ··-·no_reboot_needed
4860 Remediation_Shell_script_⇲4860 Remediation_Shell_script_⇲
4861 Complexity:·low4861 Complexity:·low
4862 Disruption:·low4862 Disruption:·low
4863 Strategy:···configure4863 Strategy:···configure
4864 #·Remediation·is·applicable·only·in·certain·platforms4864 #·Remediation·is·applicable·only·in·certain·platforms
4865 if·rpm·--quiet·-q·grub2-common·&&·[·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then4865 if·[·!·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
4866 chgrp·0·/boot/grub2/grub.cfg4866 chgrp·0·/boot/grub2/grub.cfg
  
4867 else4867 else
4868 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'4868 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
4869 fi4869 fi
4870 ***·Rule  ·Verify·/boot/grub2/grub.cfg·User·Ownership·  [ref]·***4870 ***·Rule  ·Verify·/boot/grub2/grub.cfg·User·Ownership·  [ref]·***
Offset 4897, 16 lines modifiedOffset 4897, 16 lines modified
4897 ··-·no_reboot_needed4897 ··-·no_reboot_needed
  
4898 -·name:·Test·for·existence·/boot/grub2/grub.cfg4898 -·name:·Test·for·existence·/boot/grub2/grub.cfg
4899 ··stat:4899 ··stat:
4900 ····path:·/boot/grub2/grub.cfg4900 ····path:·/boot/grub2/grub.cfg
4901 ··register:·file_exists4901 ··register:·file_exists
4902 ··when:4902 ··when:
4903 ··-·'"grub2-common"·in·ansible_facts.packages' 
4904 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'4903 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 4904 ··-·'"grub2-common"·in·ansible_facts.packages'
4905 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4905 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4906 ··tags:4906 ··tags:
4907 ··-·CJIS-5.5.2.24907 ··-·CJIS-5.5.2.2
4908 ··-·NIST-800-171-3.4.54908 ··-·NIST-800-171-3.4.5
4909 ··-·NIST-800-53-AC-6(1)4909 ··-·NIST-800-53-AC-6(1)
4910 ··-·NIST-800-53-CM-6(a)4910 ··-·NIST-800-53-CM-6(a)
4911 ··-·PCI-DSS-Req-7.14911 ··-·PCI-DSS-Req-7.1
Offset 4918, 16 lines modifiedOffset 4918, 16 lines modified
4918 ··-·no_reboot_needed4918 ··-·no_reboot_needed
  
4919 -·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg4919 -·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg
4920 ··file:4920 ··file:
4921 ····path:·/boot/grub2/grub.cfg4921 ····path:·/boot/grub2/grub.cfg
4922 ····owner:·'0'4922 ····owner:·'0'
4923 ··when:4923 ··when:
4924 ··-·'"grub2-common"·in·ansible_facts.packages' 
4925 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'4924 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 4925 ··-·'"grub2-common"·in·ansible_facts.packages'
4926 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4926 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4927 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists4927 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists
4928 ··tags:4928 ··tags:
4929 ··-·CJIS-5.5.2.24929 ··-·CJIS-5.5.2.2
4930 ··-·NIST-800-171-3.4.54930 ··-·NIST-800-171-3.4.5
4931 ··-·NIST-800-53-AC-6(1)4931 ··-·NIST-800-53-AC-6(1)
4932 ··-·NIST-800-53-CM-6(a)4932 ··-·NIST-800-53-CM-6(a)
Offset 4939, 15 lines modifiedOffset 4939, 15 lines modified
4939 ··-·medium_severity4939 ··-·medium_severity
4940 ··-·no_reboot_needed4940 ··-·no_reboot_needed
4941 Remediation_Shell_script_⇲4941 Remediation_Shell_script_⇲
4942 Complexity:·low4942 Complexity:·low
4943 Disruption:·low4943 Disruption:·low
4944 Strategy:···configure4944 Strategy:···configure
4945 #·Remediation·is·applicable·only·in·certain·platforms4945 #·Remediation·is·applicable·only·in·certain·platforms
Max diff block lines reached; 2013/7921 bytes (25.41%) of diff not shown.
399 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-standard.html
    
Offset 14539, 15 lines modifiedOffset 14539, 15 lines modified
00038ca0:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur00038ca0:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur
00038cb0:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s00038cb0:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s
00038cc0:·7472·6f6e·673e·302e·312e·3635·3c2f·7374··trong>0.1.65</st00038cc0:·7472·6f6e·673e·302e·312e·3635·3c2f·7374··trong>0.1.65</st
00038cd0:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li00038cd0:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li
00038ce0:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</00038ce0:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</
00038cf0:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········00038cf0:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········
00038d00:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·00038d00:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·
00038d10:·6f66·2032·3032·342d·3031·2d31·3429·0a20··of·2024-01-14).·00038d10:·6f66·2032·3032·352d·3032·2d31·3529·0a20··of·2025-02-15).·
00038d20:·2020·2020·2020·2020·2020·2020·2020·203c·················<00038d20:·2020·2020·2020·2020·2020·2020·2020·203c·················<
00038d30:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><00038d30:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><
00038d40:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont00038d40:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont
00038d50:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li00038d50:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li
00038d60:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf00038d60:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf
00038d70:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.00038d70:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.
00038d80:·636f·6e74·656e·745f·6772·6f75·705f·7379··content_group_sy00038d80:·636f·6e74·656e·745f·6772·6f75·705f·7379··content_group_sy
Offset 26446, 23 lines modifiedOffset 26446, 23 lines modified
000674d0:·7175·6972·6564·0a20·202d·2072·6573·7472··quired.··-·restr000674d0:·7175·6972·6564·0a20·202d·2072·6573·7472··quired.··-·restr
000674e0:·6963·745f·7374·7261·7465·6779·0a0a·2d20··ict_strategy..-·000674e0:·6963·745f·7374·7261·7465·6779·0a0a·2d20··ict_strategy..-·
000674f0:·6e61·6d65·3a20·5365·7420·6172·6368·6974··name:·Set·archit000674f0:·6e61·6d65·3a20·5365·7420·6172·6368·6974··name:·Set·archit
00067500:·6563·7475·7265·2066·6f72·2061·7564·6974··ecture·for·audit00067500:·6563·7475·7265·2066·6f72·2061·7564·6974··ecture·for·audit
00067510:·2063·686d·6f64·2074·6173·6b73·0a20·2073···chmod·tasks.··s00067510:·2063·686d·6f64·2074·6173·6b73·0a20·2073···chmod·tasks.··s
00067520:·6574·5f66·6163·743a·0a20·2020·2061·7564··et_fact:.····aud00067520:·6574·5f66·6163·743a·0a20·2020·2061·7564··et_fact:.····aud
00067530:·6974·5f61·7263·683a·2062·3634·0a20·2077··it_arch:·b64.··w00067530:·6974·5f61·7263·683a·2062·3634·0a20·2077··it_arch:·b64.··w
00067540:·6865·6e3a·0a20·202d·2027·2261·7564·6974··hen:.··-·'"audit00067540:·6865·6e3a·0a20·202d·2061·6e73·6962·6c65··hen:.··-·ansible
00067550:·2220·696e·2061·6e73·6962·6c65·5f66·6163··"·in·ansible_fac 
00067560:·7473·2e70·6163·6b61·6765·7327·0a20·202d··ts.packages'.··- 
00067570:·2061·6e73·6962·6c65·5f76·6972·7475·616c···ansible_virtual 
00067580:·697a·6174·696f·6e5f·7479·7065·206e·6f74··ization_type·not 
00067590:·2069·6e20·5b22·646f·636b·6572·222c·2022···in·["docker",·" 
000675a0:·6c78·6322·2c20·226f·7065·6e76·7a22·2c20··lxc",·"openvz",· 
000675b0:·2270·6f64·6d61·6e22·2c20·2263·6f6e·7461··"podman",·"conta00067550:·5f76·6972·7475·616c·697a·6174·696f·6e5f··_virtualization_
 00067560:·7479·7065·206e·6f74·2069·6e20·5b22·646f··type·not·in·["do
 00067570:·636b·6572·222c·2022·6c78·6322·2c20·226f··cker",·"lxc",·"o
 00067580:·7065·6e76·7a22·2c20·2270·6f64·6d61·6e22··penvz",·"podman"
 00067590:·2c20·2263·6f6e·7461·696e·6572·225d·0a20··,·"container"].·
 000675a0:·202d·2027·2261·7564·6974·2220·696e·2061···-·'"audit"·in·a
 000675b0:·6e73·6962·6c65·5f66·6163·7473·2e70·6163··nsible_facts.pac
000675c0:·696e·6572·225d·0a20·202d·2061·6e73·6962··iner"].··-·ansib000675c0:·6b61·6765·7327·0a20·202d·2061·6e73·6962··kages'.··-·ansib
000675d0:·6c65·5f61·7263·6869·7465·6374·7572·6520··le_architecture·000675d0:·6c65·5f61·7263·6869·7465·6374·7572·6520··le_architecture·
000675e0:·3d3d·2022·6161·7263·6836·3422·206f·7220··==·"aarch64"·or·000675e0:·3d3d·2022·6161·7263·6836·3422·206f·7220··==·"aarch64"·or·
000675f0:·616e·7369·626c·655f·6172·6368·6974·6563··ansible_architec000675f0:·616e·7369·626c·655f·6172·6368·6974·6563··ansible_architec
00067600:·7475·7265·203d·3d20·2270·7063·3634·2220··ture·==·"ppc64"·00067600:·7475·7265·203d·3d20·2270·7063·3634·2220··ture·==·"ppc64"·
00067610:·6f72·2061·6e73·6962·6c65·5f61·7263·6869··or·ansible_archi00067610:·6f72·2061·6e73·6962·6c65·5f61·7263·6869··or·ansible_archi
00067620:·7465·6374·7572·650a·2020·2020·3d3d·2022··tecture.····==·"00067620:·7465·6374·7572·650a·2020·2020·3d3d·2022··tecture.····==·"
00067630:·7070·6336·346c·6522·206f·7220·616e·7369··ppc64le"·or·ansi00067630:·7070·6336·346c·6522·206f·7220·616e·7369··ppc64le"·or·ansi
Offset 26769, 23 lines modifiedOffset 26769, 23 lines modified
00068900:·4620·6b65·793d·7065·726d·5f6d·6f64·0a20··F·key=perm_mod.·00068900:·4620·6b65·793d·7065·726d·5f6d·6f64·0a20··F·key=perm_mod.·
00068910:·2020·2020·2063·7265·6174·653a·2074·7275·······create:·tru00068910:·2020·2020·2063·7265·6174·653a·2074·7275·······create:·tru
00068920:·650a·2020·2020·2020·6d6f·6465·3a20·6f2d··e.······mode:·o-00068920:·650a·2020·2020·2020·6d6f·6465·3a20·6f2d··e.······mode:·o-
00068930:·7277·780a·2020·2020·2020·7374·6174·653a··rwx.······state:00068930:·7277·780a·2020·2020·2020·7374·6174·653a··rwx.······state:
00068940:·2070·7265·7365·6e74·0a20·2020·2077·6865···present.····whe00068940:·2070·7265·7365·6e74·0a20·2020·2077·6865···present.····whe
00068950:·6e3a·2073·7973·6361·6c6c·735f·666f·756e··n:·syscalls_foun00068950:·6e3a·2073·7973·6361·6c6c·735f·666f·756e··n:·syscalls_foun
00068960:·6420·7c20·6c65·6e67·7468·203d·3d20·300a··d·|·length·==·0.00068960:·6420·7c20·6c65·6e67·7468·203d·3d20·300a··d·|·length·==·0.
00068970:·2020·7768·656e·3a0a·2020·2d20·2722·6175····when:.··-·'"au00068970:·2020·7768·656e·3a0a·2020·2d20·616e·7369····when:.··-·ansi
00068980:·6469·7422·2069·6e20·616e·7369·626c·655f··dit"·in·ansible_ 
00068990:·6661·6374·732e·7061·636b·6167·6573·270a··facts.packages'. 
000689a0:·2020·2d20·616e·7369·626c·655f·7669·7274····-·ansible_virt 
000689b0:·7561·6c69·7a61·7469·6f6e·5f74·7970·6520··ualization_type· 
000689c0:·6e6f·7420·696e·205b·2264·6f63·6b65·7222··not·in·["docker" 
000689d0:·2c20·226c·7863·222c·2022·6f70·656e·767a··,·"lxc",·"openvz 
000689e0:·222c·2022·706f·646d·616e·222c·2022·636f··",·"podman",·"co 
000689f0:·6e74·6169·6e65·7222·5d0a·2020·7461·6773··ntainer"].··tags00068980:·626c·655f·7669·7274·7561·6c69·7a61·7469··ble_virtualizati
 00068990:·6f6e·5f74·7970·6520·6e6f·7420·696e·205b··on_type·not·in·[
 000689a0:·2264·6f63·6b65·7222·2c20·226c·7863·222c··"docker",·"lxc",
 000689b0:·2022·6f70·656e·767a·222c·2022·706f·646d···"openvz",·"podm
 000689c0:·616e·222c·2022·636f·6e74·6169·6e65·7222··an",·"container"
 000689d0:·5d0a·2020·2d20·2722·6175·6469·7422·2069··].··-·'"audit"·i
 000689e0:·6e20·616e·7369·626c·655f·6661·6374·732e··n·ansible_facts.
 000689f0:·7061·636b·6167·6573·270a·2020·7461·6773··packages'.··tags
00068a00:·3a0a·2020·2d20·434a·4953·2d35·2e34·2e31··:.··-·CJIS-5.4.100068a00:·3a0a·2020·2d20·434a·4953·2d35·2e34·2e31··:.··-·CJIS-5.4.1
00068a10:·2e31·0a20·202d·2044·4953·412d·5354·4947··.1.··-·DISA-STIG00068a10:·2e31·0a20·202d·2044·4953·412d·5354·4947··.1.··-·DISA-STIG
00068a20:·2d52·4845·4c2d·3038·2d30·3330·3439·300a··-RHEL-08-030490.00068a20:·2d52·4845·4c2d·3038·2d30·3330·3439·300a··-RHEL-08-030490.
00068a30:·2020·2d20·4e49·5354·2d38·3030·2d31·3731····-·NIST-800-17100068a30:·2020·2d20·4e49·5354·2d38·3030·2d31·3731····-·NIST-800-171
00068a40:·2d33·2e31·2e37·0a20·202d·204e·4953·542d··-3.1.7.··-·NIST-00068a40:·2d33·2e31·2e37·0a20·202d·204e·4953·542d··-3.1.7.··-·NIST-
00068a50:·3830·302d·3533·2d41·552d·3132·2863·290a··800-53-AU-12(c).00068a50:·3830·302d·3533·2d41·552d·3132·2863·290a··800-53-AU-12(c).
00068a60:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-00068a60:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-
Offset 27081, 23 lines modifiedOffset 27081, 23 lines modified
00069c80:·7065·726d·5f6d·6f64·0a20·2020·2020·2063··perm_mod.······c00069c80:·7065·726d·5f6d·6f64·0a20·2020·2020·2063··perm_mod.······c
00069c90:·7265·6174·653a·2074·7275·650a·2020·2020··reate:·true.····00069c90:·7265·6174·653a·2074·7275·650a·2020·2020··reate:·true.····
00069ca0:·2020·6d6f·6465·3a20·6f2d·7277·780a·2020····mode:·o-rwx.··00069ca0:·2020·6d6f·6465·3a20·6f2d·7277·780a·2020····mode:·o-rwx.··
00069cb0:·2020·2020·7374·6174·653a·2070·7265·7365······state:·prese00069cb0:·2020·2020·7374·6174·653a·2070·7265·7365······state:·prese
00069cc0:·6e74·0a20·2020·2077·6865·6e3a·2073·7973··nt.····when:·sys00069cc0:·6e74·0a20·2020·2077·6865·6e3a·2073·7973··nt.····when:·sys
00069cd0:·6361·6c6c·735f·666f·756e·6420·7c20·6c65··calls_found·|·le00069cd0:·6361·6c6c·735f·666f·756e·6420·7c20·6c65··calls_found·|·le
00069ce0:·6e67·7468·203d·3d20·300a·2020·7768·656e··ngth·==·0.··when00069ce0:·6e67·7468·203d·3d20·300a·2020·7768·656e··ngth·==·0.··when
00069cf0:·3a0a·2020·2d20·2722·6175·6469·7422·2069··:.··-·'"audit"·i 
00069d00:·6e20·616e·7369·626c·655f·6661·6374·732e··n·ansible_facts. 
00069d10:·7061·636b·6167·6573·270a·2020·2d20·616e··packages'.··-·an 
00069d20:·7369·626c·655f·7669·7274·7561·6c69·7a61··sible_virtualiza 
00069d30:·7469·6f6e·5f74·7970·6520·6e6f·7420·696e··tion_type·not·in 
00069d40:·205b·2264·6f63·6b65·7222·2c20·226c·7863···["docker",·"lxc 
00069d50:·222c·2022·6f70·656e·767a·222c·2022·706f··",·"openvz",·"po 
00069d60:·646d·616e·222c·2022·636f·6e74·6169·6e65··dman",·"containe00069cf0:·3a0a·2020·2d20·616e·7369·626c·655f·7669··:.··-·ansible_vi
 00069d00:·7274·7561·6c69·7a61·7469·6f6e·5f74·7970··rtualization_typ
 00069d10:·6520·6e6f·7420·696e·205b·2264·6f63·6b65··e·not·in·["docke
 00069d20:·7222·2c20·226c·7863·222c·2022·6f70·656e··r",·"lxc",·"open
 00069d30:·767a·222c·2022·706f·646d·616e·222c·2022··vz",·"podman",·"
 00069d40:·636f·6e74·6169·6e65·7222·5d0a·2020·2d20··container"].··-·
 00069d50:·2722·6175·6469·7422·2069·6e20·616e·7369··'"audit"·in·ansi
 00069d60:·626c·655f·6661·6374·732e·7061·636b·6167··ble_facts.packag
00069d70:·7222·5d0a·2020·2d20·6175·6469·745f·6172··r"].··-·audit_ar00069d70:·6573·270a·2020·2d20·6175·6469·745f·6172··es'.··-·audit_ar
00069d80:·6368·203d·3d20·2262·3634·220a·2020·7461··ch·==·"b64".··ta00069d80:·6368·203d·3d20·2262·3634·220a·2020·7461··ch·==·"b64".··ta
00069d90:·6773·3a0a·2020·2d20·434a·4953·2d35·2e34··gs:.··-·CJIS-5.400069d90:·6773·3a0a·2020·2d20·434a·4953·2d35·2e34··gs:.··-·CJIS-5.4
00069da0:·2e31·2e31·0a20·202d·2044·4953·412d·5354··.1.1.··-·DISA-ST00069da0:·2e31·2e31·0a20·202d·2044·4953·412d·5354··.1.1.··-·DISA-ST
00069db0:·4947·2d52·4845·4c2d·3038·2d30·3330·3439··IG-RHEL-08-0304900069db0:·4947·2d52·4845·4c2d·3038·2d30·3330·3439··IG-RHEL-08-03049
00069dc0:·300a·2020·2d20·4e49·5354·2d38·3030·2d31··0.··-·NIST-800-100069dc0:·300a·2020·2d20·4e49·5354·2d38·3030·2d31··0.··-·NIST-800-1
00069dd0:·3731·2d33·2e31·2e37·0a20·202d·204e·4953··71-3.1.7.··-·NIS00069dd0:·3731·2d33·2e31·2e37·0a20·202d·204e·4953··71-3.1.7.··-·NIS
00069de0:·542d·3830·302d·3533·2d41·552d·3132·2863··T-800-53-AU-12(c00069de0:·542d·3830·302d·3533·2d41·552d·3132·2863··T-800-53-AU-12(c
Offset 27131, 20 lines modifiedOffset 27131, 20 lines modified
00069fa0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col00069fa0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
00069fb0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·00069fb0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
00069fc0:·6964·3d22·6964·6d32·3533·3930·223e·3c70··id="idm25390"><p00069fc0:·6964·3d22·6964·6d32·3533·3930·223e·3c70··id="idm25390"><p
00069fd0:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed00069fd0:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed
00069fe0:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic00069fe0:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic
00069ff0:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer00069ff0:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer
0006a000:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i0006a000:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i
0006a010:·6620·7270·6d20·2d2d·7175·6965·7420·2d71··f·rpm·--quiet·-q 
0006a020:·2061·7564·6974·2026·616d·703b·2661·6d70···audit·&amp;&amp 
0006a030:·3b20·5b20·2120·2d66·202f·2e64·6f63·6b65··;·[·!·-f·/.docke0006a010:·6620·5b20·2120·2d66·202f·2e64·6f63·6b65··f·[·!·-f·/.docke
0006a040:·7265·6e76·205d·2026·616d·703b·2661·6d70··renv·]·&amp;&amp0006a020:·7265·6e76·205d·2026·616d·703b·2661·6d70··renv·]·&amp;&amp
0006a050:·3b20·5b20·2120·2d66·202f·7275·6e2f·2e63··;·[·!·-f·/run/.c0006a030:·3b20·5b20·2120·2d66·202f·7275·6e2f·2e63··;·[·!·-f·/run/.c
0006a060:·6f6e·7461·696e·6572·656e·7620·5d3b·2074··ontainerenv·];·t0006a040:·6f6e·7461·696e·6572·656e·7620·5d20·2661··ontainerenv·]·&a
 0006a050:·6d70·3b26·616d·703b·2072·706d·202d·2d71··mp;&amp;·rpm·--q
 0006a060:·7569·6574·202d·7120·6175·6469·743b·2074··uiet·-q·audit;·t
0006a070:·6865·6e0a·0a23·2046·6972·7374·2070·6572··hen..#·First·per0006a070:·6865·6e0a·0a23·2046·6972·7374·2070·6572··hen..#·First·per
0006a080:·666f·726d·2074·6865·2072·656d·6564·6961··form·the·remedia0006a080:·666f·726d·2074·6865·2072·656d·6564·6961··form·the·remedia
0006a090:·7469·6f6e·206f·6620·7468·6520·7379·7363··tion·of·the·sysc0006a090:·7469·6f6e·206f·6620·7468·6520·7379·7363··tion·of·the·sysc
0006a0a0:·616c·6c20·7275·6c65·0a23·2052·6574·7269··all·rule.#·Retri0006a0a0:·616c·6c20·7275·6c65·0a23·2052·6574·7269··all·rule.#·Retri
Max diff block lines reached; 303016/312530 bytes (96.96%) of diff not shown.
93.9 KB
html2text {}
    
Offset 68, 15 lines modifiedOffset 68, 15 lines modified
68 ····*·cpe:/o:redhat:enterprise_linux:8.768 ····*·cpe:/o:redhat:enterprise_linux:8.7
69 ····*·cpe:/o:redhat:enterprise_linux:8.869 ····*·cpe:/o:redhat:enterprise_linux:8.8
70 ····*·cpe:/o:redhat:enterprise_linux:8.970 ····*·cpe:/o:redhat:enterprise_linux:8.9
71 ····*·cpe:/o:redhat:enterprise_linux:871 ····*·cpe:/o:redhat:enterprise_linux:8
72 ····*·cpe:/o:centos:centos:872 ····*·cpe:/o:centos:centos:8
73 *****·Revision·History·*****73 *****·Revision·History·*****
74 Current·version:·0.1.6574 Current·version:·0.1.65
75 ····*·draft·(as·of·2024-01-14)75 ····*·draft·(as·of·2025-02-15)
76 *****·Table·of·Contents·*****76 *****·Table·of·Contents·*****
77 ···1.·System_Settings77 ···1.·System_Settings
78 ·········1.·Installing_and_Maintaining_Software78 ·········1.·Installing_and_Maintaining_Software
79 ·········2.·Account_and_Access_Control79 ·········2.·Account_and_Access_Control
80 ·········3.·System_Accounting_with_auditd80 ·········3.·System_Accounting_with_auditd
81 ·········4.·Configure_Syslog81 ·········4.·Configure_Syslog
82 ·········5.·File_Permissions_and_Masks82 ·········5.·File_Permissions_and_Masks
Offset 1454, 16 lines modifiedOffset 1454, 16 lines modified
1454 ··-·reboot_required1454 ··-·reboot_required
1455 ··-·restrict_strategy1455 ··-·restrict_strategy
  
1456 -·name:·Set·architecture·for·audit·chmod·tasks1456 -·name:·Set·architecture·for·audit·chmod·tasks
1457 ··set_fact:1457 ··set_fact:
1458 ····audit_arch:·b641458 ····audit_arch:·b64
1459 ··when:1459 ··when:
1460 ··-·'"audit"·in·ansible_facts.packages' 
1461 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1460 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1461 ··-·'"audit"·in·ansible_facts.packages'
1462 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture1462 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
1463 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"1463 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
1464 ··tags:1464 ··tags:
1465 ··-·CJIS-5.4.1.11465 ··-·CJIS-5.4.1.1
1466 ··-·DISA-STIG-RHEL-08-0304901466 ··-·DISA-STIG-RHEL-08-030490
1467 ··-·NIST-800-171-3.1.71467 ··-·NIST-800-171-3.1.7
1468 ··-·NIST-800-53-AU-12(c)1468 ··-·NIST-800-53-AU-12(c)
Offset 1600, 16 lines modifiedOffset 1600, 16 lines modified
1600 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10001600 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
1601 ········-F·auid!=unset·-F·key=perm_mod1601 ········-F·auid!=unset·-F·key=perm_mod
1602 ······create:·true1602 ······create:·true
1603 ······mode:·o-rwx1603 ······mode:·o-rwx
1604 ······state:·present1604 ······state:·present
1605 ····when:·syscalls_found·|·length·==·01605 ····when:·syscalls_found·|·length·==·0
1606 ··when:1606 ··when:
1607 ··-·'"audit"·in·ansible_facts.packages' 
1608 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1607 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1608 ··-·'"audit"·in·ansible_facts.packages'
1609 ··tags:1609 ··tags:
1610 ··-·CJIS-5.4.1.11610 ··-·CJIS-5.4.1.1
1611 ··-·DISA-STIG-RHEL-08-0304901611 ··-·DISA-STIG-RHEL-08-030490
1612 ··-·NIST-800-171-3.1.71612 ··-·NIST-800-171-3.1.7
1613 ··-·NIST-800-53-AU-12(c)1613 ··-·NIST-800-53-AU-12(c)
1614 ··-·NIST-800-53-AU-2(d)1614 ··-·NIST-800-53-AU-2(d)
1615 ··-·NIST-800-53-CM-6(a)1615 ··-·NIST-800-53-CM-6(a)
Offset 1744, 16 lines modifiedOffset 1744, 16 lines modified
1744 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10001744 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
1745 ········-F·auid!=unset·-F·key=perm_mod1745 ········-F·auid!=unset·-F·key=perm_mod
1746 ······create:·true1746 ······create:·true
1747 ······mode:·o-rwx1747 ······mode:·o-rwx
1748 ······state:·present1748 ······state:·present
1749 ····when:·syscalls_found·|·length·==·01749 ····when:·syscalls_found·|·length·==·0
1750 ··when:1750 ··when:
1751 ··-·'"audit"·in·ansible_facts.packages' 
1752 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1751 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1752 ··-·'"audit"·in·ansible_facts.packages'
1753 ··-·audit_arch·==·"b64"1753 ··-·audit_arch·==·"b64"
1754 ··tags:1754 ··tags:
1755 ··-·CJIS-5.4.1.11755 ··-·CJIS-5.4.1.1
1756 ··-·DISA-STIG-RHEL-08-0304901756 ··-·DISA-STIG-RHEL-08-030490
1757 ··-·NIST-800-171-3.1.71757 ··-·NIST-800-171-3.1.7
1758 ··-·NIST-800-53-AU-12(c)1758 ··-·NIST-800-53-AU-12(c)
1759 ··-·NIST-800-53-AU-2(d)1759 ··-·NIST-800-53-AU-2(d)
Offset 1763, 15 lines modifiedOffset 1763, 15 lines modified
1763 ··-·low_complexity1763 ··-·low_complexity
1764 ··-·low_disruption1764 ··-·low_disruption
1765 ··-·medium_severity1765 ··-·medium_severity
1766 ··-·reboot_required1766 ··-·reboot_required
1767 ··-·restrict_strategy1767 ··-·restrict_strategy
1768 Remediation_Shell_script_⇲1768 Remediation_Shell_script_⇲
1769 #·Remediation·is·applicable·only·in·certain·platforms1769 #·Remediation·is·applicable·only·in·certain·platforms
1770 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then1770 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
1771 #·First·perform·the·remediation·of·the·syscall·rule1771 #·First·perform·the·remediation·of·the·syscall·rule
1772 #·Retrieve·hardware·architecture·of·the·underlying·system1772 #·Retrieve·hardware·architecture·of·the·underlying·system
1773 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")1773 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
1774 for·ARCH·in·"${RULE_ARCHS[@]}"1774 for·ARCH·in·"${RULE_ARCHS[@]}"
1775 do1775 do
Offset 2132, 16 lines modifiedOffset 2132, 16 lines modified
2132 ··-·reboot_required2132 ··-·reboot_required
2133 ··-·restrict_strategy2133 ··-·restrict_strategy
  
2134 -·name:·Set·architecture·for·audit·chown·tasks2134 -·name:·Set·architecture·for·audit·chown·tasks
2135 ··set_fact:2135 ··set_fact:
2136 ····audit_arch:·b642136 ····audit_arch:·b64
2137 ··when:2137 ··when:
2138 ··-·'"audit"·in·ansible_facts.packages' 
2139 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2138 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2139 ··-·'"audit"·in·ansible_facts.packages'
2140 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture2140 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
2141 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"2141 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
2142 ··tags:2142 ··tags:
2143 ··-·CJIS-5.4.1.12143 ··-·CJIS-5.4.1.1
2144 ··-·DISA-STIG-RHEL-08-0304802144 ··-·DISA-STIG-RHEL-08-030480
2145 ··-·NIST-800-171-3.1.72145 ··-·NIST-800-171-3.1.7
2146 ··-·NIST-800-53-AU-12(c)2146 ··-·NIST-800-53-AU-12(c)
Offset 2280, 16 lines modifiedOffset 2280, 16 lines modified
2280 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002280 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2281 ········-F·auid!=unset·-F·key=perm_mod2281 ········-F·auid!=unset·-F·key=perm_mod
2282 ······create:·true2282 ······create:·true
2283 ······mode:·o-rwx2283 ······mode:·o-rwx
2284 ······state:·present2284 ······state:·present
2285 ····when:·syscalls_found·|·length·==·02285 ····when:·syscalls_found·|·length·==·0
2286 ··when:2286 ··when:
2287 ··-·'"audit"·in·ansible_facts.packages' 
2288 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2287 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2288 ··-·'"audit"·in·ansible_facts.packages'
2289 ··tags:2289 ··tags:
2290 ··-·CJIS-5.4.1.12290 ··-·CJIS-5.4.1.1
2291 ··-·DISA-STIG-RHEL-08-0304802291 ··-·DISA-STIG-RHEL-08-030480
2292 ··-·NIST-800-171-3.1.72292 ··-·NIST-800-171-3.1.7
2293 ··-·NIST-800-53-AU-12(c)2293 ··-·NIST-800-53-AU-12(c)
2294 ··-·NIST-800-53-AU-2(d)2294 ··-·NIST-800-53-AU-2(d)
2295 ··-·NIST-800-53-CM-6(a)2295 ··-·NIST-800-53-CM-6(a)
Offset 2426, 16 lines modifiedOffset 2426, 16 lines modified
2426 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002426 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2427 ········-F·auid!=unset·-F·key=perm_mod2427 ········-F·auid!=unset·-F·key=perm_mod
2428 ······create:·true2428 ······create:·true
2429 ······mode:·o-rwx2429 ······mode:·o-rwx
2430 ······state:·present2430 ······state:·present
Max diff block lines reached; 91629/96109 bytes (95.34%) of diff not shown.
750 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-stig.html
    
Offset 14558, 16 lines modifiedOffset 14558, 16 lines modified
00038dd0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</00038dd0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</
00038de0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve00038de0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve
00038df0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>000038df0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>0
00038e00:·2e31·2e36·353c·2f73·7472·6f6e·673e·3c2f··.1.65</strong></00038e00:·2e31·2e36·353c·2f73·7472·6f6e·673e·3c2f··.1.65</strong></
00038e10:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron00038e10:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron
00038e20:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>00038e20:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>
00038e30:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00038e30:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00038e40:·2020·2020·2028·6173·206f·6620·3230·3234·······(as·of·202400038e40:·2020·2020·2028·6173·206f·6620·3230·3235·······(as·of·2025
00038e50:·2d30·312d·3134·290a·2020·2020·2020·2020··-01-14).········00038e50:·2d30·322d·3135·290a·2020·2020·2020·2020··-02-15).········
00038e60:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u00038e60:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u
00038e70:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl00038e70:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl
00038e80:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h00038e80:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h
00038e90:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre00038e90:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre
00038ea0:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss00038ea0:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss
00038eb0:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content00038eb0:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content
00038ec0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S00038ec0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S
Offset 103074, 23 lines modifiedOffset 103074, 23 lines modified
00192a10:·6f74·5f72·6571·7569·7265·640a·2020·2d20··ot_required.··-·00192a10:·6f74·5f72·6571·7569·7265·640a·2020·2d20··ot_required.··-·
00192a20:·7265·7374·7269·6374·5f73·7472·6174·6567··restrict_strateg00192a20:·7265·7374·7269·6374·5f73·7472·6174·6567··restrict_strateg
00192a30:·790a·0a2d·206e·616d·653a·2053·6574·2061··y..-·name:·Set·a00192a30:·790a·0a2d·206e·616d·653a·2053·6574·2061··y..-·name:·Set·a
00192a40:·7263·6869·7465·6374·7572·6520·666f·7220··rchitecture·for·00192a40:·7263·6869·7465·6374·7572·6520·666f·7220··rchitecture·for·
00192a50:·6175·6469·7420·6368·6d6f·6420·7461·736b··audit·chmod·task00192a50:·6175·6469·7420·6368·6d6f·6420·7461·736b··audit·chmod·task
00192a60:·730a·2020·7365·745f·6661·6374·3a0a·2020··s.··set_fact:.··00192a60:·730a·2020·7365·745f·6661·6374·3a0a·2020··s.··set_fact:.··
00192a70:·2020·6175·6469·745f·6172·6368·3a20·6236····audit_arch:·b600192a70:·2020·6175·6469·745f·6172·6368·3a20·6236····audit_arch:·b6
00192a80:·340a·2020·7768·656e·3a0a·2020·2d20·2722··4.··when:.··-·'"00192a80:·340a·2020·7768·656e·3a0a·2020·2d20·616e··4.··when:.··-·an
00192a90:·6175·6469·7422·2069·6e20·616e·7369·626c··audit"·in·ansibl 
00192aa0:·655f·6661·6374·732e·7061·636b·6167·6573··e_facts.packages 
00192ab0:·270a·2020·2d20·616e·7369·626c·655f·7669··'.··-·ansible_vi 
00192ac0:·7274·7561·6c69·7a61·7469·6f6e·5f74·7970··rtualization_typ 
00192ad0:·6520·6e6f·7420·696e·205b·2264·6f63·6b65··e·not·in·["docke 
00192ae0:·7222·2c20·226c·7863·222c·2022·6f70·656e··r",·"lxc",·"open 
00192af0:·767a·222c·2022·706f·646d·616e·222c·2022··vz",·"podman",·" 
00192b00:·636f·6e74·6169·6e65·7222·5d0a·2020·2d20··container"].··-·00192a90:·7369·626c·655f·7669·7274·7561·6c69·7a61··sible_virtualiza
 00192aa0:·7469·6f6e·5f74·7970·6520·6e6f·7420·696e··tion_type·not·in
 00192ab0:·205b·2264·6f63·6b65·7222·2c20·226c·7863···["docker",·"lxc
 00192ac0:·222c·2022·6f70·656e·767a·222c·2022·706f··",·"openvz",·"po
 00192ad0:·646d·616e·222c·2022·636f·6e74·6169·6e65··dman",·"containe
 00192ae0:·7222·5d0a·2020·2d20·2722·6175·6469·7422··r"].··-·'"audit"
 00192af0:·2069·6e20·616e·7369·626c·655f·6661·6374···in·ansible_fact
 00192b00:·732e·7061·636b·6167·6573·270a·2020·2d20··s.packages'.··-·
00192b10:·616e·7369·626c·655f·6172·6368·6974·6563··ansible_architec00192b10:·616e·7369·626c·655f·6172·6368·6974·6563··ansible_architec
00192b20:·7475·7265·203d·3d20·2261·6172·6368·3634··ture·==·"aarch6400192b20:·7475·7265·203d·3d20·2261·6172·6368·3634··ture·==·"aarch64
00192b30:·2220·6f72·2061·6e73·6962·6c65·5f61·7263··"·or·ansible_arc00192b30:·2220·6f72·2061·6e73·6962·6c65·5f61·7263··"·or·ansible_arc
00192b40:·6869·7465·6374·7572·6520·3d3d·2022·7070··hitecture·==·"pp00192b40:·6869·7465·6374·7572·6520·3d3d·2022·7070··hitecture·==·"pp
00192b50:·6336·3422·206f·7220·616e·7369·626c·655f··c64"·or·ansible_00192b50:·6336·3422·206f·7220·616e·7369·626c·655f··c64"·or·ansible_
00192b60:·6172·6368·6974·6563·7475·7265·0a20·2020··architecture.···00192b60:·6172·6368·6974·6563·7475·7265·0a20·2020··architecture.···
00192b70:·203d·3d20·2270·7063·3634·6c65·2220·6f72···==·"ppc64le"·or00192b70:·203d·3d20·2270·7063·3634·6c65·2220·6f72···==·"ppc64le"·or
Offset 103398, 22 lines modifiedOffset 103398, 22 lines modified
00193e50:·6d6f·640a·2020·2020·2020·6372·6561·7465··mod.······create00193e50:·6d6f·640a·2020·2020·2020·6372·6561·7465··mod.······create
00193e60:·3a20·7472·7565·0a20·2020·2020·206d·6f64··:·true.······mod00193e60:·3a20·7472·7565·0a20·2020·2020·206d·6f64··:·true.······mod
00193e70:·653a·206f·2d72·7778·0a20·2020·2020·2073··e:·o-rwx.······s00193e70:·653a·206f·2d72·7778·0a20·2020·2020·2073··e:·o-rwx.······s
00193e80:·7461·7465·3a20·7072·6573·656e·740a·2020··tate:·present.··00193e80:·7461·7465·3a20·7072·6573·656e·740a·2020··tate:·present.··
00193e90:·2020·7768·656e·3a20·7379·7363·616c·6c73····when:·syscalls00193e90:·2020·7768·656e·3a20·7379·7363·616c·6c73····when:·syscalls
00193ea0:·5f66·6f75·6e64·207c·206c·656e·6774·6820··_found·|·length·00193ea0:·5f66·6f75·6e64·207c·206c·656e·6774·6820··_found·|·length·
00193eb0:·3d3d·2030·0a20·2077·6865·6e3a·0a20·202d··==·0.··when:.··-00193eb0:·3d3d·2030·0a20·2077·6865·6e3a·0a20·202d··==·0.··when:.··-
00193ec0:·2027·2261·7564·6974·2220·696e·2061·6e73···'"audit"·in·ans 
00193ed0:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa 
00193ee0:·6765·7327·0a20·202d·2061·6e73·6962·6c65··ges'.··-·ansible 
00193ef0:·5f76·6972·7475·616c·697a·6174·696f·6e5f··_virtualization_ 
00193f00:·7479·7065·206e·6f74·2069·6e20·5b22·646f··type·not·in·["do 
00193f10:·636b·6572·222c·2022·6c78·6322·2c20·226f··cker",·"lxc",·"o 
00193f20:·7065·6e76·7a22·2c20·2270·6f64·6d61·6e22··penvz",·"podman" 
00193f30:·2c20·2263·6f6e·7461·696e·6572·225d·0a20··,·"container"].·00193ec0:·2061·6e73·6962·6c65·5f76·6972·7475·616c···ansible_virtual
 00193ed0:·697a·6174·696f·6e5f·7479·7065·206e·6f74··ization_type·not
 00193ee0:·2069·6e20·5b22·646f·636b·6572·222c·2022···in·["docker",·"
 00193ef0:·6c78·6322·2c20·226f·7065·6e76·7a22·2c20··lxc",·"openvz",·
 00193f00:·2270·6f64·6d61·6e22·2c20·2263·6f6e·7461··"podman",·"conta
 00193f10:·696e·6572·225d·0a20·202d·2027·2261·7564··iner"].··-·'"aud
 00193f20:·6974·2220·696e·2061·6e73·6962·6c65·5f66··it"·in·ansible_f
 00193f30:·6163·7473·2e70·6163·6b61·6765·7327·0a20··acts.packages'.·
00193f40:·2074·6167·733a·0a20·202d·2043·4a49·532d···tags:.··-·CJIS-00193f40:·2074·6167·733a·0a20·202d·2043·4a49·532d···tags:.··-·CJIS-
00193f50:·352e·342e·312e·310a·2020·2d20·4449·5341··5.4.1.1.··-·DISA00193f50:·352e·342e·312e·310a·2020·2d20·4449·5341··5.4.1.1.··-·DISA
00193f60:·2d53·5449·472d·5248·454c·2d30·382d·3033··-STIG-RHEL-08-0300193f60:·2d53·5449·472d·5248·454c·2d30·382d·3033··-STIG-RHEL-08-03
00193f70:·3034·3930·0a20·202d·204e·4953·542d·3830··0490.··-·NIST-8000193f70:·3034·3930·0a20·202d·204e·4953·542d·3830··0490.··-·NIST-80
00193f80:·302d·3137·312d·332e·312e·370a·2020·2d20··0-171-3.1.7.··-·00193f80:·302d·3137·312d·332e·312e·370a·2020·2d20··0-171-3.1.7.··-·
00193f90:·4e49·5354·2d38·3030·2d35·332d·4155·2d31··NIST-800-53-AU-100193f90:·4e49·5354·2d38·3030·2d35·332d·4155·2d31··NIST-800-53-AU-1
00193fa0:·3228·6329·0a20·202d·204e·4953·542d·3830··2(c).··-·NIST-8000193fa0:·3228·6329·0a20·202d·204e·4953·542d·3830··2(c).··-·NIST-80
Offset 103709, 23 lines modifiedOffset 103709, 23 lines modified
001951c0:·206b·6579·3d70·6572·6d5f·6d6f·640a·2020···key=perm_mod.··001951c0:·206b·6579·3d70·6572·6d5f·6d6f·640a·2020···key=perm_mod.··
001951d0:·2020·2020·6372·6561·7465·3a20·7472·7565······create:·true001951d0:·2020·2020·6372·6561·7465·3a20·7472·7565······create:·true
001951e0:·0a20·2020·2020·206d·6f64·653a·206f·2d72··.······mode:·o-r001951e0:·0a20·2020·2020·206d·6f64·653a·206f·2d72··.······mode:·o-r
001951f0:·7778·0a20·2020·2020·2073·7461·7465·3a20··wx.······state:·001951f0:·7778·0a20·2020·2020·2073·7461·7465·3a20··wx.······state:·
00195200:·7072·6573·656e·740a·2020·2020·7768·656e··present.····when00195200:·7072·6573·656e·740a·2020·2020·7768·656e··present.····when
00195210:·3a20·7379·7363·616c·6c73·5f66·6f75·6e64··:·syscalls_found00195210:·3a20·7379·7363·616c·6c73·5f66·6f75·6e64··:·syscalls_found
00195220:·207c·206c·656e·6774·6820·3d3d·2030·0a20···|·length·==·0.·00195220:·207c·206c·656e·6774·6820·3d3d·2030·0a20···|·length·==·0.·
00195230:·2077·6865·6e3a·0a20·202d·2027·2261·7564···when:.··-·'"aud00195230:·2077·6865·6e3a·0a20·202d·2061·6e73·6962···when:.··-·ansib
00195240:·6974·2220·696e·2061·6e73·6962·6c65·5f66··it"·in·ansible_f 
00195250:·6163·7473·2e70·6163·6b61·6765·7327·0a20··acts.packages'.· 
00195260:·202d·2061·6e73·6962·6c65·5f76·6972·7475···-·ansible_virtu 
00195270:·616c·697a·6174·696f·6e5f·7479·7065·206e··alization_type·n 
00195280:·6f74·2069·6e20·5b22·646f·636b·6572·222c··ot·in·["docker", 
00195290:·2022·6c78·6322·2c20·226f·7065·6e76·7a22···"lxc",·"openvz" 
001952a0:·2c20·2270·6f64·6d61·6e22·2c20·2263·6f6e··,·"podman",·"con 
001952b0:·7461·696e·6572·225d·0a20·202d·2061·7564··tainer"].··-·aud00195240:·6c65·5f76·6972·7475·616c·697a·6174·696f··le_virtualizatio
 00195250:·6e5f·7479·7065·206e·6f74·2069·6e20·5b22··n_type·not·in·["
 00195260:·646f·636b·6572·222c·2022·6c78·6322·2c20··docker",·"lxc",·
 00195270:·226f·7065·6e76·7a22·2c20·2270·6f64·6d61··"openvz",·"podma
 00195280:·6e22·2c20·2263·6f6e·7461·696e·6572·225d··n",·"container"]
 00195290:·0a20·202d·2027·2261·7564·6974·2220·696e··.··-·'"audit"·in
 001952a0:·2061·6e73·6962·6c65·5f66·6163·7473·2e70···ansible_facts.p
 001952b0:·6163·6b61·6765·7327·0a20·202d·2061·7564··ackages'.··-·aud
001952c0:·6974·5f61·7263·6820·3d3d·2022·6236·3422··it_arch·==·"b64"001952c0:·6974·5f61·7263·6820·3d3d·2022·6236·3422··it_arch·==·"b64"
001952d0:·0a20·2074·6167·733a·0a20·202d·2043·4a49··.··tags:.··-·CJI001952d0:·0a20·2074·6167·733a·0a20·202d·2043·4a49··.··tags:.··-·CJI
001952e0:·532d·352e·342e·312e·310a·2020·2d20·4449··S-5.4.1.1.··-·DI001952e0:·532d·352e·342e·312e·310a·2020·2d20·4449··S-5.4.1.1.··-·DI
001952f0:·5341·2d53·5449·472d·5248·454c·2d30·382d··SA-STIG-RHEL-08-001952f0:·5341·2d53·5449·472d·5248·454c·2d30·382d··SA-STIG-RHEL-08-
00195300:·3033·3034·3930·0a20·202d·204e·4953·542d··030490.··-·NIST-00195300:·3033·3034·3930·0a20·202d·204e·4953·542d··030490.··-·NIST-
00195310:·3830·302d·3137·312d·332e·312e·370a·2020··800-171-3.1.7.··00195310:·3830·302d·3137·312d·332e·312e·370a·2020··800-171-3.1.7.··
00195320:·2d20·4e49·5354·2d38·3030·2d35·332d·4155··-·NIST-800-53-AU00195320:·2d20·4e49·5354·2d38·3030·2d35·332d·4155··-·NIST-800-53-AU
Offset 103759, 21 lines modifiedOffset 103759, 21 lines modified
001954e0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane001954e0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
001954f0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla001954f0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
00195500:·7073·6522·2069·643d·2269·646d·3235·3339··pse"·id="idm253900195500:·7073·6522·2069·643d·2269·646d·3235·3339··pse"·id="idm2539
00195510:·3022·3e3c·7072·653e·3c63·6f64·653e·2320··0"><pre><code>#·00195510:·3022·3e3c·7072·653e·3c63·6f64·653e·2320··0"><pre><code>#·
00195520:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a00195520:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a
00195530:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i00195530:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i
00195540:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo00195540:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo
00195550:·726d·730a·6966·2072·706d·202d·2d71·7569··rms.if·rpm·--qui 
00195560:·6574·202d·7120·6175·6469·7420·2661·6d70··et·-q·audit·&amp 
00195570:·3b26·616d·703b·205b·2021·202d·6620·2f2e··;&amp;·[·!·-f·/.00195550:·726d·730a·6966·205b·2021·202d·6620·2f2e··rms.if·[·!·-f·/.
00195580:·646f·636b·6572·656e·7620·5d20·2661·6d70··dockerenv·]·&amp00195560:·646f·636b·6572·656e·7620·5d20·2661·6d70··dockerenv·]·&amp
00195590:·3b26·616d·703b·205b·2021·202d·6620·2f72··;&amp;·[·!·-f·/r00195570:·3b26·616d·703b·205b·2021·202d·6620·2f72··;&amp;·[·!·-f·/r
001955a0:·756e·2f2e·636f·6e74·6169·6e65·7265·6e76··un/.containerenv00195580:·756e·2f2e·636f·6e74·6169·6e65·7265·6e76··un/.containerenv
 00195590:·205d·2026·616d·703b·2661·6d70·3b20·7270···]·&amp;&amp;·rp
 001955a0:·6d20·2d2d·7175·6965·7420·2d71·2061·7564··m·--quiet·-q·aud
001955b0:·205d·3b20·7468·656e·0a0a·2320·4669·7273···];·then..#·Firs001955b0:·6974·3b20·7468·656e·0a0a·2320·4669·7273··it;·then..#·Firs
001955c0:·7420·7065·7266·6f72·6d20·7468·6520·7265··t·perform·the·re001955c0:·7420·7065·7266·6f72·6d20·7468·6520·7265··t·perform·the·re
001955d0:·6d65·6469·6174·696f·6e20·6f66·2074·6865··mediation·of·the001955d0:·6d65·6469·6174·696f·6e20·6f66·2074·6865··mediation·of·the
Max diff block lines reached; 579792/589314 bytes (98.38%) of diff not shown.
174 KB
html2text {}
    
Offset 72, 15 lines modifiedOffset 72, 15 lines modified
72 ····*·cpe:/o:redhat:enterprise_linux:8.772 ····*·cpe:/o:redhat:enterprise_linux:8.7
73 ····*·cpe:/o:redhat:enterprise_linux:8.873 ····*·cpe:/o:redhat:enterprise_linux:8.8
74 ····*·cpe:/o:redhat:enterprise_linux:8.974 ····*·cpe:/o:redhat:enterprise_linux:8.9
75 ····*·cpe:/o:redhat:enterprise_linux:875 ····*·cpe:/o:redhat:enterprise_linux:8
76 ····*·cpe:/o:centos:centos:876 ····*·cpe:/o:centos:centos:8
77 *****·Revision·History·*****77 *****·Revision·History·*****
78 Current·version:·0.1.6578 Current·version:·0.1.65
79 ····*·draft·(as·of·2024-01-14)79 ····*·draft·(as·of·2025-02-15)
80 *****·Table·of·Contents·*****80 *****·Table·of·Contents·*****
81 ···1.·System_Settings81 ···1.·System_Settings
82 ·········1.·Installing_and_Maintaining_Software82 ·········1.·Installing_and_Maintaining_Software
83 ·········2.·Account_and_Access_Control83 ·········2.·Account_and_Access_Control
84 ·········3.·System_Accounting_with_auditd84 ·········3.·System_Accounting_with_auditd
85 ·········4.·GRUB2_bootloader_configuration85 ·········4.·GRUB2_bootloader_configuration
86 ·········5.·Configure_Syslog86 ·········5.·Configure_Syslog
Offset 17204, 16 lines modifiedOffset 17204, 16 lines modified
17204 ··-·reboot_required17204 ··-·reboot_required
17205 ··-·restrict_strategy17205 ··-·restrict_strategy
  
17206 -·name:·Set·architecture·for·audit·chmod·tasks17206 -·name:·Set·architecture·for·audit·chmod·tasks
17207 ··set_fact:17207 ··set_fact:
17208 ····audit_arch:·b6417208 ····audit_arch:·b64
17209 ··when:17209 ··when:
17210 ··-·'"audit"·in·ansible_facts.packages' 
17211 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]17210 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 17211 ··-·'"audit"·in·ansible_facts.packages'
17212 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture17212 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
17213 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"17213 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
17214 ··tags:17214 ··tags:
17215 ··-·CJIS-5.4.1.117215 ··-·CJIS-5.4.1.1
17216 ··-·DISA-STIG-RHEL-08-03049017216 ··-·DISA-STIG-RHEL-08-030490
17217 ··-·NIST-800-171-3.1.717217 ··-·NIST-800-171-3.1.7
17218 ··-·NIST-800-53-AU-12(c)17218 ··-·NIST-800-53-AU-12(c)
Offset 17350, 16 lines modifiedOffset 17350, 16 lines modified